{"id":453,"date":"2026-05-26T20:45:48","date_gmt":"2026-05-26T18:45:48","guid":{"rendered":"https:\/\/eryann.fr\/?p=453"},"modified":"2026-05-26T20:48:57","modified_gmt":"2026-05-26T18:48:57","slug":"fiche-configuration-dun-routeur-cisco-avec-vlan-nat-acl-et-securisation-ssh","status":"publish","type":"post","link":"https:\/\/eryann.fr\/index.php\/8021q\/fiche-configuration-dun-routeur-cisco-avec-vlan-nat-acl-et-securisation-ssh\/","title":{"rendered":"Fiche \u2013 Configuration d\u2019un routeur Cisco avec VLAN, NAT, ACL et s\u00e9curisation SSH"},"content":{"rendered":"\n<h1 class=\"wp-block-heading\"><\/h1>\n\n\n\n<h2 class=\"wp-block-heading\">Objectif<\/h2>\n\n\n\n<p class=\"wp-block-paragraph\">Cette configuration permet de :<\/p>\n\n\n\n<ul class=\"wp-block-list\">\n<li>Mettre en place un routage inter-VLAN<\/li>\n\n\n\n<li>Configurer le NAT pour l\u2019acc\u00e8s Internet<\/li>\n\n\n\n<li>S\u00e9curiser l\u2019administration du routeur en SSH<\/li>\n\n\n\n<li>Autoriser l\u2019acc\u00e8s au serveur <code>10.0.0.100<\/code><\/li>\n\n\n\n<li>Autoriser l\u2019acc\u00e8s au VLAN 10le vlan 10 est pluto m<\/li>\n\n\n\n<li>Publier un serveur web interne <code>10.0.0.2<\/code><\/li>\n\n\n\n<li>Bloquer le VLAN 30 vers Internet<\/li>\n\n\n\n<li>Interdire tout le reste via ACL<\/li>\n<\/ul>\n\n\n\n<hr class=\"wp-block-separator has-alpha-channel-opacity\"\/>\n\n\n\n<figure class=\"wp-block-image size-large\"><img loading=\"lazy\" decoding=\"async\" width=\"1024\" height=\"683\" src=\"https:\/\/eryann.fr\/wp-content\/uploads\/2026\/05\/image-14-1024x683.png\" alt=\"\" class=\"wp-image-455\" srcset=\"https:\/\/eryann.fr\/wp-content\/uploads\/2026\/05\/image-14-1024x683.png 1024w, https:\/\/eryann.fr\/wp-content\/uploads\/2026\/05\/image-14-300x200.png 300w, https:\/\/eryann.fr\/wp-content\/uploads\/2026\/05\/image-14-768x512.png 768w, https:\/\/eryann.fr\/wp-content\/uploads\/2026\/05\/image-14.png 1536w\" sizes=\"auto, (max-width: 1024px) 100vw, 1024px\" \/><\/figure>\n\n\n\n<h1 class=\"wp-block-heading\">1. Configuration de base du routeur<\/h1>\n\n\n\n<h2 class=\"wp-block-heading\">Nom du routeur et domaine<\/h2>\n\n\n\n<pre class=\"wp-block-code\"><code>hostname R1<br>ip domain name eryann.bzh<\/code><\/pre>\n\n\n\n<hr class=\"wp-block-separator has-alpha-channel-opacity\"\/>\n\n\n\n<h2 class=\"wp-block-heading\">S\u00e9curisation des mots de passe<\/h2>\n\n\n\n<pre class=\"wp-block-code\"><code>service password-encryption<br><br>enable secret motDePasseFort<br>username admin secret MotDePasseFort<\/code><\/pre>\n\n\n\n<hr class=\"wp-block-separator has-alpha-channel-opacity\"\/>\n\n\n\n<h1 class=\"wp-block-heading\">2. Configuration des interfaces<\/h1>\n\n\n\n<h2 class=\"wp-block-heading\">Interface WAN (Internet)<\/h2>\n\n\n\n<pre class=\"wp-block-code\"><code>interface GigabitEthernet0\/0\/0<br> ip address 192.168.40.126 255.255.255.0<br> ip nat outside<br> no shutdown<\/code><\/pre>\n\n\n\n<hr class=\"wp-block-separator has-alpha-channel-opacity\"\/>\n\n\n\n<h2 class=\"wp-block-heading\">Interface trunk vers le switch<\/h2>\n\n\n\n<pre class=\"wp-block-code\"><code>interface GigabitEthernet0\/0\/1<br> no ip address<br> no shutdown<\/code><\/pre>\n\n\n\n<hr class=\"wp-block-separator has-alpha-channel-opacity\"\/>\n\n\n\n<h1 class=\"wp-block-heading\">3. Configuration des VLANs<\/h1>\n\n\n\n<h2 class=\"wp-block-heading\">VLAN 10<\/h2>\n\n\n\n<pre class=\"wp-block-code\"><code>interface GigabitEthernet0\/0\/1.10<br> encapsulation dot1Q 10<br> ip address 10.0.0.1 255.255.255.224<br> ip helper-address 10.0.0.100<br> ip nat inside<br> ip access-group VLAN10-IN in<\/code><\/pre>\n\n\n\n<hr class=\"wp-block-separator has-alpha-channel-opacity\"\/>\n\n\n\n<h2 class=\"wp-block-heading\">VLAN 20<\/h2>\n\n\n\n<pre class=\"wp-block-code\"><code>interface GigabitEthernet0\/0\/1.20<br> encapsulation dot1Q 20<br> ip address 10.0.0.33 255.255.255.224<br> ip helper-address 10.0.0.100<br> ip nat inside<br> ip access-group VLAN20-IN in<\/code><\/pre>\n\n\n\n<hr class=\"wp-block-separator has-alpha-channel-opacity\"\/>\n\n\n\n<h2 class=\"wp-block-heading\">VLAN 30<\/h2>\n\n\n\n<pre class=\"wp-block-code\"><code>interface GigabitEthernet0\/0\/1.30<br> encapsulation dot1Q 30<br> ip address 10.0.0.65 255.255.255.224<br> ip helper-address 10.0.0.100<br> ip nat inside<br> ip access-group VLAN30-IN in<\/code><\/pre>\n\n\n\n<hr class=\"wp-block-separator has-alpha-channel-opacity\"\/>\n\n\n\n<h2 class=\"wp-block-heading\">VLAN 40<\/h2>\n\n\n\n<pre class=\"wp-block-code\"><code>interface GigabitEthernet0\/0\/1.40<br> encapsulation dot1Q 40<br> ip address 10.0.0.97 255.255.255.224<br> ip helper-address 10.0.0.100<br> ip nat inside<br> ip access-group VLAN40-IN in<\/code><\/pre>\n\n\n\n<hr class=\"wp-block-separator has-alpha-channel-opacity\"\/>\n\n\n\n<h1 class=\"wp-block-heading\">4. Configuration du NAT Internet<\/h1>\n\n\n\n<h2 class=\"wp-block-heading\">ACL NAT<\/h2>\n\n\n\n<pre class=\"wp-block-code\"><code>ip access-list standard NAT<br> permit 10.0.0.0 0.0.0.127<\/code><\/pre>\n\n\n\n<hr class=\"wp-block-separator has-alpha-channel-opacity\"\/>\n\n\n\n<h2 class=\"wp-block-heading\">Activation du PAT (NAT overload)<\/h2>\n\n\n\n<pre class=\"wp-block-code\"><code>ip nat inside source list NAT interface GigabitEthernet0\/0\/0 overload<\/code><\/pre>\n\n\n\n<hr class=\"wp-block-separator has-alpha-channel-opacity\"\/>\n\n\n\n<h2 class=\"wp-block-heading\">Route par d\u00e9faut<\/h2>\n\n\n\n<pre class=\"wp-block-code\"><code>ip route 0.0.0.0 0.0.0.0 192.168.40.1<\/code><\/pre>\n\n\n\n<hr class=\"wp-block-separator has-alpha-channel-opacity\"\/>\n\n\n\n<h1 class=\"wp-block-heading\">5. Publication du serveur web interne<\/h1>\n\n\n\n<h2 class=\"wp-block-heading\">Redirection du port 80 externe vers 10.0.0.2<\/h2>\n\n\n\n<pre class=\"wp-block-code\"><code>ip nat inside source static tcp 10.0.0.2 80 interface GigabitEthernet0\/0\/0 80<\/code><\/pre>\n\n\n\n<p class=\"wp-block-paragraph\">Cette r\u00e8gle permet d\u2019acc\u00e9der au serveur web depuis Internet via l\u2019adresse publique du routeur.