本帖最后由 scorpio920204 于 2018-1-29 13:28 编辑 1 z% k) \( i, S. u# s0 U- F( m
1 C5 C( H+ \2 R6 p# e8 j' K( e題庫很穩一點小變化5 ~% A% p' h/ x! {& @* y+ P2 g- L) `2 t
" L6 ~; O( o! n& q# oNAT Inside) {3 X0 p( }2 ~
ip nat inside source list nat_pool interface s0/0/1 overload ip access-list standard nat_pool
: h! p) T7 z; x permit 10.1.0.0
3 z* J$ ?1 e; o7 K1 O permit 10.2.0.09 N, r; `! p' u$ {+ j
!
1 U3 J, M" q' O! D0 h6 T5 b interface Serial0/0/1
@' D5 K2 C! T6 m* ?8 m n ip address 209.65.200.225 255.255.255.2526 `" }# C' k% ^
ip nat inside
# D' k. E- z, n* n- h* ] !! j' n1 i$ [' C" x( X+ e v
interface Serial0/0/0.120 X: ?6 ?6 R( @/ W, v
ip address 10.1.1.1 255.255.255.252
. V' e0 A( K, D2 }& O ip nat inside4 d4 Z2 h' J. f
ip ospf message-digest-key 1 md5 TSHOOT; `0 s2 `' }- J; R! l
ip ospf authentication message-digest . F( r0 {; `" S7 s& W; \$ @
Ans1) R1
/ c7 i9 f& P; N- }# b0 n t1 I8 e# C Ans2) NAT: r# e4 f8 W- C- K6 _' Q: d
Ans3) Under interface Serial0/0/1 add the “ip nat outside” command.
* D5 \) a( g* _$ U: _
Switchport VLAN 10 Configuration of ASW1
4 ~: J( z( @% s- n interface FastEthernet1/0/1
, h# `3 y8 @5 [: G" K; p; U9 D* Z switchport access vlan 10: Q9 D. R3 E7 d6 F. F( P
switchport trunk encapsulation dot1q
( R- G+ U' y; R switchport mode trunk
8 u$ ]* L- V0 K4 J! \) N !
6 c: s: Q8 B# q$ ` interface FastEthernet1/0/26 \5 O; Z! n% F9 ^% Q; p
switchport access vlan 10
# V7 E0 p* `& f switchport trunk encapsulation dot1q! b4 v4 {( |* G4 t* [/ L
switchport mode trunk* C. G, ^5 x+ @' y1 w
!
0 V& S' z* }% v9 J# I. q VAnswer: Ans1) ASW1$ l9 Y8 f! M" ~4 }: S6 E. n6 w( F
Ans2) Access Vlans
' h6 L. g- ?: v! |/ s Ans3) In Configuration mode, using the ‘interface range Fastethernet 1/0/1 – 2’, then ‘switchport mode access’, ‘no switchport trunk encapsulation dot1q’ commands. . X& D2 k [+ b8 L( G
Redistribution Route-map On R4:1 _" m1 t3 }% \
router eigrp 10: S/ [4 @- b, ~5 k# o0 W
redistribute ospf 1 route-map OSPF->EIGRP, a7 X/ W4 C4 E- Y, D/ Q) X& k. N+ H
network 10.1.4.0 0.0.0.255* y, s/ P" k% ^3 c4 d3 U
network 10.1.10.0 0.0.0.255
7 J7 b/ H% N0 K2 I2 ~% O network 10.1.21.128 0.0.0.3; l' V: w y8 F& Q6 _' Z& R u% X% i
default-metric 100000 100 100 1 1500; f& |# r1 O% ]7 K, m. e7 t
no auto-summary( L# p/ z3 y {' @8 r$ ^
! route-map OSPF->EIGRP deny 108 d6 x3 I- v# U; Y4 X2 }
match tag 90
& n6 D1 C$ @6 m( ~3 ^ route-map OSPF->EIGRP deny 201 d. \1 _- @& k: O$ f
set tag 110 2 A7 y) G+ G% _! x
Ans1) R4# u$ @! H+ u; z" U4 s
Ans2) IPv4 Route Redistribution
3 K* F+ B/ r2 D4 E: H( c8 m Ans3) Change the “route-map OSPF->EIGRP deny 20” to “route-map OSPF->EIGRP permit 20”
9 k8 l- u" z8 ]' n1 v
IPv6就用R3 show ipv6 ospf neig
7 m( `! {- m$ ^9 B& F( f
可以參考考 4 v" r6 [/ ]" @! h; x" d
對於剛要開始讀的新同學 要把答案給背起來,差不多就完成了一半, 我自己的背法給同學參考一下
' b7 M+ R4 X! F: M/ d* X10.1.1.1 可以ping 通 v4 layer 3 security -- R1 -- permit 209.65.200.224 any -- show run IP NAT -- R1 -- S 0/0/1 ip nat outside -- show ip nat statist : f/ L9 w8 g8 o& j* d
10.1.1.2 可以ping 通 v4 OSPF router -- R1 -- S 0/0/0 IP OSPF Auth messag -- show ip ospf neig 無2.2.2.2鄰居
) Y' W' e) M. I; n& C* X
10.2.1.254 可以ping 通 v4 router redisbribu -- R4 -- router-map OSPF->EIGRP diny 20 permit 20 -- show ip eigrp neig 有鄰居, 客戶1 ping 到10.1.4.5 v4 EIGRP router -- R4 -- E 0/0 E0/1 NO pass-int -- EIGRP 10 有pass-int default ,show ip eigrp neig 無鄰居
* Y+ Y8 q1 k: A% `9 e
10.2.1.254 ping 不通 VLAN ACL / P A -- DSW -- NO vlan filter -- show run Access V -- ASW -- swpo mode acc , NO swpo trunk en do -- 看Fa 1/0/1 - 2 Sw to Sw Conn -- ASW -- port-channel 13/23 , swpo trunk all V 10.200 -- sh ip int bri 接PC被shut IP DHCP Helper -- DSW -- delete 10.2.21.129 , add 10.1.21.129 -- 看VLAN 10
) [% f% ^: \- i
IPv6看題目就可以看的出來, 不放心可以Ping 209.65.200.241 在R3上show ipv6 ospf neig 看鄰居狀況, 千萬不要手快打成show ip ospf neig 鄰居狀況是不一樣的,一開始我犯的錯 v6 OSPF router -- R2 -- S 0/0/0 23 IPv6 OSPF 6 area 0 -- 看S 0/0/0 23 無, 有R4 v6 OSPF router -- R4 -- redistribu rip RIP_ZO -- 看ospf 6 無, 有R2/R4 v4 and v6 interoper -- R3 -- delete tunnel mode IPv6 -- 看Tunnel34 多了, 有R2 還是以自己看的懂為主~~但答案最好要背起來 4 A: P4 E- y3 M2 }& Q0 M. d' O8 ] ^
|