本帖最后由 scorpio920204 于 2018-1-29 13:28 编辑 , C) |$ H2 ~ k$ v7 i
- ?7 _9 k$ _( N) d題庫很穩一點小變化 t$ O& o) `6 l# ]( b) I1 }
$ ?: J% w2 t" D: H7 |: h$ WNAT Inside
* V9 Y5 f6 c3 C% \# P- s' tip nat inside source list nat_pool interface s0/0/1 overload ip access-list standard nat_pool
: e! |* i7 n* {$ W permit 10.1.0.0
& `1 ^5 W4 g; {8 ^4 b permit 10.2.0.0) t4 e- w( T# E5 Z" M
!
8 |( ^+ r& i l ]! N! q! D interface Serial0/0/1
+ ?, H4 S, g$ r; L* k ip address 209.65.200.225 255.255.255.252! }" m+ K, {$ i' ^6 N- I
ip nat inside
+ g2 d( q- o1 N- |3 \ !% }7 {$ X" C0 X- _4 Q0 o2 `2 o3 p* q/ q
interface Serial0/0/0.12
1 w# p4 s1 o& R! z. {1 J ip address 10.1.1.1 255.255.255.252
0 c& V- j6 `8 p ip nat inside8 L% z1 K% N1 D8 u5 \% B, q
ip ospf message-digest-key 1 md5 TSHOOT4 F. D: k: e% X) R+ o( D' p
ip ospf authentication message-digest 4 J$ r/ ~4 j0 @4 u0 J8 G; C- w# ]
Ans1) R18 B" J5 J# m5 D. ?: N/ B. _- y+ P+ Z, G
Ans2) NAT6 P+ o- q+ Z9 V
Ans3) Under interface Serial0/0/1 add the “ip nat outside” command. , N0 Q9 y& B& Z, `$ c6 h
Switchport VLAN 10 Configuration of ASW1% v. S7 ~- ~4 R6 V) K0 u
interface FastEthernet1/0/1
. a$ r/ h2 G9 U- }% y! o+ I* S switchport access vlan 10
6 @! J4 z x- F$ _ switchport trunk encapsulation dot1q
7 h' G$ j ?: H& S switchport mode trunk
$ d6 y1 t; g3 Q0 E1 D& s !! o: r# ~" u' t z# f; ^
interface FastEthernet1/0/2( S: g5 L" K2 i& d. N- g
switchport access vlan 10* ]* E( S: H8 j" `6 y; S
switchport trunk encapsulation dot1q
* q4 L6 X" |8 V% b4 a2 f switchport mode trunk
! w6 r5 N# N0 H: g !
8 ~; f% w$ V" \! |: L) c( s" ~8 f: }Answer: Ans1) ASW1" U( ] E# l+ A. b
Ans2) Access Vlans0 L" _( F3 c" _: R; H5 K+ I: N
Ans3) In Configuration mode, using the ‘interface range Fastethernet 1/0/1 – 2’, then ‘switchport mode access’, ‘no switchport trunk encapsulation dot1q’ commands.
6 ^$ ~! T' y- y. d- [; I& n( D
Redistribution Route-map On R4:( E# c$ z# C1 c2 a: e
router eigrp 10
9 A+ t, J9 r% ~ N4 Y1 l redistribute ospf 1 route-map OSPF->EIGRP4 \4 ?' U, ?! H7 Y" z
network 10.1.4.0 0.0.0.255. A) ~# p9 B. \1 C3 f1 a2 D! N
network 10.1.10.0 0.0.0.255: a- o1 x# k X M
network 10.1.21.128 0.0.0.3/ S( ^& T5 X9 N- y+ M Z
default-metric 100000 100 100 1 1500: D* w S$ t7 Q! e7 P# X% a
no auto-summary
. j2 T7 J: E& n: T ! route-map OSPF->EIGRP deny 10
% A8 M, g7 x) s! S match tag 90$ h. v7 A2 `) E# J& g2 y
route-map OSPF->EIGRP deny 20- P$ V" ?+ S/ o; m6 e
set tag 110 - I+ C. x2 j6 b3 ]" X
Ans1) R46 D& T1 O2 e, e3 K6 h, ^
Ans2) IPv4 Route Redistribution
5 m, }9 T' E! s1 G0 ^- n6 E Ans3) Change the “route-map OSPF->EIGRP deny 20” to “route-map OSPF->EIGRP permit 20” 6 o4 X5 q% A; [" ?9 z
IPv6就用R3 show ipv6 ospf neig
" P2 b2 a9 U1 N+ D# W( W
可以參考考 % D1 }4 f0 F( V2 }2 I! S
對於剛要開始讀的新同學 要把答案給背起來,差不多就完成了一半, 我自己的背法給同學參考一下 . |* W: |" X1 Z0 f
10.1.1.1 可以ping 通 v4 layer 3 security -- R1 -- permit 209.65.200.224 any -- show run IP NAT -- R1 -- S 0/0/1 ip nat outside -- show ip nat statist 4 A! e' M4 ?1 j$ S* q* ?# N: M
10.1.1.2 可以ping 通 v4 OSPF router -- R1 -- S 0/0/0 IP OSPF Auth messag -- show ip ospf neig 無2.2.2.2鄰居 + h# Y/ O9 q+ E6 {" w8 R
10.2.1.254 可以ping 通 v4 router redisbribu -- R4 -- router-map OSPF->EIGRP diny 20 permit 20 -- show ip eigrp neig 有鄰居, 客戶1 ping 到10.1.4.5 v4 EIGRP router -- R4 -- E 0/0 E0/1 NO pass-int -- EIGRP 10 有pass-int default ,show ip eigrp neig 無鄰居
! i0 f' e+ D- Y: m" a( w
10.2.1.254 ping 不通 VLAN ACL / P A -- DSW -- NO vlan filter -- show run Access V -- ASW -- swpo mode acc , NO swpo trunk en do -- 看Fa 1/0/1 - 2 Sw to Sw Conn -- ASW -- port-channel 13/23 , swpo trunk all V 10.200 -- sh ip int bri 接PC被shut IP DHCP Helper -- DSW -- delete 10.2.21.129 , add 10.1.21.129 -- 看VLAN 10 ) _# S! i) H2 ?; h6 f" W! a% S6 J
IPv6看題目就可以看的出來, 不放心可以Ping 209.65.200.241 在R3上show ipv6 ospf neig 看鄰居狀況, 千萬不要手快打成show ip ospf neig 鄰居狀況是不一樣的,一開始我犯的錯 v6 OSPF router -- R2 -- S 0/0/0 23 IPv6 OSPF 6 area 0 -- 看S 0/0/0 23 無, 有R4 v6 OSPF router -- R4 -- redistribu rip RIP_ZO -- 看ospf 6 無, 有R2/R4 v4 and v6 interoper -- R3 -- delete tunnel mode IPv6 -- 看Tunnel34 多了, 有R2 還是以自己看的懂為主~~但答案最好要背起來
( ] Y0 O) j/ k s. v! W |