<\/p>\n\n\n\n<hr class=\"wp-block-separator has-alpha-channel-opacity\"\/>\n\n\n\n<h1 class=\"wp-block-heading\">6. S\u00e9curisation SSH<\/h1>\n\n\n\n<h2 class=\"wp-block-heading\">G\u00e9n\u00e9ration des cl\u00e9s RSA<\/h2>\n\n\n\n<pre class=\"wp-block-code\"><code>crypto key generate rsa<\/code><\/pre>\n\n\n\n<p class=\"wp-block-paragraph\">Taille recommand\u00e9e :<\/p>\n\n\n\n<pre class=\"wp-block-code\"><code>1024<\/code><\/pre>\n\n\n\n<hr class=\"wp-block-separator has-alpha-channel-opacity\"\/>\n\n\n\n<h2 class=\"wp-block-heading\">Activation SSH v2<\/h2>\n\n\n\n<pre class=\"wp-block-code\"><code>ip ssh version 2<\/code><\/pre>\n\n\n\n<hr class=\"wp-block-separator has-alpha-channel-opacity\"\/>\n\n\n\n<h2 class=\"wp-block-heading\">Configuration des lignes VTY<\/h2>\n\n\n\n<pre class=\"wp-block-code\"><code>line vty 0 15<br> login local<br> transport input ssh<br> exec-timeout 5 0<\/code><\/pre>\n\n\n\n<hr class=\"wp-block-separator has-alpha-channel-opacity\"\/>\n\n\n\n<h2 class=\"wp-block-heading\">D\u00e9sactivation Telnet<\/h2>\n\n\n\n<p class=\"wp-block-paragraph\">Le Telnet est d\u00e9sactiv\u00e9 gr\u00e2ce \u00e0 :<\/p>\n\n\n\n<pre class=\"wp-block-code\"><code>transport input ssh<\/code><\/pre>\n\n\n\n<hr class=\"wp-block-separator has-alpha-channel-opacity\"\/>\n\n\n\n<h1 class=\"wp-block-heading\">7. Configuration des ACL de s\u00e9curit\u00e9<\/h1>\n\n\n\n<h2 class=\"wp-block-heading\">Objectifs<\/h2>\n\n\n\n<figure class=\"wp-block-table\"><table class=\"has-fixed-layout\"><thead><tr><th>R\u00e8gle<\/th><th>Autorisation<\/th><\/tr><\/thead><tbody><tr><td>Tous les VLAN<\/td><td>Acc\u00e8s au serveur <code>10.0.0.100<\/code><\/td><\/tr><tr><td>Tous les VLAN<\/td><td>Acc\u00e8s au VLAN 10<\/td><\/tr><tr><td>VLAN 10<\/td><td>Internet<\/td><\/tr><tr><td>VLAN 20<\/td><td>Internet<\/td><\/tr><tr><td>VLAN 40<\/td><td>Internet<\/td><\/tr><tr><td>VLAN 30<\/td><td>Internet interdit<\/td><\/tr><tr><td>Tout le reste<\/td><td>Refus\u00e9<\/td><\/tr><\/tbody><\/table><\/figure>\n\n\n\n<hr class=\"wp-block-separator has-alpha-channel-opacity\"\/>\n\n\n\n<h1 class=\"wp-block-heading\">ACL VLAN 10<\/h1>\n\n\n\n<pre class=\"wp-block-code\"><code>ip access-list extended VLAN10-IN<br><br> remark Acces serveur<br> permit ip any host 10.0.0.100<br><br> remark Acces VLAN 10<br> permit ip any 10.0.0.0 0.0.0.31<br><br> remark Internet<br> permit ip any any<br><br> deny ip any any<\/code><\/pre>\n\n\n\n<hr class=\"wp-block-separator has-alpha-channel-opacity\"\/>\n\n\n\n<h1 class=\"wp-block-heading\">ACL VLAN 20<\/h1>\n\n\n\n<pre class=\"wp-block-code\"><code>ip access-list extended VLAN20-IN<br><br> remark Acces serveur<br> permit ip any host 10.0.0.100<br><br> remark Acces VLAN 10<br> permit ip any 10.0.0.0 0.0.0.31<br><br> remark Internet<br> permit ip any any<br><br> deny ip any any<\/code><\/pre>\n\n\n\n<hr class=\"wp-block-separator has-alpha-channel-opacity\"\/>\n\n\n\n<h1 class=\"wp-block-heading\">ACL VLAN 30<\/h1>\n\n\n\n<pre class=\"wp-block-code\"><code>ip access-list extended VLAN30-IN<br><br> remark Acces serveur<br> permit ip any host 10.0.0.100<br><br> remark Acces VLAN 10<br> permit ip any 10.0.0.0 0.0.0.31<br><br> remark Blocage Internet<br> deny ip any any<\/code><\/pre>\n\n\n\n<hr class=\"wp-block-separator has-alpha-channel-opacity\"\/>\n\n\n\n<h1 class=\"wp-block-heading\">ACL VLAN 40<\/h1>\n\n\n\n<pre class=\"wp-block-code\"><code>ip access-list extended VLAN40-IN<br><br> remark Acces serveur<br> permit ip any host 10.0.0.100<br><br> remark Acces VLAN 10<br> permit ip any 10.0.0.0 0.0.0.31<br><br> remark Internet<br> permit ip any any<br><br> deny ip any any<\/code><\/pre>\n\n\n\n<hr class=\"wp-block-separator has-alpha-channel-opacity\"\/>\n\n\n\n<h1 class=\"wp-block-heading\">8. Sauvegarde de la configuration<\/h1>\n\n\n\n<h2 class=\"wp-block-heading\">Sauvegarde imm\u00e9diate<\/h2>\n\n\n\n<pre class=\"wp-block-code\"><code>copy running-config startup-config<\/code><\/pre>\n\n\n\n<hr class=\"wp-block-separator has-alpha-channel-opacity\"\/>\n\n\n\n<h1 class=\"wp-block-heading\">9. V\u00e9rifications utiles<\/h1>\n\n\n\n<h2 class=\"wp-block-heading\">V\u00e9rifier les interfaces<\/h2>\n\n\n\n<pre class=\"wp-block-code\"><code>show ip interface brief<\/code><\/pre>\n\n\n\n<hr class=\"wp-block-separator has-alpha-channel-opacity\"\/>\n\n\n\n<h2 class=\"wp-block-heading\">V\u00e9rifier le NAT<\/h2>\n\n\n\n<pre class=\"wp-block-code\"><code>show ip nat translations<\/code><\/pre>\n\n\n\n<hr class=\"wp-block-separator has-alpha-channel-opacity\"\/>\n\n\n\n<h2 class=\"wp-block-heading\">V\u00e9rifier les ACL<\/h2>\n\n\n\n<pre class=\"wp-block-code\"><code>show access-lists<\/code><\/pre>\n\n\n\n<hr class=\"wp-block-separator has-alpha-channel-opacity\"\/>\n\n\n\n<h2 class=\"wp-block-heading\">V\u00e9rifier SSH<\/h2>\n\n\n\n<pre class=\"wp-block-code\"><code>show ip ssh<\/code><\/pre>\n\n\n\n<p