- 积分
- 304
- 鸿鹄币
- 个
- 好评度
- 点
- 精华
- 注册时间
- 2012-9-3
- 最后登录
- 1970-1-1
- 阅读权限
- 30
- 听众
- 收听
初级工程师
|
准备了快一年(当然不是每天都在看),现总算告一段落了,但就如电影里常说“战斗才刚刚开始。能顺利通过考试,得力于客服5的耐心和热情,非常感谢。事实证明,自学NP也是可以的,只是多了寂寞和枯燥,还有中途放弃和前进间的挣扎,总是在深夜让思绪悠长地延伸到远方···只有自己才知道真正想要的是什么。好了,结束废话直接正题:# k8 `9 O% ?7 g* [; Z% u
单纯的正对考试而言。和前人发的战报一样,TT中的HRSP/EIGRP AS/DHCP没考到,其他都有。不管怎么都得要先知道错点在哪里。前人战报太经典,一下为本人平时学习题库和实验并联系答案的缩略标记。~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
' a) L; i' f) p: G8 z( p9 F& ?1.client 1 is able to ping 10.1.1.2 but not 10.1.1.1. R1 does not have any ospf neighbors or any ospf routes
4 j; [6 e0 R/ p# |; i$ ~->R1->ipv4 ospf routing->useing the ip ospf authentication messagedigest3 J( M* k$ z1 `5 }
2.HSPR4 k+ x! r8 B2 W* R! ]; U
->DSW1->HSRP->standby 10 should track 10 not 1
) `' Q, l0 M o7 J8 c: w3.client 1 is able to ping 209.65.200.226 but not the web server, R1 does not have any BGP neighbors or routes.
. I: _% K0 A: x3 k->R1->BGP-> neighbor's network wrong- C- r4 A7 [6 [) h$ h. a
4.clients are not able to reach the web server and all the routers are able reach the web serber.
9 c7 D2 H' w0 Y: a+ q4 d6 L5 |5 u0 i->R1->IP NAT->ip access-list standar nat_trafic enter the permit 10.2.0.0 0.0.255.255
1 z. a. F3 R0 D' Z, T F' Y5.R1 is not able to reach the web server,and R1 does not have any active BGP neighbors: e3 s* s- z: I. v% G, b
->R1->IPv4 layer 3 security->add the permit ip 209.65.200.241 0.0.0.3 any' K: e8 c: a: G: C; `0 ?# l
6.client 1 is getting an IP address from the DHCP server but is not able to ping DSW1 or the FTP server. l+ Y! P! I1 [& z3 h
->DSW1->vlan acl/port acl->enter no vlan filter test1 vlan-list 10% X6 o, H/ n b# Z; ~; {' K
7.port security
& o+ f" t5 s: H1 e# v! a9 j8.port vlan z2 P7 A M4 A/ F5 b1 X1 Z$ w3 u
9.port trunk1 l4 W- k" A5 s7 @6 f/ `! t
10.client can not ping 10.1.4.5, DSW1 can ping the Fa0/1 interface of R4 but not the s0/0/0/0.34 interface
) @* ~, z% L, n, @/ @7 j->R4->IPv4 EIGRP Routing->fault as number
! L# d+ l: M4 }& v11.client can ping 10.1.4.5, DSW1 can ping the Fa0/1 interface of R4 but not the s0/0/0/0.34 interface
; G: W6 H7 o/ z% W->R4->ipv4 route redistribution->delete the redistribute ospf 1 router-map `````.....````.....
) L" Q$ q1 j T% i% [ e. {7 m12.client can not gei ip address
F4 E8 ~0 R& R6 H8 i/ f. y->R4->DHCP->ip dhcp excluded-address fault
) t" k; X: D. K5 s: r13.the neighborship between R4 and DSW1 wasn't establised.client 1can't ping R4
1 h& x+ }5 s9 S& L/ j d->R4->IPv4 EIGRP Routing->Remove "passive interface" in interface f0/1 and f0/0; U# L' m% A: Y, [& T- t: R
14.IPv6 ospf
3 L" x6 Y: q+ b: P5 X# P! i->R2->ipv6 routing-> add ipv6 ospf 6 area 0
) x) H6 A' E( p. h# `9 T4 [15.IPv6 redistribution
/ t* R0 v+ T! p& Z6 X->R4->IPv6 ospf routing->enter the redistribute rip RIP_ZONE include-connected
, c" x2 s4 ~6 r* W' L0 C" I6 G& f16.IPv6 Tunnel
" i, V5 Z1 _# X( [' F->R3->ipv6 and ipv4 interoperability->delete the tunnel mode ipv6& t; D4 P- K7 _2 n0 e
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~* o6 D9 l, m/ D( p
1.先查看题目,是判断出是考IPv4还是IPV6,如果标识有IPv6的地址,如2026::1:1等就是IPv6题目了,总共只有三个类型,直接show run就可以很快找到答案。
2 W+ ?6 `5 J0 u4 M! F2.我采取的是先ping远端设备再近端的方法。ping 209.65.200.241题目明确标明client端ping不通的,所以没必要再ping了。能ping10.1.1.1不能ping209.65.200.226,有两种可能,IP NAT和R1 ACL。3 L5 d8 T8 G& @, W# ]
1)其他设备上都能ping209.65.200.241 那一定是IP NAT,再show run 确定在ip access-list standard Nat_Traffic下是否缺少permit 10.2.0.0 0.0.255.255。: \1 G- a, c/ H/ m. N
2)其他设备上不能ping209.65.200.241 只有R1能ping209.65.200.226那就是是R1 ACL这题了,再show run 确定一下edge_security。9 C) h$ j6 q: R/ S% ?
