- 积分
- 304
- 鸿鹄币
- 个
- 好评度
- 点
- 精华
- 最后登录
- 1970-1-1
- 阅读权限
- 30
- 听众
- 收听
初级工程师
  
|
准备了快一年(当然不是每天都在看),现总算告一段落了,但就如电影里常说“战斗才刚刚开始。能顺利通过考试,得力于客服5的耐心和热情,非常感谢。事实证明,自学NP也是可以的,只是多了寂寞和枯燥,还有中途放弃和前进间的挣扎,总是在深夜让思绪悠长地延伸到远方···只有自己才知道真正想要的是什么。好了,结束废话直接正题:
" q1 \, G8 u- o$ M" Z 单纯的正对考试而言。和前人发的战报一样,TT中的HRSP/EIGRP AS/DHCP没考到,其他都有。不管怎么都得要先知道错点在哪里。前人战报太经典,一下为本人平时学习题库和实验并联系答案的缩略标记。~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
8 u, A+ @9 Y2 G- |1.client 1 is able to ping 10.1.1.2 but not 10.1.1.1. R1 does not have any ospf neighbors or any ospf routes# b9 m2 ?; R! o; F" T2 ~& j
->R1->ipv4 ospf routing->useing the ip ospf authentication messagedigest Q. k# J6 R' q/ }
2.HSPR+ J7 D9 q- ?2 G+ q5 m
->DSW1->HSRP->standby 10 should track 10 not 15 t4 Y3 f+ C- s( c
3.client 1 is able to ping 209.65.200.226 but not the web server, R1 does not have any BGP neighbors or routes.
# V L5 |( {. `->R1->BGP-> neighbor's network wrong9 E' B# W0 _9 n o) W
4.clients are not able to reach the web server and all the routers are able reach the web serber.
; `, s; Z8 O5 {! I$ {- E* n: V->R1->IP NAT->ip access-list standar nat_trafic enter the permit 10.2.0.0 0.0.255.255
7 _ a9 C7 k1 t. }- ~( ?5.R1 is not able to reach the web server,and R1 does not have any active BGP neighbors
+ @( w* T. S! b' x->R1->IPv4 layer 3 security->add the permit ip 209.65.200.241 0.0.0.3 any) `3 d: n9 K. U( n) x
6.client 1 is getting an IP address from the DHCP server but is not able to ping DSW1 or the FTP server.
( G- {+ @, c$ B H3 q4 O->DSW1->vlan acl/port acl->enter no vlan filter test1 vlan-list 10( l! t: V% k7 Q; T
7.port security5 `* Q" M0 W1 M2 V. k" u' O
8.port vlan% Z; I% W* p0 x& F4 R
9.port trunk
3 N4 S4 t0 @" n R+ _) L' m10.client can not ping 10.1.4.5, DSW1 can ping the Fa0/1 interface of R4 but not the s0/0/0/0.34 interface
4 P( G; \3 l' C: @+ i->R4->IPv4 EIGRP Routing->fault as number
3 N; Y+ u% ]+ V5 H" D11.client can ping 10.1.4.5, DSW1 can ping the Fa0/1 interface of R4 but not the s0/0/0/0.34 interface
/ ^ Y D# Q4 q9 z- L+ z->R4->ipv4 route redistribution->delete the redistribute ospf 1 router-map `````.....````.....' w3 r- v& @# ^) x' k7 j5 I* U: H
12.client can not gei ip address 1 k& j8 L I& f
->R4->DHCP->ip dhcp excluded-address fault
" X# \; e. N6 I+ x7 x# V7 T13.the neighborship between R4 and DSW1 wasn't establised.client 1can't ping R4
1 T- i( B: d; j: J2 k->R4->IPv4 EIGRP Routing->Remove "passive interface" in interface f0/1 and f0/0$ G2 M& m0 R( n3 @$ _! u
14.IPv6 ospf, F6 z* U; O9 s
->R2->ipv6 routing-> add ipv6 ospf 6 area 0
; S) P N/ I1 J/ I h# e W15.IPv6 redistribution1 ^. Y c1 ?. S+ i6 l- e$ N, ]
->R4->IPv6 ospf routing->enter the redistribute rip RIP_ZONE include-connected1 ]( b6 Z4 d% D2 { R( }
16.IPv6 Tunnel
* A" o+ z+ |1 v/ p- o->R3->ipv6 and ipv4 interoperability->delete the tunnel mode ipv6! o. y3 K" G6 \( Z5 J9 ]* V3 j
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
L+ P+ U+ l4 C4 i* Q$ x1.先查看题目,是判断出是考IPv4还是IPV6,如果标识有IPv6的地址,如2026::1:1等就是IPv6题目了,总共只有三个类型,直接show run就可以很快找到答案。
0 z3 p# {) i- ^% w$ _2.我采取的是先ping远端设备再近端的方法。ping 209.65.200.241题目明确标明client端ping不通的,所以没必要再ping了。能ping10.1.1.1不能ping209.65.200.226,有两种可能,IP NAT和R1 ACL。0 r0 h8 l. ^$ V6 i, k, j) B
1)其他设备上都能ping209.65.200.241 那一定是IP NAT,再show run 确定在ip access-list standard Nat_Traffic下是否缺少permit 10.2.0.0 0.0.255.255。! F$ x# Q( s; [$ E
2)其他设备上不能ping209.65.200.241 只有R1能ping209.65.200.226那就是是R1 ACL这题了,再show run 确定一下edge_security。4 I# ]( R6 I' y& ?