class=\"wp-block-paragraph\"><\/p>\n\n\n\n<h1 class=\"wp-block-heading\">11. Configuration du switch Cisco<\/h1>\n\n\n\n<h2 class=\"wp-block-heading\">Objectif<\/h2>\n\n\n\n<p class=\"wp-block-paragraph\">Cette configuration permet :<\/p>\n\n\n\n<ul class=\"wp-block-list\">\n<li>La cr\u00e9ation des VLAN<\/li>\n\n\n\n<li>Le param\u00e9trage des ports access et trunk<\/li>\n\n\n\n<li>La s\u00e9curisation des ports<\/li>\n\n\n\n<li>La limitation des attaques r\u00e9seau<\/li>\n\n\n\n<li>Le raccordement de plusieurs \u00e9quipements sur diff\u00e9rents ports VLAN<\/li>\n<\/ul>\n\n\n\n<hr class=\"wp-block-separator has-alpha-channel-opacity\"\/>\n\n\n\n<h1 class=\"wp-block-heading\">12. Cr\u00e9ation des VLAN<\/h1>\n\n\n\n<pre class=\"wp-block-code\"><code>configure terminal<br><br>vlan 10<br> name ADMIN<br><br>vlan 20<br> name USERS<br><br>vlan 30<br> name IOT<br><br>vlan 40<br> name WIFI<\/code><\/pre>\n\n\n\n<hr class=\"wp-block-separator has-alpha-channel-opacity\"\/>\n\n\n\n<h1 class=\"wp-block-heading\">13. Configuration du trunk vers le routeur<\/h1>\n\n\n\n<h2 class=\"wp-block-heading\">Port connect\u00e9 au routeur<\/h2>\n\n\n\n<p class=\"wp-block-paragraph\">Exemple : interface <code>GigabitEthernet0\/1<\/code><\/p>\n\n\n\n<pre class=\"wp-block-code\"><code>interface GigabitEthernet0\/1<br> description TRUNK_VERS_ROUTEUR<br> switchport mode trunk<br> switchport trunk allowed vlan 10,20,30,40<br> no shutdown<\/code><\/pre>\n\n\n\n<hr class=\"wp-block-separator has-alpha-channel-opacity\"\/>\n\n\n\n<h1 class=\"wp-block-heading\">14. Configuration des ports utilisateurs<\/h1>\n\n\n\n<h1 class=\"wp-block-heading\">VLAN 10 \u2014 Administration<\/h1>\n\n\n\n<h2 class=\"wp-block-heading\">Ports avec plusieurs \u00e9quipements<\/h2>\n\n\n\n<p class=\"wp-block-paragraph\">Exemple :<\/p>\n\n\n\n<ul class=\"wp-block-list\">\n<li>PC administratifs<\/li>\n\n\n\n<li>Imprimantes<\/li>\n\n\n\n<li>T\u00e9l\u00e9phones IP<\/li>\n<\/ul>\n\n\n\n<p class=\"wp-block-paragraph\">Ports <code>Fa0\/1 \u00e0 Fa0\/6<\/code><\/p>\n\n\n\n<pre class=\"wp-block-code\"><code>interface range FastEthernet0\/1 - 6<br> description VLAN10_ADMIN<br> switchport mode access<br> switchport access vlan 10<br> spanning-tree portfast<br> spanning-tree bpduguard enable<br> switchport port-security<br> switchport port-security maximum 3<br> switchport port-security violation restrict<br> switchport port-security mac-address sticky<br> no shutdown<\/code><\/pre>\n\n\n\n<hr class=\"wp-block-separator has-alpha-channel-opacity\"\/>\n\n\n\n<h1 class=\"wp-block-heading\">VLAN 20 \u2014 Utilisateurs<\/h1>\n\n\n\n<h2 class=\"wp-block-heading\">Ports utilisateurs classiques<\/h2>\n\n\n\n<p class=\"wp-block-paragraph\">Ports <code>Fa0\/7 \u00e0 Fa0\/16<\/code><\/p>\n\n\n\n<pre class=\"wp-block-code\"><code>interface range FastEthernet0\/7 - 16<br> description VLAN20_USERS<br> switchport mode access<br> switchport access vlan 20<br> spanning-tree portfast<br> spanning-tree bpduguard enable<br> switchport port-security<br> switchport port-security maximum 2<br> switchport port-security violation restrict<br> switchport port-security mac-address sticky<br> no shutdown<\/code><\/pre>\n\n\n\n<hr class=\"wp-block-separator has-alpha-channel-opacity\"\/>\n\n\n\n<h1 class=\"wp-block-heading\">VLAN 30 \u2014 IoT \/ Cam\u00e9ras \/ Objets connect\u00e9s<\/h1>\n\n\n\n<p class=\"wp-block-paragraph\">Ports <code>Fa0\/17 \u00e0 Fa0\/20<\/code><\/p>\n\n\n\n<pre class=\"wp-block-code\"><code>interface range FastEthernet0\/17 - 20<br> description VLAN30_IOT<br> switchport mode access<br> switchport access vlan 30<br> spanning-tree portfast<br> spanning-tree bpduguard enable<br> switchport port-security<br> switchport port-security maximum 5<br> switchport port-security violation shutdown<br> switchport port-security mac-address sticky<br> no shutdown<\/code><\/pre>\n\n\n\n<hr class=\"wp-block-separator has-alpha-channel-opacity\"\/>\n\n\n\n<h1 class=\"wp-block-heading\">VLAN 40 \u2014 WiFi \/ Bornes<\/h1>\n\n\n\n<p class=\"wp-block-paragraph\">Ports <code>Fa0\/21 \u00e0 Fa0\/24<\/code><\/p>\n\n\n\n<pre class=\"wp-block-code\"><code>interface range FastEthernet0\/21 - 24<br> description VLAN40_WIFI<br> switchport mode access<br> switchport access vlan 40<br> spanning-tree portfast<br> spanning-tree bpduguard enable<br> switchport port-security<br> switchport port-security maximum 10<br> switchport port-security violation restrict<br> switchport port-security mac-address sticky<br> no shutdown<\/code><\/pre>\n\n\n\n<hr class=\"wp-block-separator has-alpha-channel-opacity\"\/>\n\n\n\n<h1 class=\"wp-block-heading\">15. S\u00e9curisation des ports inutilis\u00e9s<\/h1>\n\n\n\n<h2 class=\"wp-block-heading\">D\u00e9sactivation des ports non utilis\u00e9s<\/h2>\n\n\n\n<pre class=\"wp-block-code\"><code>interface range GigabitEthernet0\/2 - 2<br> shutdown<br> description PORT_DESACTIVE<\/code><\/pre>\n\n\n\n<hr class=\"wp-block-separator has-alpha-channel-opacity\"\/>\n\n\n\n<h1 class=\"wp-block-heading\">16. Protection contre les attaques r\u00e9seau<\/h1>\n\n\n\n<h1 class=\"wp-block-heading\">Activation de Port Security<\/h1>\n\n\n\n<h2 class=\"wp-block-heading\">Fonctionnement<\/h2>\n\n\n\n<p class=\"wp-block-paragraph\">Le switch :<\/p>\n\n\n\n<ul class=\"wp-block-list\">\n<li>Apprend automatiquement les adresses MAC<\/li>\n\n\n\n<li>Limite le nombre d\u2019\u00e9quipements<\/li>\n\n\n\n<li>Bloque les \u00e9quipements inconnus<\/li>\n<\/ul>\n\n\n\n<hr class=\"wp-block-separator has-alpha-channel-opacity\"\/>\n\n\n\n<h1 class=\"wp-block-heading\">Types de violations<\/h1>\n\n\n\n<figure class=\"wp-block-table\"><table class=\"has-fixed-layout\"><thead><tr><th>Mode<\/th><th>Effet<\/th><\/tr><\/thead><tbody><tr><td>protect<\/td><td>Ignore les paquets<\/td><\/tr><tr><td>restrict<\/td><td>Ignore + log<\/td><\/tr><tr><td>shutdown<\/td><td>Coupe le port<\/td><\/tr><\/tbody><\/table><\/figure>\n\n\n\n<hr class=\"wp-block-separator has-alpha-channel-opacity\"\/>\n\n\n\n<h1 class=\"wp-block-heading\">Protection BPDU Guard<\/h1>\n\n\n\n<h2 class=\"wp-block-heading\">Objectif<\/h2>\n\n\n\n<p class=\"wp-block-paragraph\">Emp\u00eacher un utilisateur de connecter un switch non autoris\u00e9.