|
本帖最后由 kandlly 于 2012-5-15 11:54 编辑
2 r- s8 }6 K9 H: ~9 K; H V( e. [. Z8 g z; `! j
各位战友:希望本帖一起给位战友重视!! [$ C2 H5 x* K5 l, C
之前战报“ http://bbs.hh010.com/forum.php?mod=viewthread&tid=172375&fromuid=60253 说随后对题库中遇到错题提出进行补充,本人将守信用,在下面将给出错题内容!. L$ m7 j- M; A1 a5 f% z
本人综合几位642-832千分PASS战报或交流经验得出642-832题库中错误部分,同时也希望版主对题库中错误尽早修改过来。# l5 I) F- A. @0 N# l) n+ l
有1道选择题。如果你已经在其他战报中看到过,在这里加深一下印象;你如果第一次看到,请在题库中标出。
' ~$ c; q/ M a6 C3 N1 Y
3 k* P/ E1 _ c: l4 l" L; u% |QUESTION 13
8 y- @. F9 |' m8 y" U% `! _What is the result of configuring the logging console warning command?
& D% h6 E% Y% O( O% s! @2 m' e' v8 }$ p' c1 B: S; u
A. warning,critical,alert,and emergency messages will be logged on console+ v* A5 }+ j* A, L* ?3 O
B. messages with a severity level of 4 and higher will be logged to all available TTY lines" X, b+ L3 g0 y7 O8 h# o; e) \1 a1 H
C. warning,error,critical,and informational messages will be logged on the console
: @# M' G- M+ w8 bD. the logging console warning command needs to be followed in the configuration with logging
; p+ n5 E3 [* |, X8 v1 V& F3 ?buffered bute size to …size for the console
* _# ?1 [+ G# B4 s+ o8 \& HE. only warning messages will be logged on the console4 h; Q. T# ~% [6 |* P; M" W, a' a$ D
$ Q! v. U0 c( L' C3 ^9 r+ O
这在V200题库中,答案为B。但是综合几位战友(考试中遇到过),说答案有问题,至少两位1000PASS战友对于肯定答案选择"A "。希望后来战友注意。
5 p' b3 T! ?7 X) R
" j3 H/ N. Q. l& P$ D& y9 b2 w一道13TT中Port Secuity的问题解决,加下划线部分考试是题目中是没有的,相应题目中内容都是需要自己考试时候在相应设备使用命名得出来的。我们考试时候得出的内容没有这么直接,所以给位在看题库时候找出关键内容。其实万精油中已经给出来的。不清楚,可以再次使用上面链接到本人642-832战报中下载解题思路看一看。2 b6 `2 G4 J! O
TROUBLE TICKET STATEMENT:4 O6 u9 j. @! o5 k
The implementation group has been using the test bed to do a ‘proof-of-concept’ that required both client 1 and client 2 to access the Web Server at 209.65.200.241. After several changed to interface status, network addressing, routing schemes and layer 2 connectivity, at trouble ticket has been opened indicating that client 1 cannot ping the 209.65.200.241 (internet Server)." v4 L+ U8 s `% h4 X- m
以下信息需要自己show run获得:
. Q4 O% l" o( H8 H. \9 t8 c8 AClient one is getting a 169.x.x.x IP address and is not able to ping Client 2 or DSW1. Inital troubleshooting
# M; h' G# Q/ x, c8 c pshows that port Fa1/0/1 on ASW1 is in errdisable state.
* ^) B9 [, l, W+ UConfiguration on ASW1
0 [2 S( x+ ?7 {% z* ]Interface FastEthernet1/0/1( _8 W0 w! U! j0 w X: S$ v
switchport mode access
) y0 g' G: S7 c. B$ ?switchport port-security
) i# Q: e& ~- nswitchport port-security mac-address 0000.0000.00013 @1 Z4 F. l2 [/ W* o4 j5 H
Interface FastEthernet1/0/2- L" p; [/ {$ [, q4 a
switchport mode access$ ]. i8 Y9 e, \1 u
switchport port-security: s- Q4 E2 W4 _3 I4 |1 T: d3 L4 A
switchport port-security mac-address 0000.0000.0002* W1 o) c0 @4 N z. g2 ?1 H
& V; x& q4 m* X- WWhat is the solution of the fault condition?& R/ j0 U8 E. ]2 M& B: Q
) S* E3 B+ ^: J) x, _2 j, r7 t
A. In Configuration mode, using the interface range Fa 1/0/1 -2, then no switchport-security interface configuration commands. Then in exec mode clear errdisable interface fa 1/0/1-2vlan 10 command
3 m) x# V% l/ j$ i* W& [5 yB. In Configuration mode, using the interface range Fa 1/0/1 -2, then no switchport-security,followed by shutdown,no shutdown interface configuration commands.
2 h+ a( B( r! g; E# P' vC. In Configuration mode, using the interface range Fa 1/0/1 -2, then no switchport-security interface configuration commands.
, J9 ~/ a$ w4 v0 dD. In Configuration mode, using the interface range Fa 1/0/1 -2, then no switchport-security interface configuration commands. Then in exec mode clear errdisable interface fa 1/0/1, then clear errdisable interface fa 1/0/2 commands
' J: b) g0 P- u: U+ t- Y. C# Z. R
7 e- p/ D+ U/ r, x8 c/ }( w) C这在V200题库中,答案为D。但是综合几位战友和自己经验(每人都会遇到)得出答案为B 。7 A/ ?% \" h- \* X9 a
拓展一下:端口安全有三种违规规则,考过813的战友应该一定都不会陌生。
* m2 `5 C* S# DS(config-if)#switchport port-secuity violation {protect| restrict| shutdown } ===={}是必选,但是三选一,默认选择是shutdown,违规端口立即进入“Errdisable”状态,相当于关闭端口。要使shutdown端口重新恢复使用,有两种方式恢复:必须手工重启或通过errdisable自动恢复,可以设置自动恢复时间。6 I( k% V/ K6 d4 X
如果违规规则设置的是restrict或protect,那么在重新启用端口就需要清空获悉的MAC地址,从而让交换机能够使用该端口。清空命令clear prot-security dynamic [ address mac地址 |interface 端口号 ]5 V* X2 Q; U9 |3 O; s& x
* ~$ T, i$ p/ b& b8 f- j! r希望上面对后来战友有用。
$ X1 @- h; ^* v要是觉得不错,麻烦给位坛友顶起来,让更多后来的832战友看到!!!
/ H1 N! J& C% O$ B
$ P$ r: x: J T4 G
* r. L, s4 w ^8 R: D9 B6 V {% a8 g% E( i
7 k9 p7 [- j& ^/ U* ~2 a
3 p, T* M* R. M* q3 n' Q |
评分
-
查看全部评分
|