Replace ISP_2/edge routers with Library Query Station (AS 500) and implement comprehensive access control#6
Draft
Copilot wants to merge 6 commits into
Draft
Conversation
…nd ACL requirements Co-authored-by: AbooSalh <93827342+AbooSalh@users.noreply.github.com>
…on (AS 500) topology and ACL requirements Co-authored-by: AbooSalh <93827342+AbooSalh@users.noreply.github.com>
… ISP_2/edge routers Co-authored-by: AbooSalh <93827342+AbooSalh@users.noreply.github.com>
…and ACL changes Co-authored-by: AbooSalh <93827342+AbooSalh@users.noreply.github.com>
Copilot
AI
changed the title
[WIP] Update presentation.md with network changes and ACL configurations
Replace ISP_2/edge routers with Library Query Station (AS 500) and implement VLAN30-only access control
Dec 20, 2025
Collaborator
|
@copilot also i have denied that any one cannot accessing the library servers vlan 31 192.168.30.64/27 |
…n and Library PCs allowed Co-authored-by: AbooSalh <93827342+AbooSalh@users.noreply.github.com>
Contributor
Author
Added comprehensive Library Server Protection ACL for VLAN 31 (192.168.30.64/27). The ACL now denies all networks from accessing library servers except Admin Building and Library PCs (VLAN 30). Implementation: Applied to Router-C VLAN 31 interface (inbound). Result:
Updated in commit 1d82a3c |
Copilot
AI
changed the title
Replace ISP_2/edge routers with Library Query Station (AS 500) and implement VLAN30-only access control
Replace ISP_2/edge routers with Library Query Station (AS 500) and implement comprehensive access control
Dec 20, 2025
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Network topology updated to replace generic ISP_2/edge routing segment with a purpose-built Library Query Station (AS 500) that enforces strict access control—allowing only VLAN30 (library PCs) access and denying all other campus networks including guest WiFi. Additionally implements comprehensive server protection for VLAN31 (library servers).
Architecture Changes
Access Control Lists
Query Station Isolation
Applied at Library Building Router BGP interface:
Library Server Protection (VLAN 31) - NEW
Comprehensive protection for library servers (192.168.30.64/27), applied at Router-C VLAN 31 interface:
Result:
Guest WiFi Enhancement
Block Query Station networks from Guest WiFi:
Routing Protocol Updates
Files Modified
PRESENTATION.md- All 16 slides updated with Query Station topology, ACLs (including server protection), budget ($300,150)Smart_Campus_Network_Design_Report.md- Topology diagrams, routing configs, comprehensive ACL policies including server protection, BoMREADME.md- Architecture overview, routing protocols, security policies with server protectionTOPOLOGY_UPDATE_SUMMARY.md- Component changes, BGP/EIGRP configs, IP addressing tables, ACL implementationsOriginal prompt
💬 We'd love your input! Share your thoughts on Copilot coding agent in our 2 minute survey.