<\/p>\n\n\n\n<pre class=\"wp-block-code\"><code>spanning-tree bpduguard enable<\/code><\/pre>\n\n\n\n<p class=\"wp-block-paragraph\">Si un BPDU est re\u00e7u :<\/p>\n\n\n\n<ul class=\"wp-block-list\">\n<li>le port passe automatiquement en erreur (<code>err-disabled<\/code>)<\/li>\n<\/ul>\n\n\n\n<hr class=\"wp-block-separator has-alpha-channel-opacity\"\/>\n\n\n\n<h1 class=\"wp-block-heading\">Activation globale de PortFast<\/h1>\n\n\n\n<pre class=\"wp-block-code\"><code>spanning-tree portfast default<\/code><\/pre>\n\n\n\n<hr class=\"wp-block-separator has-alpha-channel-opacity\"\/>\n\n\n\n<h1 class=\"wp-block-heading\">Activation globale BPDU Guard<\/h1>\n\n\n\n<pre class=\"wp-block-code\"><code>spanning-tree portfast bpduguard default<\/code><\/pre>\n\n\n\n<hr class=\"wp-block-separator has-alpha-channel-opacity\"\/>\n\n\n\n<h1 class=\"wp-block-heading\">17. S\u00e9curisation DHCP (DHCP Snooping)<\/h1>\n\n\n\n<h2 class=\"wp-block-heading\">Activation globale<\/h2>\n\n\n\n<pre class=\"wp-block-code\"><code>ip dhcp snooping<br>ip dhcp snooping vlan 10,20,30,40<\/code><\/pre>\n\n\n\n<hr class=\"wp-block-separator has-alpha-channel-opacity\"\/>\n\n\n\n<h2 class=\"wp-block-heading\">Autoriser le trunk vers le routeur DHCP<\/h2>\n\n\n\n<pre class=\"wp-block-code\"><code>interface GigabitEthernet0\/1<br> ip dhcp snooping trust<\/code><\/pre>\n\n\n\n<hr class=\"wp-block-separator has-alpha-channel-opacity\"\/>\n\n\n\n<h1 class=\"wp-block-heading\">18. Protection ARP (Dynamic ARP Inspection)<\/h1>\n\n\n\n<pre class=\"wp-block-code\"><code>ip arp inspection vlan 10,20,30,40<\/code><\/pre>\n\n\n\n<hr class=\"wp-block-separator has-alpha-channel-opacity\"\/>\n\n\n\n<h2 class=\"wp-block-heading\">Autoriser le trunk<\/h2>\n\n\n\n<pre class=\"wp-block-code\"><code>interface GigabitEthernet0\/1<br> ip arp inspection trust<\/code><\/pre>\n\n\n\n<hr class=\"wp-block-separator has-alpha-channel-opacity\"\/>\n\n\n\n<h1 class=\"wp-block-heading\">19. Protection contre les temp\u00eates r\u00e9seau<\/h1>\n\n\n\n<h2 class=\"wp-block-heading\">Storm Control<\/h2>\n\n\n\n<pre class=\"wp-block-code\"><code>interface range FastEthernet0\/1 - 24<br> storm-control broadcast level 5.00<br> storm-control multicast level 5.00<br> storm-control action shutdown<\/code><\/pre>\n\n\n\n<hr class=\"wp-block-separator has-alpha-channel-opacity\"\/>\n\n\n\n<h1 class=\"wp-block-heading\">20. S\u00e9curisation de l\u2019acc\u00e8s au switch<\/h1>\n\n\n\n<h1 class=\"wp-block-heading\">Configuration SSH<\/h1>\n\n\n\n<h2 class=\"wp-block-heading\">Nom et domaine<\/h2>\n\n\n\n<pre class=\"wp-block-code\"><code>hostname SW1<br>ip domain-name eryann.bzh<\/code><\/pre>\n\n\n\n<hr class=\"wp-block-separator has-alpha-channel-opacity\"\/>\n\n\n\n<h2 class=\"wp-block-heading\">Utilisateur local<\/h2>\n\n\n\n<pre class=\"wp-block-code\"><code>username admin secret MotDePasseFort<br>enable secret MotDePasseFort<\/code><\/pre>\n\n\n\n<hr class=\"wp-block-separator has-alpha-channel-opacity\"\/>\n\n\n\n<h2 class=\"wp-block-heading\">G\u00e9n\u00e9ration des cl\u00e9s RSA<\/h2>\n\n\n\n<pre class=\"wp-block-code\"><code>crypto key generate rsa<\/code><\/pre>\n\n\n\n<p class=\"wp-block-paragraph\">Taille :<\/p>\n\n\n\n<pre class=\"wp-block-code\"><code>1024<\/code><\/pre>\n\n\n\n<hr class=\"wp-block-separator has-alpha-channel-opacity\"\/>\n\n\n\n<h2 class=\"wp-block-heading\">Activation SSH<\/h2>\n\n\n\n<pre class=\"wp-block-code\"><code>ip ssh version 2<\/code><\/pre>\n\n\n\n<hr class=\"wp-block-separator has-alpha-channel-opacity\"\/>\n\n\n\n<h2 class=\"wp-block-heading\">Lignes VTY<\/h2>\n\n\n\n<pre class=\"wp-block-code\"><code>line vty 0 15<br> login local<br> transport input ssh<br> exec-timeout 5 0<\/code><\/pre>\n\n\n\n<hr class=\"wp-block-separator has-alpha-channel-opacity\"\/>\n\n\n\n<h1 class=\"wp-block-heading\">21. Adresse IP de management du switch<\/h1>\n\n\n\n<h2 class=\"wp-block-heading\">Interface VLAN de gestion<\/h2>\n\n\n\n<pre class=\"wp-block-code\"><code>interface vlan 10<br> ip address 10.0.0.2 255.255.255.224<br> no shutdown<\/code><\/pre>\n\n\n\n<hr class=\"wp-block-separator has-alpha-channel-opacity\"\/>\n\n\n\n<h2 class=\"wp-block-heading\">Passerelle par d\u00e9faut<\/h2>\n\n\n\n<pre class=\"wp-block-code\"><code>ip default-gateway 10.0.0.1<\/code><\/pre>\n\n\n\n<hr class=\"wp-block-separator has-alpha-channel-opacity\"\/>\n\n\n\n<h1 class=\"wp-block-heading\">22. V\u00e9rifications importantes<\/h1>\n\n\n\n<h1 class=\"wp-block-heading\">V\u00e9rifier les VLAN<\/h1>\n\n\n\n<pre class=\"wp-block-code\"><code>show vlan brief<\/code><\/pre>\n\n\n\n<hr class=\"wp-block-separator has-alpha-channel-opacity\"\/>\n\n\n\n<h1 class=\"wp-block-heading\">V\u00e9rifier le trunk<\/h1>\n\n\n\n<pre class=\"wp-block-code\"><code>show interfaces