|

楼主 |
发表于 2019-11-25 19:30:47
|
显示全部楼层
本帖最后由 Lapot16 于 2019-11-25 20:17 编辑 , m+ q7 f; H6 A7 N# S+ z
justin215 发表于 2019-11-25 11:57
$ M$ v$ N, R" ]- wThanks!!! |& I5 u) R6 d; @( _ \
The next thing is to download a lab before Exam. 6 b* k. z, e9 n1 e* I& j
By the way:
5 y' e6 F0 _* V; J9 tIf not ping 209.65.200.225 it`s problem in ACL security % A* R, K( O2 ], A. v
Pings in second column is debug info for me , if I stuck in any TT
: h, e0 W* Y9 h! j: o, |) V/ N1 i( sI recommended do the ping too for better understanding how labs work.
& W$ A/ H& D& a+ zIt`s help me in TT portchannel .5 s3 O" [# E+ f$ p' ?
I liitle confused, when in TT portchannel don`t work command show port-channel.
9 d0 B$ e: y! ?% f' v S; tThen ping from DSW2 => DSW1(10.2.1.1) not pass.
0 n/ Z- l2 G# E, h% ^Show interface trunk=> NONE.
8 b" F8 _* l. |( Q2 D# ?. `show run/ A2 m$ n |9 X& U& W- }6 O# n$ {
I recommended do the ping too for better understanding how lab operates.4 `$ e& Z s; R! g
" t9 e+ v7 G; K2 n: N: _3 xI try explain tickets NAT
: u m+ ~! I0 b) s% @ping 209.65.200.241 -no pass8 ~( z1 K- k/ X; c
ping 10.1.1.10 - pass
3 H( ?, ?: |) ~) Q( D+ wping 10.1.1.1 -pass
6 Z1 g( J" S+ b/ q( Z: v SSo problem is on R1" d( w% a, E7 I) V
) p! K5 u5 C: ] }
- A4 s7 G) V- f; H$ D6 B# v3 D! xR1>show ip route
* D, g7 L) m& X* d5 h5 MGateway of last resort is 209.65.200.226 to network 0.0.0.06 I0 t+ h, h4 U
$ O i* b* A3 k2 ~: }( ]0 `, p
6 C7 U z; J' R9 t/ a' t, j5 FB* 0.0.0.0/0 [20/0] via 209.65.200.226, 00:00:01. F# t2 q2 z2 O9 c" V+ ?
1.0.0.0/32 is subnetted, 1 subnets
+ p# C, [3 E% n2 ~" iC 1.1.1.1 is directly connected, Loopback05 B% k$ J2 V) i1 k- K# \" g+ R
2.0.0.0/32 is subnetted, 1 subnets9 @; U4 l/ |4 i* J8 @
O IA 2.2.2.2 [110/65] via 10.1.1.2, 00:00:34, Serial1/0.122 b6 s7 w; Z( X* E
If BGP route consist in route table -problem not BGP or ACL security( y4 T9 J! |' a: Z' R, N0 \+ \# s
: F5 _# }8 d9 F( g/ n+ N$ k problem probably NAT
# F) c0 w1 n! n* O5 b1 [% c8 l; y + O6 ]+ \) N1 u: }% q& Y5 Y
R1>sh ip nat stat
2 v( D. y* m1 q7 Y3 M U8 |+ mTotal active translations: 0 (0 static, 0 dynamic; 0 extended)
, k$ k2 q2 v$ x5 t, zPeak translations: 0
3 t. b) R) j5 h8 a4 {Outside interfaces:
$ R- _+ v; C6 b) P( J6 R, dInside interfaces:$ t& t5 C7 L; [- q6 @
Serial1/0.12, Serial1/1
4 ~/ ^& M' M( k6 CHits: 0 Misses: 0
3 b1 [- L& v& |) h( J/ S6 K$ Y ?* ?- o
If TT is NAT-ACL contunue our trip
, a- ~7 L# L' p J" _# M2 j, gUnfortunately, commands show access-list is absent.6 K. t# B; S8 q& z: n( J1 c, t8 x
* K9 I" R! N" J% F, z- o1 {6 Mgoing to config" a8 F" P9 @. `7 X
ip access-list extended acl.nat$ |: m' X- `! V3 ?& e7 ]0 Q
permit ip 10.1.0.0 0.0.255.255 any) @6 Z$ g. K* T' G: e1 c0 p5 x/ e# m
permit ip 192.168.0.0 0.0.255.255 any
* n) Q# }: \5 @/ _* M |
18#
2019-11-25 19:30:47
回复(0)
收起回复
|