|
发表于 2017-10-20 22:34:20
|
显示全部楼层
[First topo here] [thanks to the guys who shared this image from ccie 4 career dot com]
3 Y1 X& Z9 g9 _ b h
# ]2 c$ ~1 a: g1 EQuestion 1: Layer 2
# ?4 B. ~5 i* g' d" n( ~ b. n( F8 L
- VLAN 12 is missing, d8 H+ Z" a6 @/ R
- vlan 12 not ALLOWED over the trunk on SW2
! ~$ }9 p% L& X! h, O l- Access vlan 100 to interface connect to PC 101.- k+ u7 d S" h! ^% S1 o
- Passive-int in OSPF
% I& B& R. g# l t- ACL on SW2 (?)" `6 E$ w( f6 `1 Z
7 N# c' ~6 O+ U9 o$ M$ O# M+ d
Question 2: PPP- a. n$ b% j7 t' f* T5 L6 ]* c
4 `5 l9 S: h0 B" v$ R" l* {- Add command: peer default ip address pool in R12
4 [7 |. Y! N' G7 ~, w5 M- Remove ppp auth chap call out on R17 (WAN)
: X- u9 N' p" U# v: n6 \- Username was ..spoke1 on R12 but spoke1 on R17
" ?4 z5 @6 M( Y) G5 N Q6 @1 q, h- Wrong password on R17
# z+ L" s4 M# l/ _8 W- R12 did not advertised the net in EIGRP* e6 p w, V$ t4 z. Q" @9 g i
1 }. K+ @% {8 k# d3 KQuestion 3: OSPF6 r; o; G* z( a
& T2 Y- X3 b' p5 I5 Q$ S9 Q- Correct IP address in R22 and remove max-metric router-lsa in R5.( C0 Z7 L; I+ W4 r4 p# {
- Remove cost on R1 (OSPF)
& A8 x4 M! [- Z u' y6 {- passive-interface default on R22 and R21 was configured! K. L( X" K1 Q: w4 w3 A
- R22 : Wrong router-id/ K. G( k* C2 i5 b
P/ a8 o: z3 x4 u3 HQuestion 4: EIGRP
: ]1 M! `9 Q! G' U* d6 W
: O: v3 ^5 s! A& I- Modify access-list in R13.+ `1 y! ?! U' \# w" V" ?
- Remove delay on R13 and Set Metric (EIGRP)
+ _; w9 M! W3 @0 c: M+ x+ n- Metric weight of 0 1 1 1 1 was missing
6 F: j, m) u, C* \- Offset-list on R12 permitting any. Need to deny ip 145.15.15.15 above that.
: j% ^# j- h) q. `$ A J% a- Passive Int on R14
$ R$ I, |" ?8 e3 Q$ {$ B8 \8 W3 J( p6 R: J, |; K
Question 5: BGP$ b7 i! k- x, B: q6 E5 X
/ D: s- `9 m3 U% u1 ]- Set metric in R4
3 R; a1 Y+ Z. G) u4 u9 g- Active neighborship between R4 & R5.+ J% A% d: a/ q3 g
- set lower prefix to 123.XXXX on R4 and 134.xxx on R6+ o+ \4 e/ l; x& F3 Y7 A ^
- Set max-path on R12 (BGP)& \' l W. H# b( u6 ^- m. N% K
- R21 : Wrong ip prefix-list 194
- d% G8 Y; ]/ Y P: w8 E S8 @; l) y8 }
Question 6: IPv6: [/ k1 N5 G& \* @: y5 A; c
! w4 f E# n" A8 N
- Correct advertise network in R25 (2525::25/64 instead of 25::/64)
0 F3 ?( [( m# p4 Q" o- Wrong next hop in R22 route-map (IPv6). Q" Q5 A! I5 H8 K! J
2 [! x2 L4 I/ D/ j
Question 7: DMVPN$ ^% L5 U0 Q* G n( N1 }
; k( z0 z7 g% s3 b9 L- ACL was denying ESP traffic in R19.
2 g6 ?) |& e# a- Wrong NHRP config on R18/R19 (DMVPN)7 {" e6 S* w8 S
- R17 missing nhrp multicast
& N3 Y Q* T- I7 ]" e# H' |- no ip next-hop-self eigrp 200 in R15
( g" N+ G# w1 m* v, {0 M, p- NEW : ONLY 2 CORRECTIONS PERMITTED (Needs confirmation)$ ?- d! j- E6 F1 E9 X ]
& A# R) t, S3 [6 U f3 G/ XQuestion 8: MPLS VPN
7 e1 U X1 O' m& x
; x) |& ?7 @) |" e; N1 r' K- Add R8's eth0/0.123 ip nat inside5 R/ v( ?: x3 J
- Advertise default-route in BGP on R7/8.
; _% z/ G9 j7 ?( ]4 H) s5 V- R6: add import and export Route-target.
X/ j/ Q( j! T0 z/ H& ?- VRF import on R3/4
' n# E4 l% T5 S8 _* h3 D- R3 : advertise .125 network+ l5 g5 X! ~: M! S2 Z8 f) Z
- R4's and R6's e2/0 ip ospf cost 200 (backup path)& C/ T+ ^; v" W z* t3 q
- DHCP issues on R9/SW3- e( @- P2 r* ?; E$ e' q1 T
- NEW : ONLY 2 CORRECTIONS PERMITTED (Needs confirmation)% ?& c$ @6 X4 D9 Q" d8 `" c
" e+ Q: a& b% x+ i& C {Question 9: DMVPN NAT- ~& R+ I4 r$ Z
% n7 g4 } N- r
- Correct transform-set and mode in R24.
$ K# |: e# [( D) V6 {* J) [- Wrong crypto isakmp Address was configured on R7. F2 q8 L* M. i7 k, A: D/ s
- Wrong tunnel source on R7% G5 _. D- Q0 I
- Wrong tunnel source on R24
) Z8 W2 O6 N2 H' C- R23 : no crypto udp transformation
1 m$ q; |1 L! }7 `! p9 l* L( y: U, E% ]/ [2 w" Q% |* g
Question 10: NAT% B( [8 i7 V+ q c$ F
8 ?6 W- q2 ^- g; H* ]6 L
- Modify NAT command in R23
! [* z4 z0 z. a9 \- Add command: ip domain lookup in R21.
0 _7 d8 h7 D/ J: `0 v- Add NAS mac add on R23 dhcp pool. X8 C2 {5 e1 {' z: k7 S( {
- IP domain lookup and ip name-server was missing on both R23 and NAS( R$ e/ f* n, N
- NAS has no ip assigned (not even DHCP)
$ m( Q7 J* k x3 p |
|