trunk<\/code><\/pre>\n\n\n\n<hr class=\"wp-block-separator has-alpha-channel-opacity\"\/>\n\n\n\n<h1 class=\"wp-block-heading\">V\u00e9rifier Port Security<\/h1>\n\n\n\n<pre class=\"wp-block-code\"><code>show port-security<br>show port-security interface FastEthernet0\/1<\/code><\/pre>\n\n\n\n<hr class=\"wp-block-separator has-alpha-channel-opacity\"\/>\n\n\n\n<h1 class=\"wp-block-heading\">V\u00e9rifier les adresses MAC apprises<\/h1>\n\n\n\n<pre class=\"wp-block-code\"><code>show mac address-table<\/code><\/pre>\n\n\n\n<hr class=\"wp-block-separator has-alpha-channel-opacity\"\/>\n\n\n\n<h1 class=\"wp-block-heading\">V\u00e9rifier DHCP Snooping<\/h1>\n\n\n\n<pre class=\"wp-block-code\"><code>show ip dhcp snooping<\/code><\/pre>\n\n\n\n<hr class=\"wp-block-separator has-alpha-channel-opacity\"\/>\n\n\n\n<h1 class=\"wp-block-heading\">V\u00e9rifier SSH<\/h1>\n\n\n\n<pre class=\"wp-block-code\"><code>show ip ssh<\/code><\/pre>\n\n\n\n<hr class=\"wp-block-separator has-alpha-channel-opacity\"\/>\n\n\n\n<h1 class=\"wp-block-heading\">23. Sauvegarde de la configuration<\/h1>\n\n\n\n<pre class=\"wp-block-code\"><code>copy running-config startup-config<\/code><\/pre>\n\n\n\n<hr class=\"wp-block-separator has-alpha-channel-opacity\"\/>\n\n\n\n<h1 class=\"wp-block-heading\">24. R\u00e9sultat final de l\u2019architecture<\/h1>\n\n\n\n<figure class=\"wp-block-table\"><table class=\"has-fixed-layout\"><thead><tr><th>VLAN<\/th><th>R\u00e9seau<\/th><th>Usage<\/th><th>Internet<\/th><\/tr><\/thead><tbody><tr><td>VLAN 10<\/td><td>10.0.0.0\/27<\/td><td>Administration<\/td><td>Oui<\/td><\/tr><tr><td>VLAN 20<\/td><td>10.0.0.32\/27<\/td><td>Utilisateurs<\/td><td>Oui<\/td><\/tr><tr><td>VLAN 30<\/td><td>10.0.0.64\/27<\/td><td>IoT<\/td><td>Non<\/td><\/tr><tr><td>VLAN 40<\/td><td>10.0.0.96\/27<\/td><td>WiFi<\/td><td>Oui<\/td><\/tr><\/tbody><\/table><\/figure>\n\n\n\n<hr class=\"wp-block-separator has-alpha-channel-opacity\"\/>\n\n\n\n<h1 class=\"wp-block-heading\">25. Fichiers de configuration importants<\/h1>\n\n\n\n<h2 class=\"wp-block-heading\">Configuration active<\/h2>\n\n\n\n<pre class=\"wp-block-code\"><code>running-config<\/code><\/pre>\n\n\n\n<hr class=\"wp-block-separator has-alpha-channel-opacity\"\/>\n\n\n\n<h2 class=\"wp-block-heading\">Configuration sauvegard\u00e9e<\/h2>\n\n\n\n<pre class=\"wp-block-code\"><code>startup-config<\/code><\/pre>\n\n\n\n<hr class=\"wp-block-separator has-alpha-channel-opacity\"\/>\n\n\n\n<h2 class=\"wp-block-heading\">Commandes utiles<\/h2>\n\n\n\n<pre class=\"wp-block-code\"><code>show running-config<br>show vlan brief<br>show interfaces trunk<br>show port-security<br>show mac address-table<br>show spanning-tree<br>show ip ssh<\/code><\/pre>\n","protected":false},"excerpt":{"rendered":"<p>Objectif Cette configuration permet de : 1. Configuration de base du routeur Nom du routeur et domaine S\u00e9curisation des mots de passe 2. Configuration des interfaces Interface WAN (Internet) Interface trunk vers le switch 3. Configuration des VLANs VLAN 10 VLAN 20 VLAN 30 VLAN 40 4. Configuration du NAT Internet ACL NAT Activation du [&hellip;]<\/p>\n","protected":false},"author":1,"featured_media":0,"comment_status":"closed","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"_import_markdown_pro_load_document_selector":0,"_import_markdown_pro_submit_text_textarea":"","site-sidebar-layout":"default","site-content-layout":"","ast-site-content-layout":"default","site-content-style":"default","site-sidebar-style":"default","ast-global-header-display":"","ast-banner-title-visibility":"","ast-main-header-display":"","ast-hfb-above-header-display":"","ast-hfb-below-header-display":"","ast-hfb-mobile-header-display":"","site-post-title":"","ast-breadcrumbs-content":"","ast-featured-img":"","footer-sml-layout":"","ast-disable-related-posts":"","theme-transparent-header-meta":"","adv-header-id-meta":"","stick-header-meta":"","header-above-stick-meta":"","header-main-stick-meta":"","header-below-stick-meta":"","astra-migrate-meta-layouts":"default","ast-page-background-enabled":"default","ast-page-background-meta":{"desktop":{"background-color":"var(--ast-global-color-5)","background-image":"","background-repeat":"repeat","background-position":"center center","background-size":"auto","background-attachment":"scroll","background-type":"","background-media":"","overlay-type":"","overlay-color":"","overlay-opacity":"","overlay-gradient":""},"tablet":{"background-color":"","background-image":"","background-repeat":"repeat","background-position":"center center","background-size":"auto","background-attachment":"scroll","background-type":"","background-media":"","overlay-type":"","overlay-color":"","overlay-opacity":"","overlay-gradient":""},"mobile":{"background-color":"","background-image":"","background-repeat":"repeat","background-position":"center center","background-size":"auto","background-attachment":"scroll","background-type":"","background-media":"","overlay-type":"","overlay-color":"","overlay-opacity":"","overlay-gradient":""}},"ast-content-background-meta":{"desktop":{"background-color":"var(--ast-global-color-4)","background-image":"","background-repeat":"repeat","background-position":"center center","background-size":"auto","background-attachment":"scroll","background-type":"","background-media":"","overlay-type":"","overlay-color":"","overlay-opacity":"","overlay-gradient":""},"tablet":{"background-color":"var(--ast-global-color-4)","background-image":"","background-repeat":"repeat","background-position":"center center","background-size":"auto","background-attachment":"scroll","background-type":"","background-media":"","overlay-type":"","overlay-color":"","overlay-opacity":"","overlay-gradient":""},"mobile":{"background-color":"var(--ast-global-color-4)","background-image":"","background-repeat":"repeat","background-position":"center center","background-size":"auto","background-attachment":"scroll","background-type":"","background-media":"","overlay-type":"","overlay-color":"","overlay-opacity":"","overlay-gradient":""}},"footnotes":""},"categories":[23,4,10],"tags":[],"class_list":["post-453","post","type-post","status-publish","format-standard","hentry","category-8021q","category-cisco","category-reseau"],"yoast_head":"<!