本帖最后由 scorpio920204 于 2018-1-29 13:28 编辑
2 f0 ~+ U" Q2 Q
& Y# i3 @4 e8 X- T. Q) }題庫很穩一點小變化
! X$ P; U8 @% r' W- Z7 T7 Y
2 O5 i; H/ ^! d# b; u5 x* W- PNAT Inside& y( x: q7 r5 h$ V+ Z0 V
ip nat inside source list nat_pool interface s0/0/1 overload ip access-list standard nat_pool) |: P; k& T2 S& W. @
permit 10.1.0.09 @6 X1 u! J! |) _
permit 10.2.0.0" H3 n7 b- T0 u* u q
!
% G0 _) x: b) V5 ~5 V" y interface Serial0/0/1% H1 n& H' ~/ V1 }# z% B
ip address 209.65.200.225 255.255.255.252
7 R& K& r& A2 b9 E* G ip nat inside
+ p0 z: x- }. k !3 E; w9 U0 |4 }, t8 k G
interface Serial0/0/0.125 B( e w- L1 Y5 ^4 a0 N
ip address 10.1.1.1 255.255.255.2528 U- |. u! @! f* [
ip nat inside5 p" f, p+ y+ B( j+ x
ip ospf message-digest-key 1 md5 TSHOOT
) ]4 k- m& F5 a- W" z ip ospf authentication message-digest
! s, V! Q/ H9 A- T
Ans1) R1
; ?' e1 i7 m: e! u; D Ans2) NAT
8 R" X( t& \8 k3 k( v7 w/ u Ans3) Under interface Serial0/0/1 add the “ip nat outside” command.
* z; C4 }9 x" K' q
Switchport VLAN 10 Configuration of ASW1
% {9 `; D, V! m2 Z, b4 |2 Z' S$ \ interface FastEthernet1/0/1+ Y% L8 b6 q0 p2 }
switchport access vlan 10$ n5 F* q- d( Q6 d) R( D9 `& M
switchport trunk encapsulation dot1q
3 h0 w/ P, i& Q- s. h% ]5 z switchport mode trunk
: |# L0 A* S0 H n6 t9 _6 L. `" K !
4 V* W% q9 x% p% l7 K4 X: i6 E interface FastEthernet1/0/2% c9 f8 S) Q% i# U
switchport access vlan 10
) }) v" y9 n( ^% ?8 o) q switchport trunk encapsulation dot1q u/ q' {2 ] ]
switchport mode trunk
2 z! p, ^2 S2 H" ~8 h7 w" w !
; H3 i/ {$ C5 _' z) F: ]2 m7 C1 EAnswer: Ans1) ASW15 u' H5 {6 g1 V9 c. M
Ans2) Access Vlans
6 N# T0 a; a6 q0 } s Ans3) In Configuration mode, using the ‘interface range Fastethernet 1/0/1 – 2’, then ‘switchport mode access’, ‘no switchport trunk encapsulation dot1q’ commands.
6 p+ [$ ^; X; X0 q, B0 X9 |
Redistribution Route-map On R4:
) p" E- H8 l" l8 F* g3 Q router eigrp 10
+ O* s# ^1 U( [' Z9 Q5 P8 v redistribute ospf 1 route-map OSPF->EIGRP
. i) b( o" y$ ~( }: O/ E network 10.1.4.0 0.0.0.255) y- d+ H+ [; J0 o" F5 C. q
network 10.1.10.0 0.0.0.255/ u- q% R* E" {* h, ^7 t& q" g& u. o
network 10.1.21.128 0.0.0.3$ v5 _& K- v# X3 m* N! M4 ~ P
default-metric 100000 100 100 1 1500
: X6 l9 G3 J* y M, B/ Z no auto-summary
2 z& F; r" b5 t ! route-map OSPF->EIGRP deny 104 U$ q1 Y% c/ D$ K
match tag 906 I8 j. m# N2 G8 j% ~
route-map OSPF->EIGRP deny 206 B3 f g: c+ h q1 e, P. K8 Z
set tag 110
- m$ s u3 X. |' {# t( G: jAns1) R4
$ W& }# l \! r B$ I Ans2) IPv4 Route Redistribution
4 P, Q3 y8 Q4 x( Y- h) S: N- k" i Ans3) Change the “route-map OSPF->EIGRP deny 20” to “route-map OSPF->EIGRP permit 20”
7 z* h8 h5 J; x) X# z! I
IPv6就用R3 show ipv6 ospf neig
$ t0 F+ z3 @- y+ k3 J2 I% @
可以參考考 / |0 M5 [% l" S3 T* \( E1 j
對於剛要開始讀的新同學 要把答案給背起來,差不多就完成了一半, 我自己的背法給同學參考一下
$ ]# V0 o$ B8 r0 K10.1.1.1 可以ping 通 v4 layer 3 security -- R1 -- permit 209.65.200.224 any -- show run IP NAT -- R1 -- S 0/0/1 ip nat outside -- show ip nat statist $ Q1 G% q9 {( c6 P
10.1.1.2 可以ping 通 v4 OSPF router -- R1 -- S 0/0/0 IP OSPF Auth messag -- show ip ospf neig 無2.2.2.2鄰居
* r [" k: o' w, q
10.2.1.254 可以ping 通 v4 router redisbribu -- R4 -- router-map OSPF->EIGRP diny 20 permit 20 -- show ip eigrp neig 有鄰居, 客戶1 ping 到10.1.4.5 v4 EIGRP router -- R4 -- E 0/0 E0/1 NO pass-int -- EIGRP 10 有pass-int default ,show ip eigrp neig 無鄰居 ! z0 U, I3 d6 \- X2 ~* P V
10.2.1.254 ping 不通 VLAN ACL / P A -- DSW -- NO vlan filter -- show run Access V -- ASW -- swpo mode acc , NO swpo trunk en do -- 看Fa 1/0/1 - 2 Sw to Sw Conn -- ASW -- port-channel 13/23 , swpo trunk all V 10.200 -- sh ip int bri 接PC被shut IP DHCP Helper -- DSW -- delete 10.2.21.129 , add 10.1.21.129 -- 看VLAN 10 8 |' l' P$ H% W: S
IPv6看題目就可以看的出來, 不放心可以Ping 209.65.200.241 在R3上show ipv6 ospf neig 看鄰居狀況, 千萬不要手快打成show ip ospf neig 鄰居狀況是不一樣的,一開始我犯的錯 v6 OSPF router -- R2 -- S 0/0/0 23 IPv6 OSPF 6 area 0 -- 看S 0/0/0 23 無, 有R4 v6 OSPF router -- R4 -- redistribu rip RIP_ZO -- 看ospf 6 無, 有R2/R4 v4 and v6 interoper -- R3 -- delete tunnel mode IPv6 -- 看Tunnel34 多了, 有R2 還是以自己看的懂為主~~但答案最好要背起來
' ~; F2 d/ K! g. b9 v5 V0 \ |