本帖最后由 scorpio920204 于 2018-1-29 13:28 编辑 $ ~, @5 E3 f, P& G( X2 [
' P' f9 J! U5 ^4 b6 `題庫很穩一點小變化/ m5 E* o5 Y0 Q- J+ \
. E. d9 L$ H2 @3 SNAT Inside
$ u" i1 I- J6 s2 Zip nat inside source list nat_pool interface s0/0/1 overload ip access-list standard nat_pool) m: I/ z W' {$ c
permit 10.1.0.0
: X. t& l* S i2 W permit 10.2.0.07 `+ B6 Q, `; u# G- C2 R% D) w
!( I# q7 I. Y* _* D8 v
interface Serial0/0/1$ `0 {0 T( b) l# [- s. j. V3 c
ip address 209.65.200.225 255.255.255.2529 ]' x: t* s; K: s1 Z/ b) m7 { W
ip nat inside% O3 s8 i/ |$ i( k. _
!
4 R" W$ g) X# ` R) N) R interface Serial0/0/0.125 L' _5 F5 ^3 L
ip address 10.1.1.1 255.255.255.252; M! B- n! P: l2 |" z& `) T
ip nat inside
C( ]3 V" H% w0 I7 { ip ospf message-digest-key 1 md5 TSHOOT
* H5 B8 A, ^1 W; W: ], g ip ospf authentication message-digest
* w4 D& Z9 V0 W ~( ]9 H
Ans1) R11 g ?3 ^! x1 _0 q( k
Ans2) NAT
* _% | M1 N! { Ans3) Under interface Serial0/0/1 add the “ip nat outside” command. 9 t& U) Y6 V4 E
Switchport VLAN 10 Configuration of ASW1' q. W" ^1 E! v0 m3 c. f
interface FastEthernet1/0/1
' @/ E$ E H* i K switchport access vlan 10
9 \& I% C. g z, t1 C/ ` switchport trunk encapsulation dot1q
5 r/ j* z- G! d switchport mode trunk& p' J2 e) D0 o- x" a
!
& D$ t' m# x& t( Z$ k5 M" v interface FastEthernet1/0/2& P" {/ |- Q' F7 X" A! w, ^
switchport access vlan 103 f+ h- [- n" |) n) M' P5 R
switchport trunk encapsulation dot1q
1 l8 K, M7 l5 e9 t. k- R( ~ switchport mode trunk
Z+ h+ z5 \. p% Z* M, Z/ L !
# w5 M4 p" {, ]! ZAnswer: Ans1) ASW1" z7 ]8 Y' K' a" J8 u m) N T) f, ^
Ans2) Access Vlans
# Z1 r Q! f. s3 p7 U8 E9 }: Y9 s- R Ans3) In Configuration mode, using the ‘interface range Fastethernet 1/0/1 – 2’, then ‘switchport mode access’, ‘no switchport trunk encapsulation dot1q’ commands. 5 _1 J4 G# ~3 o# U z' k
Redistribution Route-map On R4:
$ ^1 O ]9 ^' O0 p3 x3 O# [6 f1 o7 E router eigrp 10
7 G' R3 \8 W& n O2 J redistribute ospf 1 route-map OSPF->EIGRP
* U) i* e, }3 l5 E2 s network 10.1.4.0 0.0.0.255+ n3 f t4 p+ e1 x
network 10.1.10.0 0.0.0.255( K' m3 x, N! a
network 10.1.21.128 0.0.0.3
" O9 P4 l3 v1 C. N0 {1 r& ` default-metric 100000 100 100 1 1500/ d: q5 y3 h7 L) m$ `
no auto-summary ]. H2 ]" |2 i) D
! route-map OSPF->EIGRP deny 10# n& o( C* g: y/ @) U& X) d+ b# U& [- r
match tag 90
& F/ v4 d( A0 B/ J# \ route-map OSPF->EIGRP deny 20% u4 k: O. r0 a$ {: P0 q' F: f! }
set tag 110
3 x3 J ?" \# C$ Q, e# H1 b( lAns1) R4
1 ]- k% e7 m/ r4 _: @ Ans2) IPv4 Route Redistribution$ T* q* K; I7 I6 s6 b
Ans3) Change the “route-map OSPF->EIGRP deny 20” to “route-map OSPF->EIGRP permit 20”
0 L) l2 |1 m+ L7 S8 b' L) F
IPv6就用R3 show ipv6 ospf neig % v. m( i+ _: @+ B% ]9 o, N2 {
可以參考考 7 a. X1 X! C, X3 Z$ }, h" x+ l2 L
對於剛要開始讀的新同學 要把答案給背起來,差不多就完成了一半, 我自己的背法給同學參考一下
$ T) E" n: L' ]; U- b. D( q4 }10.1.1.1 可以ping 通 v4 layer 3 security -- R1 -- permit 209.65.200.224 any -- show run IP NAT -- R1 -- S 0/0/1 ip nat outside -- show ip nat statist
1 v3 ?8 b0 H# Z2 ^& o+ H. B( K# F
10.1.1.2 可以ping 通 v4 OSPF router -- R1 -- S 0/0/0 IP OSPF Auth messag -- show ip ospf neig 無2.2.2.2鄰居 5 C# E& @, g' }& ?# a
10.2.1.254 可以ping 通 v4 router redisbribu -- R4 -- router-map OSPF->EIGRP diny 20 permit 20 -- show ip eigrp neig 有鄰居, 客戶1 ping 到10.1.4.5 v4 EIGRP router -- R4 -- E 0/0 E0/1 NO pass-int -- EIGRP 10 有pass-int default ,show ip eigrp neig 無鄰居 8 Q7 A$ u) Y( z5 L }8 |% W6 K% w
10.2.1.254 ping 不通 VLAN ACL / P A -- DSW -- NO vlan filter -- show run Access V -- ASW -- swpo mode acc , NO swpo trunk en do -- 看Fa 1/0/1 - 2 Sw to Sw Conn -- ASW -- port-channel 13/23 , swpo trunk all V 10.200 -- sh ip int bri 接PC被shut IP DHCP Helper -- DSW -- delete 10.2.21.129 , add 10.1.21.129 -- 看VLAN 10
7 `' M# M4 a( h+ n+ W1 J
IPv6看題目就可以看的出來, 不放心可以Ping 209.65.200.241 在R3上show ipv6 ospf neig 看鄰居狀況, 千萬不要手快打成show ip ospf neig 鄰居狀況是不一樣的,一開始我犯的錯 v6 OSPF router -- R2 -- S 0/0/0 23 IPv6 OSPF 6 area 0 -- 看S 0/0/0 23 無, 有R4 v6 OSPF router -- R4 -- redistribu rip RIP_ZO -- 看ospf 6 無, 有R2/R4 v4 and v6 interoper -- R3 -- delete tunnel mode IPv6 -- 看Tunnel34 多了, 有R2 還是以自己看的懂為主~~但答案最好要背起來 & Y3 {/ P3 {3 r
|