3.client能ping209.65.200.226,那再在R1show ip bgp nei 没有邻居,就是BGP这题了。
d% G3 T/ U; I; `6 f: [7 t1 n/ r4.client不能ping 10.1.1.1 但是能ping10.1.1.2,多半是ospf authentication这题,在R1上 show ip ospf neighbors确认没有条目,那就没错了,题库的对比方法就如试友所说一样,不可取的。, _8 `9 c" h8 h7 i# x D
5.如果ping10.1.1.2不通,那问题点在R4到ASW1之间,如果ping网关10.2.1.254不通,问题在ASW1上和DSW1上,直接show run查看吧。7 ^7 R4 {9 T2 g* Z
1)如果在Interface FastEthernet1/0/1-2 上有MAC地址,如 0000.0000.0001等,就是switchport security了。: u* S6 e0 u& ?: u
2)如果在Interface FastEthernet1/0/1-2没有access vlan 10,那就是access vlan这题了。
7 T3 Y: N" l+ J: e0 ]# \3)如果是在Interface PortChannel13 和Interface PortChannel23上allow 的vlan 不是10和200,那就是switchport trunk了。
( \- x$ I6 P5 C3 c$ @4)在DSW1上show run 如果有vlan filter test1 vlan-list10 那就是vlan filter这题了。 G0 m# ~0 d% r- y8 L5 z. O
6.能ping网关,问题点在R4上。show run吧,IPv4只有两个错误。( ?' E+ o" G1 z. v- L5 W* h6 E
1)在vlan 10下如果有passive-interface default,client是ping不通R4 10.1.4.5 并且在R4上没有EIGRP neighbors,EIGRP passive-interface。% k; j; L& B8 T# c7 b& e4 C J
2)剩下的就是在router eigrp下redistribute的 route-map匹配错误了,client是能ping通R4 10.1.4.5的,但不能继续往下ping, EIGRPredistribute 。
% k3 y% Z/ }9 \7.IPv6+ R3 `* H7 T1 u/ B k
1)R2上 show run 查看连接R3的接口interfaces0/0/0/0.23缺少 ipv6 ospf 6 area 0 ,IPv6 OSPF这题了。& j" T. _) V( o: d! H. ?! c) V$ V M
2)R3上show run 是否多了条tunnel mode ipv6的命令,这是IPv4 and IPv6 互操作问题。
6 r9 `* R* j! U. i' v7 G3)R4上show run 在ipv6 router ospf 6 下缺少redistribute rip RIP_ZONE include-connected命令,就是IPv6 redistribute这题 。
3 T; e4 L% ~% R( S考试的时候我是这样标记的
# {$ \# J# q& [$ \% r$ U# f$ pR1:ospf authentication3 \: o# Y0 [, p/ S* P
IP NAT
, q+ G) h% S' V5 q- t edge_security
. y# i! y9 `* v7 @( | ] F- q BGP$ f5 I0 D( y0 Y! T3 M$ M" x# B
R2:IPv6 OSPF
. t! H& G: e7 b+ fR3:Tunnel
! b" f+ _" N/ B* c% q6 ~R4:EIGRP RED
* ?# q# ~" I- r6 [$ m! l$ O1 D IPv6 RED
2 j8 o" U( j+ E- ]) ^# `" e3 K passive-interface
% l7 U0 o @3 D; [, K% TDSW1:vlan filter
6 e* z5 w- E# r$ c& |4 ]3 r# i$ b4 b# x& uASW1:port security
. I* Q" G6 d8 u7 K) O8 Y( Q access vlan0 S! g7 e5 Q" E* o4 j; s
port trunk
* s7 k# e3 V. `$ @+ L刚好13题,每个人有自己的助忆方法,怎样使自己方便的就是好方法,希望对即将考试的 朋友们有点用处。
7 R# x6 l v: K/ P q3 F6 x9 e! D当个敲门砖而已,其他的都是浮云!!路漫漫其修远兮,。考,做最充分的准备,做最坏的打算,相信自己!题库很稳。
/ J. G% i: ]' f& J* s ]8 k3 [* L推荐两个经典战报经验,感谢他们的分享。
$ J4 ^) [4 k1 i# G5 chttp://bbs.hh010.com/forum.php?mod=viewthread&tid=430807
. y- B; Q) Q, z" @/ x4 Z$ A5 {1 F8 Dhttp://bbs.hh010.com/forum.php?mod=viewthread&tid=431713&extra=page%3D1 http://bbs.hh010.com/forum.php?m ... &extra=page%3D2' c1 y3 F, J" s2 M& M7 b
# E ?1 D; e' y# C. l8 o: K- d; S
3 I1 f2 b# L0 m# `& o9 b3 h
|
评分
-
查看全部评分
|