3.client能ping209.65.200.226,那再在R1show ip bgp nei 没有邻居,就是BGP这题了。 C8 b: R9 d. e: L1 s
4.client不能ping 10.1.1.1 但是能ping10.1.1.2,多半是ospf authentication这题,在R1上 show ip ospf neighbors确认没有条目,那就没错了,题库的对比方法就如试友所说一样,不可取的。' v; H. Z9 p7 g
5.如果ping10.1.1.2不通,那问题点在R4到ASW1之间,如果ping网关10.2.1.254不通,问题在ASW1上和DSW1上,直接show run查看吧。
9 Q4 z5 e$ ]* ?1)如果在Interface FastEthernet1/0/1-2 上有MAC地址,如 0000.0000.0001等,就是switchport security了。
7 y, u* I- q0 @9 a2)如果在Interface FastEthernet1/0/1-2没有access vlan 10,那就是access vlan这题了。0 u: X) h4 ^' X& b! M
3)如果是在Interface PortChannel13 和Interface PortChannel23上allow 的vlan 不是10和200,那就是switchport trunk了。
' O& s7 t" ?; M+ X4)在DSW1上show run 如果有vlan filter test1 vlan-list10 那就是vlan filter这题了。6 b; G. r5 N4 c! E& g& C
6.能ping网关,问题点在R4上。show run吧,IPv4只有两个错误。
) h; _( s" r. z9 j( P% g1)在vlan 10下如果有passive-interface default,client是ping不通R4 10.1.4.5 并且在R4上没有EIGRP neighbors,EIGRP passive-interface。
% s& C; `2 a, s; s2)剩下的就是在router eigrp下redistribute的 route-map匹配错误了,client是能ping通R4 10.1.4.5的,但不能继续往下ping, EIGRPredistribute 。* N* }9 }. K( G. k& [
7.IPv61 Q1 I# }; K1 v+ z/ j
1)R2上 show run 查看连接R3的接口interfaces0/0/0/0.23缺少 ipv6 ospf 6 area 0 ,IPv6 OSPF这题了。
: j5 ?7 V# F( M2)R3上show run 是否多了条tunnel mode ipv6的命令,这是IPv4 and IPv6 互操作问题。$ C2 m5 v0 W c, c% H$ u) M
3)R4上show run 在ipv6 router ospf 6 下缺少redistribute rip RIP_ZONE include-connected命令,就是IPv6 redistribute这题 。
. F6 C6 z* P8 J& F0 U; l考试的时候我是这样标记的: { x- ^" |4 Y$ T
R1:ospf authentication
) X9 U* e% b" A0 t IP NAT" L# H4 k( k& W& \
edge_security
) \& F6 ^3 Y$ J" W/ I0 B BGP0 y& ?$ f" @/ r- B
R2:IPv6 OSPF. `, w7 X+ a3 Y( m8 P# c$ C! ^
R3:Tunnel& _) k9 d+ C" n! w
R4:EIGRP RED; L; U; k; K" m- \; U
IPv6 RED! n0 w1 M, q6 y2 B' }) S/ y
passive-interface
3 }7 E6 E6 v9 T; ]; E( t; J% T, p* BDSW1:vlan filter
" n+ l8 K C( Q# Z; \- i1 ]8 RASW1:port security: \- N5 J; y; u6 H6 P/ n7 ^
access vlan/ [9 A3 _& F1 W P, n
port trunk0 f1 P9 P/ {& D- A4 {7 o; r
刚好13题,每个人有自己的助忆方法,怎样使自己方便的就是好方法,希望对即将考试的 朋友们有点用处。* A: J( ?6 x) k' j0 }1 p
当个敲门砖而已,其他的都是浮云!!路漫漫其修远兮,。考,做最充分的准备,做最坏的打算,相信自己!题库很稳。. B$ [1 o: {8 M9 G" C, h
推荐两个经典战报经验,感谢他们的分享。2 a' H* m2 f& a5 e5 M& a0 |, S! S# v
http://bbs.hh010.com/forum.php?mod=viewthread&tid=430807
5 w3 W( j6 w5 P; u- L1 ~# shttp://bbs.hh010.com/forum.php?mod=viewthread&tid=431713&extra=page%3D1 http://bbs.hh010.com/forum.php?m ... &extra=page%3D2
8 M# O$ d% ?6 B1 b' N, r: |: |
4 d( P ?% m( {/ ?6 @( D. F5 k: S3 `
7 @9 P3 ?' h* _: m/ C' w+ ` |
评分
-
查看全部评分
|