-- This site is optimized with the Yoast SEO plugin v27.8 - https:\/\/yoast.com\/product\/yoast-seo-wordpress\/ -->\n<title>Fiche \u2013 Configuration d\u2019un routeur Cisco avec VLAN, NAT, ACL et s\u00e9curisation SSH - Eryann Breizh SecOps<\/title>\n<meta name=\"robots\" content=\"index, follow, max-snippet:-1, max-image-preview:large, max-video-preview:-1\" \/>\n<link rel=\"canonical\" href=\"https:\/\/eryann.fr\/index.php\/8021q\/fiche-configuration-dun-routeur-cisco-avec-vlan-nat-acl-et-securisation-ssh\/\" \/>\n<meta property=\"og:locale\" content=\"fr_FR\" \/>\n<meta property=\"og:type\" content=\"article\" \/>\n<meta property=\"og:title\" content=\"Fiche \u2013 Configuration d\u2019un routeur Cisco avec VLAN, NAT, ACL et s\u00e9curisation SSH - Eryann Breizh SecOps\" \/>\n<meta property=\"og:description\" content=\"Objectif Cette configuration permet de : 1. Configuration de base du routeur Nom du routeur et domaine S\u00e9curisation des mots de passe 2. Configuration des interfaces Interface WAN (Internet) Interface trunk vers le switch 3. Configuration des VLANs VLAN 10 VLAN 20 VLAN 30 VLAN 40 4. Configuration du NAT Internet ACL NAT Activation du [&hellip;]\" \/>\n<meta property=\"og:url\" content=\"https:\/\/eryann.fr\/index.php\/8021q\/fiche-configuration-dun-routeur-cisco-avec-vlan-nat-acl-et-securisation-ssh\/\" \/>\n<meta property=\"og:site_name\" content=\"Eryann Breizh SecOps\" \/>\n<meta property=\"article:published_time\" content=\"2026-05-26T18:45:48+00:00\" \/>\n<meta property=\"article:modified_time\" content=\"2026-05-26T18:48:57+00:00\" \/>\n<meta property=\"og:image\" content=\"https:\/\/eryann.fr\/wp-content\/uploads\/2026\/05\/image-14.png\" \/>\n\t<meta property=\"og:image:width\" content=\"1536\" \/>\n\t<meta property=\"og:image:height\" content=\"1024\" \/>\n\t<meta property=\"og:image:type\" content=\"image\/png\" \/>\n<meta name=\"author\" content=\"wpadmin\" \/>\n<meta name=\"twitter:card\" content=\"summary_large_image\" \/>\n<meta name=\"twitter:label1\" content=\"\u00c9crit par\" \/>\n\t<meta name=\"twitter:data1\" content=\"wpadmin\" \/>\n\t<meta name=\"twitter:label2\" content=\"Dur\u00e9e de lecture estim\u00e9e\" \/>\n\t<meta name=\"twitter:data2\" content=\"3 minutes\" \/>\n<script type=\"application\/ld+json\" class=\"yoast-schema-graph\">{\"@context\":\"https:\\\/\\\/schema.org\",\"@graph\":[{\"@type\":\"Article\",\"@id\":\"https:\\\/\\\/eryann.fr\\\/index.php\\\/8021q\\\/fiche-configuration-dun-routeur-cisco-avec-vlan-nat-acl-et-securisation-ssh\\\/#article\",\"isPartOf\":{\"@id\":\"https:\\\/\\\/eryann.fr\\\/index.php\\\/8021q\\\/fiche-configuration-dun-routeur-cisco-avec-vlan-nat-acl-et-securisation-ssh\\\/\"},\"author\":{\"name\":\"wpadmin\",\"@id\":\"https:\\\/\\\/eryann.fr\\\/#\\\/schema\\\/person\\\/d2ee98d2385cd045ed4fe1c07ca320b5\"},\"headline\":\"Fiche \u2013 Configuration d\u2019un routeur Cisco avec VLAN, NAT, ACL et s\u00e9curisation SSH\",\"datePublished\":\"2026-05-26T18:45:48+00:00\",\"dateModified\":\"2026-05-26T18:48:57+00:00\",\"mainEntityOfPage\":{\"@id\":\"https:\\\/\\\/eryann.fr\\\/index.php\\\/8021q\\\/fiche-configuration-dun-routeur-cisco-avec-vlan-nat-acl-et-securisation-ssh\\\/\"},\"wordCount\":574,\"publisher\":{\"@id\":\"https:\\\/\\\/eryann.fr\\\/#organization\"},\"image\":{\"@id\":\"https:\\\/\\\/eryann.fr\\\/index.php\\\/8021q\\\/fiche-configuration-dun-routeur-cisco-avec-vlan-nat-acl-et-securisation-ssh\\\/#primaryimage\"},\"thumbnailUrl\":\"https:\\\/\\\/eryann.fr\\\/wp-content\\\/uploads\\\/2026\\\/05\\\/image-14-1024x683.png\",\"articleSection\":[\"8021q\",\"Cisco\",\"R\u00e9seau\"],\"inLanguage\":\"fr-FR\"},{\"@type\":\"WebPage\",\"@id\":\"https:\\\/\\\/eryann.fr\\\/index.php\\\/8021q\\\/fiche-configuration-dun-routeur-cisco-avec-vlan-nat-acl-et-securisation-ssh\\\/\",\"url\":\"https:\\\/\\\/eryann.fr\\\/index.php\\\/8021q\\\/fiche-configuration-dun-routeur-cisco-avec-vlan-nat-acl-et-securisation-ssh\\\/\",\"name\":\"Fiche \u2013 Configuration d\u2019un routeur Cisco avec VLAN, NAT, ACL et s\u00e9curisation SSH - Eryann Breizh