- 积分
- 150
- 鸿鹄币
- 个
- 好评度
- 点
- 精华
- 最后登录
- 1970-1-1
- 阅读权限
- 20
- 听众
- 收听
助理工程师
 
|
发表于 2011-10-1 00:40:24
|
显示全部楼层
TS3++ solution:
0 G5 W/ T! a/ Y# O& v" n% t- O+ P+ K) @6 u8 o% w& `
1) R15 cannot telnet R14 & R13 while sourcing loopacbk zero( fram relay question)
: w7 Q2 r b+ I2 _& g$ YR13% ]& U! ]( G- Q U; o9 N
interface Serial0/0* D5 O( |7 e" P2 T
frame-relay map ip 172.16.13.1 341 broadcast
8 B2 q+ k% r1 ?0 D; x: p/ B) W# f frame-relay map ip 172.16.13.3 345 broadcast9 t, E- M4 R% \6 A: I% }3 K
- m, X; S& j4 \1 E- i: i0 k, r2) Ensure the output of show standby on R22 and R23 is the same as show below
1 g- s& \5 R: u5 K8 K' @( G track 1 is shut down remove it
; J+ f; z) u$ u- h9 S missinf preemtion on r23
9 h3 {/ c& V$ w( h( @9 o) C R22 is not nessary to confing preempt
5 o v2 N) q" V priority on r22 is 150 and R23 is 100" @6 Y, A" n, I; r
8 W5 J2 L- N* h! @/ B) \3) R24 cannot telnet or pi g r29 192.168.20.1 fix it
9 _- q: T( p- X* f- u) H chap authentication bet R25 and R29' [! A7 N- D* Y d0 D! c, m% L
R25 ask for authentication without username
* _# Y- v6 c) ]& T \8 c/ _0 [& X ensure password is the same on both side/ s9 w/ N" P+ @8 J" j
! }# R$ S! ~: l+ z% l
4) pc 10.1.1.20 on R20 cannt teolnet or ping pc 10.1.1.28on R28 fix it
; T! @& g8 [$ B V% w `2 I W2 b R8 is ASBR all bgp route from as300 need to redistribute into ospf and flood into R20
6 ~, P" t; J+ S; v. C3 W ensure ospf route also redistributed into bgp on R8
: Q' ]. M) k, j. c: M8 Q( u6 x! P' F" v* F5 i5 ]
5) R28 must see two next hop with network 1.100.100.100 in show ip bgp table% {7 ^( ]# r* I, t' k% O7 ]
on r6 add r8 as route-relfector client$ y' ?) X9 _- P$ n# q5 W. C
on r26 add next hop self to r28
$ Z5 ?" b8 k% [1 u on 27 add bgp default local-preference 200
/ w! V1 p* [4 v9 T" Z5 }+ a! v
; o5 N; x" E q- T6 Q) @$ ~6) Ensure R13 can ping multicast group 224.8.8.8 in AS 200" E6 ~4 w/ Z. r( L% l
r1 r2 r3 r5 r6 r7 r8 r9 r11 are running multicasst and in sparse-dense mode; ~) b/ D' c& x
ensure r3 is the rp in as100 and r8 is rp in as200 }2 Q+ y/ }+ _* H! k4 n6 T$ p
R3 and R8 running MDSP ensure they can access each oter so that can exchange source: i: n3 h% T& x) q, `8 X) h' ?
information
6 n2 x3 A$ V7 a. Z1 R3 X& PR1# O6 W. b* z% J V( v. D
router bgp 100
# m( G" m0 G$ c# a3 c' X redistribute ospf 1 metric 20
% O$ ?! a/ q* u- B Hrouter ospf 11 e* @ Z2 m2 c# R/ j( H+ R- `& u
redistribute bgp 100 subnets; K& Q) @" f- X& C
R3
# A. n- B4 m8 M- h# X3 }ip msdp peer 10.1.1.8 connect-source loopback0 remote-as 200
" p" H; X! ^5 r/ |
3 w4 v0 d8 ~. p+ b$ `7) R1 can not telnet R4 ipv6 ADDRESS 2011:abc:43::4 ,fix the problem
& T3 [8 z7 f2 P$ G6 w# V) P ipv6 ospf is down between R1 and R33 \" E$ P1 `0 z) ~$ ^
R1 R2 R3 R4 are running ospfv3 area 0
( c% f9 h# y! n- k4 B; M3 @ r1 should can ping r4 ipv6 unicast address not r23 w! @# B8 I) M# K! u7 E0 \+ W$ z
on r3 there is an acl(traffic-filter) pls remove it or allow it
) J* u0 O: L1 E* p4 V6 \; c1 M/ ^& j2 i) ?% ~# K, K
8) R13 can not sync with r5 pls fix it
6 F9 B4 P$ e% V3 k9 a& P+ n note:-r3 get the time from r5 thr' ntp
9 |1 ?! k1 l+ g) U% A ensure there is not acl blocking ntp traffic udp port 123' v* \. s; Z, y3 z. w
check authentication
5 E6 `3 f2 Z+ e7 t! h1 K( C
/ ]6 a# n D8 P8 o' u6 A: i9) switching
5 D6 ]# c. `$ z9 V+ \' A fix sw2 so that sw2 is the root for mst 1,cannot change any config in sw1% K% t# \0 H( B, N$ L) z$ G
note: the layer 2 traffic from r9 to R10 should goto sw1 and sw2
( a1 _+ O; ^9 f( E( Y common preconfiguration% k/ z) T: D) O
SW1, SW29 _# [; |3 P/ ?$ b8 g
spanning-tree mst configuration
" C4 T! q+ ~/ E* h a name cisco; H4 j+ l: T8 T0 h: {% z
instance 1 vlan 109 121
; `" a8 X0 k% K1 g insnce 2 vlan 112 119
+ N- O y; X% A$ x% PSW16 S- m G7 X( p; H8 l
spanning tree mst 2 root pri# M1 K7 X) D" n/ P
SW2" `2 w5 g* s8 i9 j6 I
spanning-tree mst 1 root pri. O) M2 k$ t0 Q" I) W- @' k' k
change port priority on the interfCE, }3 A5 A6 J9 R4 l9 @
Interface F0/X ( THE PORT CONNECTED TO VLAN 109 AND 121)
1 m) P: A8 F. L- U Y% K! B spanning-tree-mst 1 port-priority 0/ ]; l' r l c; M1 d. y
) ^* g. N) c! u1 d1 U) @/ @3 g$ S
10) ZONE BASE FIREWALL, x$ l# I7 G1 p6 X5 w' r
r30 cannot not telnet r31 fix it5 e# y& T# J% M$ o4 l- a
note:-' H$ l8 q- D6 j6 X7 w7 [- S
on r29 is configured as zone base firewall" J+ w3 F( B$ U! f
remove match all statement in class map type inspect or change it to match-any. ~( T: i/ ~; Z; s/ l% z+ b
ensure ther is not acl or the acl match ip right ip address in the exam
. `0 X2 \$ c$ S% W$ } Also the IP address on R31 is incorrect.
- o: F7 H6 H( h" T/ G9 ]$ v4 d/ i Two static routes needs to be added on R29. One to R29, other to R31 |
12#
2011-10-1 00:40:24
回复(0)
收起回复
|