- 积分
- 150
- 鸿鹄币
- 个
- 好评度
- 点
- 精华
- 最后登录
- 1970-1-1
- 阅读权限
- 20
- 听众
- 收听
助理工程师
 
|
发表于 2011-10-1 00:40:24
|
显示全部楼层
TS3++ solution:+ w3 N5 W+ D1 j. N; `0 N. {( R
! a' ?* S: W }& M- L6 j
1) R15 cannot telnet R14 & R13 while sourcing loopacbk zero( fram relay question)
3 U4 o0 @$ U, iR13
) C6 g9 t. a8 O2 [$ y9 ginterface Serial0/0! ~1 V* o: Y5 `: ^+ X% Z _2 W& Y: i) w
frame-relay map ip 172.16.13.1 341 broadcast
9 E2 @# x/ z/ o+ B5 a j7 a frame-relay map ip 172.16.13.3 345 broadcast
4 N7 ^1 Q! C4 J. X& [1 I5 ~' r% a1 e) R
2) Ensure the output of show standby on R22 and R23 is the same as show below/ b }8 h4 N3 u# \
track 1 is shut down remove it3 H! }! p' z! j/ Y2 w8 c4 o2 l: u
missinf preemtion on r23. F4 y# _! X6 e l, q) c1 o
R22 is not nessary to confing preempt
! |0 }" ^' \9 c5 N% b priority on r22 is 150 and R23 is 1002 I* \+ x* ~; ?% I5 p4 @# j
* q7 ?7 C4 n2 |! e* d2 c3) R24 cannot telnet or pi g r29 192.168.20.1 fix it6 v) V. d* C4 f" `. w2 f) y$ W
chap authentication bet R25 and R29- ^; d' e# _: R. b( w9 X0 V0 D6 h
R25 ask for authentication without username
# R" Q4 o+ p: Q: D5 Z ensure password is the same on both side5 u% H, J) a# d5 U. S+ ^6 I- I+ ^) v
" l* X K. T6 H1 E1 N; o
4) pc 10.1.1.20 on R20 cannt teolnet or ping pc 10.1.1.28on R28 fix it
! g# ?& H6 ]) C R8 is ASBR all bgp route from as300 need to redistribute into ospf and flood into R20
- b- H4 _5 Q5 T ensure ospf route also redistributed into bgp on R81 n. {& b2 e+ m
) v1 e) r9 C! n: z9 D
5) R28 must see two next hop with network 1.100.100.100 in show ip bgp table
- K) ^6 Y3 }- ?+ ` on r6 add r8 as route-relfector client
7 x- B* \* n6 R- n9 C on r26 add next hop self to r282 V+ S( A* K9 ~
on 27 add bgp default local-preference 200
" `5 ^, a1 [* R8 k# W7 \) p7 _1 ^8 H- O& y3 x
6) Ensure R13 can ping multicast group 224.8.8.8 in AS 200
5 j% j4 X, d, t0 F( | r1 r2 r3 r5 r6 r7 r8 r9 r11 are running multicasst and in sparse-dense mode& h! C. i7 C9 V. b
ensure r3 is the rp in as100 and r8 is rp in as200* y- b% z7 m7 L- h& }- l
R3 and R8 running MDSP ensure they can access each oter so that can exchange source* t+ {2 X5 C/ x* l) s6 W, l# ]+ `
information: q3 D9 B. Q o( O0 w. Y( \8 Y) W
R1: \% i* a; J8 d: R2 H
router bgp 100
" i1 T; t0 ^3 P redistribute ospf 1 metric 20 x3 O* k, L+ N2 d' D
router ospf 1
9 R; G4 H; ^4 J redistribute bgp 100 subnets5 n# b% r) G3 s, i% \% v7 m: ?* s k5 I
R3
1 f& u: L; W, E/ a; V8 h/ Qip msdp peer 10.1.1.8 connect-source loopback0 remote-as 2008 Z5 y. |. n) m" ^8 s- Z
8 _" R4 E9 b$ Y! [5 m7 n
7) R1 can not telnet R4 ipv6 ADDRESS 2011:abc:43::4 ,fix the problem
6 j. }3 C# m$ j9 @/ }( B ipv6 ospf is down between R1 and R30 Q, F6 v6 n) O. B1 s% P% H# O
R1 R2 R3 R4 are running ospfv3 area 0) Z# @$ ^5 N( Z+ l( h1 U+ B, z
r1 should can ping r4 ipv6 unicast address not r2
/ E( H$ C5 s5 K& T2 | on r3 there is an acl(traffic-filter) pls remove it or allow it$ g$ l7 M% j4 u8 j' \2 s
- f7 G0 ~) q" H ]8) R13 can not sync with r5 pls fix it/ ~. f5 U+ u4 F; Q/ @
note:-r3 get the time from r5 thr' ntp
, P0 y+ e0 w* ?8 _/ g ensure there is not acl blocking ntp traffic udp port 123# ~. B% D3 c( ]) q9 q; k4 Y7 }& e. s
check authentication
/ ]+ R; m0 a6 G2 `1 t% Z A8 H) D) ?6 u$ H+ b% N
9) switching$ J7 M9 B- X; o
fix sw2 so that sw2 is the root for mst 1,cannot change any config in sw1
. l& B# Y D# U9 F note: the layer 2 traffic from r9 to R10 should goto sw1 and sw2
/ k. ^8 n1 R/ F) o- T6 B9 y common preconfiguration- ~3 w; e$ B# U/ F+ ]6 p
SW1, SW29 R+ G6 P1 W. w' s
spanning-tree mst configuration
1 o% K1 l" Q7 U/ H name cisco
" B) I+ a; m( F instance 1 vlan 109 121 w* U4 i) E$ C
insnce 2 vlan 112 119
2 Q/ S. G+ K! v4 Q ?& z! }SW1
; H- l, _/ W3 p* V# f- r8 g; v spanning tree mst 2 root pri
) }/ y9 X6 `7 Z, cSW2
; t! A( N5 j8 @* _. i spanning-tree mst 1 root pri
1 I) z y0 b- L7 dchange port priority on the interfCE
! L2 n3 _0 J3 N% w8 `% ^ Interface F0/X ( THE PORT CONNECTED TO VLAN 109 AND 121)
# @3 G2 j7 Y, S spanning-tree-mst 1 port-priority 0" u" m+ ~7 V5 F) U# l
/ H! ^! l4 d& S7 J4 b
10) ZONE BASE FIREWALL
3 L8 H% K( ~5 t5 e) }9 @. ? r30 cannot not telnet r31 fix it1 A6 R Y/ A4 \
note:-" s: }9 r' U/ X3 M0 v# m# i5 l
on r29 is configured as zone base firewall3 i& t/ c1 `& ?2 D$ a/ s
remove match all statement in class map type inspect or change it to match-any
; S; d$ k* b7 E5 u7 R& k- A ensure ther is not acl or the acl match ip right ip address in the exam 5 z. x6 P* u& D& `3 i; I
Also the IP address on R31 is incorrect.0 {* M4 E, A' y8 I: y
Two static routes needs to be added on R29. One to R29, other to R31 |
12#
2011-10-1 00:40:24
回复(0)
收起回复
|