SecOps\",\"isPartOf\":{\"@id\":\"https:\\\/\\\/eryann.fr\\\/#website\"},\"primaryImageOfPage\":{\"@id\":\"https:\\\/\\\/eryann.fr\\\/index.php\\\/8021q\\\/fiche-configuration-dun-routeur-cisco-avec-vlan-nat-acl-et-securisation-ssh\\\/#primaryimage\"},\"image\":{\"@id\":\"https:\\\/\\\/eryann.fr\\\/index.php\\\/8021q\\\/fiche-configuration-dun-routeur-cisco-avec-vlan-nat-acl-et-securisation-ssh\\\/#primaryimage\"},\"thumbnailUrl\":\"https:\\\/\\\/eryann.fr\\\/wp-content\\\/uploads\\\/2026\\\/05\\\/image-14-1024x683.png\",\"datePublished\":\"2026-05-26T18:45:48+00:00\",\"dateModified\":\"2026-05-26T18:48:57+00:00\",\"breadcrumb\":{\"@id\":\"https:\\\/\\\/eryann.fr\\\/index.php\\\/8021q\\\/fiche-configuration-dun-routeur-cisco-avec-vlan-nat-acl-et-securisation-ssh\\\/#breadcrumb\"},\"inLanguage\":\"fr-FR\",\"potentialAction\":[{\"@type\":\"ReadAction\",\"target\":[\"https:\\\/\\\/eryann.fr\\\/index.php\\\/8021q\\\/fiche-configuration-dun-routeur-cisco-avec-vlan-nat-acl-et-securisation-ssh\\\/\"]}]},{\"@type\":\"ImageObject\",\"inLanguage\":\"fr-FR\",\"@id\":\"https:\\\/\\\/eryann.fr\\\/index.php\\\/8021q\\\/fiche-configuration-dun-routeur-cisco-avec-vlan-nat-acl-et-securisation-ssh\\\/#primaryimage\",\"url\":\"https:\\\/\\\/eryann.fr\\\/wp-content\\\/uploads\\\/2026\\\/05\\\/image-14.png\",\"contentUrl\":\"https:\\\/\\\/eryann.fr\\\/wp-content\\\/uploads\\\/2026\\\/05\\\/image-14.png\",\"width\":1536,\"height\":1024},{\"@type\":\"BreadcrumbList\",\"@id\":\"https:\\\/\\\/eryann.fr\\\/index.php\\\/8021q\\\/fiche-configuration-dun-routeur-cisco-avec-vlan-nat-acl-et-securisation-ssh\\\/#breadcrumb\",\"itemListElement\":[{\"@type\":\"ListItem\",\"position\":1,\"name\":\"Accueil\",\"item\":\"https:\\\/\\\/eryann.fr\\\/\"},{\"@type\":\"ListItem\",\"position\":2,\"name\":\"Fiche \u2013 Configuration d\u2019un routeur Cisco avec VLAN, NAT, ACL et s\u00e9curisation SSH\"}]},{\"@type\":\"WebSite\",\"@id\":\"https:\\\/\\\/eryann.fr\\\/#website\",\"url\":\"https:\\\/\\\/eryann.fr\\\/\",\"name\":\"Eryann Breizh SecOps\",\"description\":\"Fiches techniques &amp; labs en syst\u00e8mes et r\u00e9seaux poor les \u00e9tudiants en BTS CEIL ET SIO\",\"publisher\":{\"@id\":\"https:\\\/\\\/eryann.fr\\\/#organization\"},\"potentialAction\":[{\"@type\":\"SearchAction\",\"target\":{\"@type\":\"EntryPoint\",\"urlTemplate\":\"https:\\\/\\\/eryann.fr\\\/?s={search_term_string}\"},\"query-input\":{\"@type\":\"PropertyValueSpecification\",\"valueRequired\":true,\"valueName\":\"search_term_string\"}}],\"inLanguage\":\"fr-FR\"},{\"@type\":\"Organization\",\"@id\":\"https:\\\/\\\/eryann.fr\\\/#organization\",\"name\":\"Breizh Sec Ops\",\"url\":\"https:\\\/\\\/eryann.fr\\\/\",\"logo\":{\"@type\":\"ImageObject\",\"inLanguage\":\"fr-FR\",\"@id\":\"https:\\\/\\\/eryann.fr\\\/#\\\/schema\\\/logo\\\/image\\\/\",\"url\":\"https:\\\/\\\/eryann.fr\\\/wp-content\\\/uploads\\\/2026\\\/05\\\/cropped-088112b9-fd28-4b18-b02d-4d9dded3e900-e1777846396685.png\",\"contentUrl\":\"https:\\\/\\\/eryann.fr\\\/wp-content\\\/uploads\\\/2026\\\/05\\\/cropped-088112b9-fd28-4b18-b02d-4d9dded3e900-e1777846396685.png\",\"width\":1246,\"height\":229,\"caption\":\"Breizh Sec Ops\"},\"image\":{\"@id\":\"https:\\\/\\\/eryann.fr\\\/#\\\/schema\\\/logo\\\/image\\\/\"}},{\"@type\":\"Person\",\"@id\":\"https:\\\/\\\/eryann.fr\\\/#\\\/schema\\\/person\\\/d2ee98d2385cd045ed4fe1c07ca320b5\",\"name\":\"wpadmin\",\"image\":{\"@type\":\"ImageObject\",\"inLanguage\":\"fr-FR\",\"@id\":\"https:\\\/\\\/secure.gravatar.com\\\/avatar\\\/d71b4031c3d015de3ca68c137413277e548b331b07db0acf781b9379b798eb3e?s=96&d=mm&r=g\",\"url\":\"https:\\\/\\\/secure.gravatar.com\\\/avatar\\\/d71b4031c3d015de3ca68c137413277e548b331b07db0acf781b9379b798eb3e?s=96&d=mm&r=g\",\"contentUrl\":\"https:\\\/\\\/secure.gravatar.com\\\/avatar\\\/d71b4031c3d015de3ca68c137413277e548b331b07db0acf781b9379b798eb3e?s=96&d=mm&r=g\",\"caption\":\"wpadmin\"},\"sameAs\":[\"https:\\\/\\\/eryann.fr\"],\"url\":\"https:\\\/\\\/eryann.fr\\\/index.php\\\/author\\\/wpadmin\\\/\"}]}<\/script>\n<!-- \/ Yoast SEO plugin. -->","yoast_head_json":{"title":"Fiche \u2013 Configuration d\u2019un routeur Cisco avec VLAN, NAT, ACL et s\u00e9curisation SSH - Eryann Breizh SecOps","robots":{"index":"index","follow":"follow","max-snippet":"max-snippet:-1","max-image-preview":"max-image-preview:large","max-video-preview":"max-video-preview:-1"},"canonical":"https:\/\/eryann.fr\/index.php\/8021q\/fiche-configuration-dun-routeur-cisco-avec-vlan-nat-acl-et-securisation-ssh\/","og_locale":"fr_FR","og_type":"article","og_title":"Fiche \u2013 Configuration d\u2019un routeur Cisco avec VLAN, NAT, ACL et s\u00e9curisation SSH - Eryann Breizh SecOps","og_description":"Objectif Cette configuration permet de : 1. Configuration de base du routeur Nom du routeur et domaine S\u00e9curisation des mots de passe 2. Configuration des interfaces Interface WAN (Internet) Interface trunk vers le switch 3. Configuration des VLANs VLAN 10 VLAN 20 VLAN 30 VLAN 40 4. Configuration du NAT Internet ACL NAT Activation du [&hellip;]","og_url":"https:\/\/eryann.fr\/index.php\/8021q\/fiche-configuration-dun-routeur-cisco-avec-vlan-nat-acl-et-securisation-ssh\/","og_site_name":"Eryann Breizh SecOps","article_published_time":"2026-05-26T18:45:48+00:00","article_modified_time":"2026-05-26T18:48:57+00:00","og_image":[{"width":1536,"height":1024,"url":"https:\/\/eryann.fr\/wp-content\/uploads\/2026\/05\/image-14.png","type":"image\/png"}],"author":"wpadmin","twitter_card":"summary_large_image","twitter_misc":{"\u00c9crit par":"wpadmin","Dur\u00e9e de lecture estim\u00e9e":"3 minutes"},"schema":{"@context":"https:\/\/schema.org","@graph":[{"@type":"Article","@id":"https:\/\/eryann.fr\/index.php\/8021q\/fiche-configuration-dun-routeur-cisco-avec-vlan-nat-acl-et-securisation-ssh\/#article","isPartOf":{"@id":"https:\/\/eryann.fr\/index.php\/8021q\/fiche-configuration-dun-routeur-cisco-avec-vlan-nat-acl-et-securisation-ssh\/"},"author":{"name":"wpadmin","@id":"https:\/\/eryann.fr\/#\/schema\/person\/d2ee98d2385cd045ed4fe1c07ca320b5"},"headline":"Fiche \u2013 Configuration d\u2019un routeur Cisco avec VLAN, NAT, ACL et s\u00e9curisation