- 积分
- 150
- 鸿鹄币
- 个
- 好评度
- 点
- 精华
- 注册时间
- 2011-8-26
- 最后登录
- 1970-1-1
- 阅读权限
- 20
- 听众
- 收听
助理工程师
|
发表于 2011-10-1 00:40:24
|
显示全部楼层
TS3++ solution:. d d+ }" \" p* j! w& d, r5 d9 F
6 Q$ ]8 P) \: ~
1) R15 cannot telnet R14 & R13 while sourcing loopacbk zero( fram relay question)
5 B+ E9 l# }! x0 }6 hR13/ B/ W/ B0 b% Q8 s5 }
interface Serial0/04 g/ X1 j5 e9 A4 U, F1 @
frame-relay map ip 172.16.13.1 341 broadcast
6 e% y* J- ^# t) f+ S. V frame-relay map ip 172.16.13.3 345 broadcast3 B3 p; H& q: j7 J( [) ^; B5 D
" I2 [: J( Q y. P* a- }
2) Ensure the output of show standby on R22 and R23 is the same as show below
6 Q# B4 U% e: B' r# X# T6 k* C- _ track 1 is shut down remove it+ Z% C: r$ f1 d% O
missinf preemtion on r235 C, y8 c4 t( t+ m
R22 is not nessary to confing preempt
6 B9 Y% h1 J& p9 j! w priority on r22 is 150 and R23 is 100
2 Q/ b- P8 i' N' P/ V; e; f( h- \% f8 t# B
3) R24 cannot telnet or pi g r29 192.168.20.1 fix it( a9 B, F4 I9 v( e$ s9 v+ n
chap authentication bet R25 and R29
- u& p! `1 d% n R25 ask for authentication without username8 Z; K8 u$ T( F, w/ t- ]# [
ensure password is the same on both side
* K) Y5 E4 \( h5 O) a7 s' |: v0 J$ Z
4) pc 10.1.1.20 on R20 cannt teolnet or ping pc 10.1.1.28on R28 fix it
G2 o- E( V& J! ~ R8 is ASBR all bgp route from as300 need to redistribute into ospf and flood into R20
& @( C$ D. c' w2 y- @ ensure ospf route also redistributed into bgp on R8
* z; u, w' U4 ] C, l) O3 t
$ s, z" l* ?9 Z5 k# ?- z% f5) R28 must see two next hop with network 1.100.100.100 in show ip bgp table
( N. u6 L- a% P* ? w on r6 add r8 as route-relfector client. A- k! G5 v, v
on r26 add next hop self to r28( c9 @. h' V! X5 s5 M$ u* @5 e
on 27 add bgp default local-preference 200. }$ y) o: C& m$ v* y0 H
: H1 h0 t8 u( v2 Z
6) Ensure R13 can ping multicast group 224.8.8.8 in AS 200
0 ~4 O" _& N9 K9 Y I) [0 x r1 r2 r3 r5 r6 r7 r8 r9 r11 are running multicasst and in sparse-dense mode1 N: C" _9 Z# o, S- F. \7 S) [
ensure r3 is the rp in as100 and r8 is rp in as200
/ k/ m8 [3 [; g R3 and R8 running MDSP ensure they can access each oter so that can exchange source
6 I8 ]2 q W5 i9 M$ u information- D4 r0 c5 C0 u, {: n
R19 y: G' ?8 y* M/ [9 N$ o2 b" z6 @
router bgp 100' x5 V2 ?, f+ V6 `
redistribute ospf 1 metric 20
) Q) P+ d# r8 _( [) f1 M0 Wrouter ospf 1! s' f' k9 A% f2 s& h/ s5 h( O) A
redistribute bgp 100 subnets
- O y: |. o5 ]' v2 a% o% h# i) I6 CR3
* W* W% l6 \( Y) m& O" V) iip msdp peer 10.1.1.8 connect-source loopback0 remote-as 200
( A1 r' }2 V0 n1 j/ t* u- A# E2 F/ D: H' \0 b) U% g& U8 N0 J/ C( n
7) R1 can not telnet R4 ipv6 ADDRESS 2011:abc:43::4 ,fix the problem
6 E' f0 O8 w# C: A3 }! V+ R n ipv6 ospf is down between R1 and R30 K2 u. N( t. E# {7 _* W
R1 R2 R3 R4 are running ospfv3 area 0
Z5 O$ z% w) y& \$ S r1 should can ping r4 ipv6 unicast address not r2
- A5 D% y) ^- L- V on r3 there is an acl(traffic-filter) pls remove it or allow it$ p, S3 z; p4 K
9 Q# e6 }0 y i2 V
8) R13 can not sync with r5 pls fix it1 `& e$ F! s5 Y- z6 w" l% p3 J
note:-r3 get the time from r5 thr' ntp
) S1 Z/ f# w$ G# x" y4 d" F$ _ ensure there is not acl blocking ntp traffic udp port 1234 B, `3 b, _/ ^6 C! F
check authentication
% q- X% T/ B& a- Q* c4 R& N5 F8 m
2 o/ v! X& l% {3 [$ k9) switching e( X p# q [8 A5 B
fix sw2 so that sw2 is the root for mst 1,cannot change any config in sw1
4 @9 {0 u# w6 l$ d( v* S note: the layer 2 traffic from r9 to R10 should goto sw1 and sw2
7 J7 O5 [1 `5 M/ |' ~$ s1 d5 w common preconfiguration
9 d) d$ k9 F, l V1 @' ?- F1 G' _SW1, SW22 w) d' p6 B% w6 z0 o, B) C
spanning-tree mst configuration
, ^0 ? U2 F* j& P) a3 E name cisco* n7 U2 U# H ?, }8 m
instance 1 vlan 109 121
* `- `* L' q% G insnce 2 vlan 112 119+ q' N; Q9 ~5 S; i$ z* I) C
SW18 p' G/ L8 M; Y- T
spanning tree mst 2 root pri3 }3 e8 f" W3 A4 y' X6 c
SW2
0 b9 K6 B! Q* _$ s spanning-tree mst 1 root pri/ `4 _! i1 s a. \
change port priority on the interfCE
+ f: K3 T c$ L8 L- e& b4 [9 u Interface F0/X ( THE PORT CONNECTED TO VLAN 109 AND 121), \6 f" L1 `( Y% w$ k4 o4 o
spanning-tree-mst 1 port-priority 0
6 ~# r7 [2 J) D& e! W# m7 o ?4 ]2 H, F w5 U! X& O! j' G
10) ZONE BASE FIREWALL* x& M. U$ l w: l
r30 cannot not telnet r31 fix it
: ]; `& A7 U: C$ p$ R note:-
4 b+ g( C0 a3 b4 J) F on r29 is configured as zone base firewall
6 H$ E% a6 e. M+ j6 H+ I remove match all statement in class map type inspect or change it to match-any6 h# K( _/ S! u! y' l. b) B' ~
ensure ther is not acl or the acl match ip right ip address in the exam - K# G0 [% K9 | @ U) m
Also the IP address on R31 is incorrect.
3 s. S) b9 [1 I. C" j& v, |8 t Two static routes needs to be added on R29. One to R29, other to R31 |
12#
2011-10-1 00:40:24
回复(0)
收起回复
|