设为首页收藏本站language→→ 语言切换

鸿鹄论坛

 找回密码
 论坛注册

QQ登录

先注册再绑定QQ

查看: 1152|回复: 4
收起左侧

[其他] 300-101 第202题疑问

[复制链接]
发表于 2017-8-28 08:18:27 | 显示全部楼层 |阅读模式
10鸿鹄币
QUESTION 2028 y4 {. T+ R5 H
When unicast reverse path forwarding is configured on an interface, which action does2 `: B3 ~$ a/ x
the interface take first when it receives a packet?/ h; Z9 N7 q9 w( I
A. It check the ingress access list% Q' J  m/ f0 j! f; R0 p
B. It check the egress access list
9 ~1 q/ U" E4 gC. It verifies that the source has a valid CEF adjacency
. f7 @' e  O# q. v  ]( QD. It verifies a reverse path via the FIB to the source
3 o- T* {6 ^; H/ yCorrect Answer: D. e# W# T5 g6 R+ |& u: T
Section: part 5; P% C6 ]; n) w0 s
Explanation
* C6 X" ~) R6 d0 ?  T9 d+ y+ ZExplanation/Reference:
  K4 d8 F' @) V) ?$ H' W0 TWhen a packet is received at the interface where Unicast RPF and ACLs have been configured, the6 u5 V, P2 |' ^8 `" a/ E
following actions occur:
; m2 C1 s$ |. C( V3 TStep 1: Input ACLs configured on the inbound interface are checked.
& w7 U) d) Q+ ~2 VStep 2: Unicast RPF checks to see if the packet has arrived on the best return path to the source, which it1 C, K) A$ v8 [) f
does by doing a reverse lookup in the FIB table, g( [; z& I5 C- ?8 M4 q) D, v& D
) |: H& X- V( M5 F' @
下面的解析中的第一步 说的是先检查  进口ACL  那么为啥不会选A呢。。。。。( M9 ?' \2 h) W; r! z

% Q' B0 P8 M% t! i  J0 [

最佳答案

查看完整内容

我觉得题库是错的,不过有一点需要考虑,就是题干并没有指明ACL有被配置。 思科官网链接:https://www.cisco.com/c/en/us/td/docs/ios-xml/ios/sec_data_urpf/configuration/15-sy/sec-data-urpf-15-sy-book/cfg-unicast-rfp.html?dtid=osscdc000283#GUID-07331556-315A-4327-9679-0390DD2F6FC1 思科给出的带ACL的uRPF配置案例: int eth0/1/1 ip address 192.168.200.1 255.255.255.0 ip verify unicast reverse-pat ...
发表于 2017-8-28 08:18:28 | 显示全部楼层
我觉得题库是错的,不过有一点需要考虑,就是题干并没有指明ACL有被配置。' b0 G5 O9 W+ U+ L2 X6 O: x& F
+ R, T1 N  E1 u
思科官网链接:https://www.cisco.com/c/en/us/td ... 7-9679-0390DD2F6FC1
. T$ ^. w, S1 Z9 q
3 o- d. ~$ L& I7 {思科给出的带ACL的uRPF配置案例:
" C" F. U4 q0 a: L" I6 z0 j2 K$ D8 o; M4 J
int eth0/1/1
, ]4 B1 y/ @; K5 ]$ u ip address 192.168.200.1 255.255.255.0
$ A$ L* b/ ^/ @& o% z ip verify unicast reverse-path 1972 m1 D* o/ R  U( q$ b6 W& y
!
/ D: c! H! p) B6 h; M/ Aint eth0/1/2( B, ?7 ~* g  ]" L& L5 Q
ip address 192.168.201.1 255.255.255.0
9 E7 |/ x7 q" |+ g. U' U!
# j$ F9 |3 p. G8 _' ^, b1 h+ \! baccess-list 197 deny   ip 192.168.201.0 0.0.0.63 any log-input' A" C! l) Z( J* g% w2 p
access-list 197 permit ip 192.168.201.64 0.0.0.63 any log-input
) B9 y2 y9 T- x- F$ vaccess-list 197 deny   ip 192.168.201.128 0.0.0.63 any log-input, Y/ `5 [/ b+ A0 S5 M
access-list 197 permit ip 192.168.201.192 0.0.0.63 any log-input
. c/ ^% Z+ {1 P3 z- r+ jaccess-list 197 deny ip host 0.0.0.0 any log
沙发 2017-8-28 08:18:28 回复 收起回复
回复

使用道具 举报

您需要登录后才可以回帖 登录 | 论坛注册

本版积分规则

QQ|Archiver|手机版|小黑屋|sitemap|鸿鹄论坛 ( 京ICP备14027439号 )  

GMT+8, 2024-5-18 20:04 , Processed in 0.064116 second(s), 11 queries , Redis On.  

  Powered by Discuz!

  © 2001-2024 HH010.COM

快速回复 返回顶部 返回列表