SSH","datePublished":"2026-05-26T18:45:48+00:00","dateModified":"2026-05-26T18:48:57+00:00","mainEntityOfPage":{"@id":"https:\/\/eryann.fr\/index.php\/8021q\/fiche-configuration-dun-routeur-cisco-avec-vlan-nat-acl-et-securisation-ssh\/"},"wordCount":574,"publisher":{"@id":"https:\/\/eryann.fr\/#organization"},"image":{"@id":"https:\/\/eryann.fr\/index.php\/8021q\/fiche-configuration-dun-routeur-cisco-avec-vlan-nat-acl-et-securisation-ssh\/#primaryimage"},"thumbnailUrl":"https:\/\/eryann.fr\/wp-content\/uploads\/2026\/05\/image-14-1024x683.png","articleSection":["8021q","Cisco","R\u00e9seau"],"inLanguage":"fr-FR"},{"@type":"WebPage","@id":"https:\/\/eryann.fr\/index.php\/8021q\/fiche-configuration-dun-routeur-cisco-avec-vlan-nat-acl-et-securisation-ssh\/","url":"https:\/\/eryann.fr\/index.php\/8021q\/fiche-configuration-dun-routeur-cisco-avec-vlan-nat-acl-et-securisation-ssh\/","name":"Fiche \u2013 Configuration d\u2019un routeur Cisco avec VLAN, NAT, ACL et s\u00e9curisation SSH - Eryann Breizh SecOps","isPartOf":{"@id":"https:\/\/eryann.fr\/#website"},"primaryImageOfPage":{"@id":"https:\/\/eryann.fr\/index.php\/8021q\/fiche-configuration-dun-routeur-cisco-avec-vlan-nat-acl-et-securisation-ssh\/#primaryimage"},"image":{"@id":"https:\/\/eryann.fr\/index.php\/8021q\/fiche-configuration-dun-routeur-cisco-avec-vlan-nat-acl-et-securisation-ssh\/#primaryimage"},"thumbnailUrl":"https:\/\/eryann.fr\/wp-content\/uploads\/2026\/05\/image-14-1024x683.png","datePublished":"2026-05-26T18:45:48+00:00","dateModified":"2026-05-26T18:48:57+00:00","breadcrumb":{"@id":"https:\/\/eryann.fr\/index.php\/8021q\/fiche-configuration-dun-routeur-cisco-avec-vlan-nat-acl-et-securisation-ssh\/#breadcrumb"},"inLanguage":"fr-FR","potentialAction":[{"@type":"ReadAction","target":["https:\/\/eryann.fr\/index.php\/8021q\/fiche-configuration-dun-routeur-cisco-avec-vlan-nat-acl-et-securisation-ssh\/"]}]},{"@type":"ImageObject","inLanguage":"fr-FR","@id":"https:\/\/eryann.fr\/index.php\/8021q\/fiche-configuration-dun-routeur-cisco-avec-vlan-nat-acl-et-securisation-ssh\/#primaryimage","url":"https:\/\/eryann.fr\/wp-content\/uploads\/2026\/05\/image-14.png","contentUrl":"https:\/\/eryann.fr\/wp-content\/uploads\/2026\/05\/image-14.png","width":1536,"height":1024},{"@type":"BreadcrumbList","@id":"https:\/\/eryann.fr\/index.php\/8021q\/fiche-configuration-dun-routeur-cisco-avec-vlan-nat-acl-et-securisation-ssh\/#breadcrumb","itemListElement":[{"@type":"ListItem","position":1,"name":"Accueil","item":"https:\/\/eryann.fr\/"},{"@type":"ListItem","position":2,"name":"Fiche \u2013 Configuration d\u2019un routeur Cisco avec VLAN, NAT, ACL et s\u00e9curisation SSH"}]},{"@type":"WebSite","@id":"https:\/\/eryann.fr\/#website","url":"https:\/\/eryann.fr\/","name":"Eryann Breizh SecOps","description":"Fiches techniques &amp; labs en syst\u00e8mes et r\u00e9seaux poor les \u00e9tudiants en BTS CEIL ET SIO","publisher":{"@id":"https:\/\/eryann.fr\/#organization"},"potentialAction":[{"@type":"SearchAction","target":{"@type":"EntryPoint","urlTemplate":"https:\/\/eryann.fr\/?s={search_term_string}"},"query-input":{"@type":"PropertyValueSpecification","valueRequired":true,"valueName":"search_term_string"}}],"inLanguage":"fr-FR"},{"@type":"Organization","@id":"https:\/\/eryann.fr\/#organization","name":"Breizh Sec Ops","url":"https:\/\/eryann.fr\/","logo":{"@type":"ImageObject","inLanguage":"fr-FR","@id":"https:\/\/eryann.fr\/#\/schema\/logo\/image\/","url":"https:\/\/eryann.fr\/wp-content\/uploads\/2026\/05\/cropped-088112b9-fd28-4b18-b02d-4d9dded3e900-e1777846396685.png","contentUrl":"https:\/\/eryann.fr\/wp-content\/uploads\/2026\/05\/cropped-088112b9-fd28-4b18-b02d-4d9dded3e900-e1777846396685.png","width":1246,"height":229,"caption":"Breizh Sec Ops"},"image":{"@id":"https:\/\/eryann.fr\/#\/schema\/logo\/image\/"}},{"@type":"Person","@id":"https:\/\/eryann.fr\/#\/schema\/person\/d2ee98d2385cd045ed4fe1c07ca320b5","name":"wpadmin","image":{"@type":"ImageObject","inLanguage":"fr-FR","@id":"https:\/\/secure.gravatar.com\/avatar\/d71b4031c3d015de3ca68c137413277e548b331b07db0acf781b9379b798eb3e?s=96&d=mm&r=g","url":"https:\/\/secure.gravatar.com\/avatar\/d71b4031c3d015de3ca68c137413277e548b331b07db0acf781b9379b798eb3e?s=96&d=mm&r=g","contentUrl":"https:\/\/secure.gravatar.com\/avatar\/d71b4031c3d015de3ca68c137413277e548b331b07db0acf781b9379b798eb3e?s=96&d=mm&r=g","caption":"wpadmin"},"sameAs":["https:\/\/eryann.fr"],"url":"https:\/\/eryann.fr\/index.php\/author\/wpadmin\/"}]}},"_links":{"self":[{"href":"https:\/\/eryann.fr\/index.php\/wp-json\/wp\/v2\/posts\/453","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/eryann.fr\/index.php\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/eryann.fr\/index.php\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/eryann.fr\/index.php\/wp-json\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/eryann.fr\/index.php\/wp-json\/wp\/v2\/comments?post=453"}],"version-history":[{"count":2,"href":"https:\/\/eryann.fr\/index.php\/wp-json\/wp\/v2\/posts\/453\/revisions"}],"predecessor-version":[{"id":457,"href":"https:\/\/eryann.fr\/index.php\/wp-json\/wp\/v2\/posts\/453\/revisions\/457"}],"wp:attachment":[{"href":"https:\/\/eryann.fr\/index.php\/wp-json\/wp\/v2\/media?parent=453"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/eryann.fr\/index.php\/wp-json\/wp\/v2\/categories?post=453"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/eryann.fr\/index.php\/wp-json\/wp\/v2\/tags?post=453"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}