|

楼主 |
发表于 2019-11-25 19:30:47
|
显示全部楼层
本帖最后由 Lapot16 于 2019-11-25 20:17 编辑 4 A3 @' E6 G# Y2 @# e7 m" O) p4 O
justin215 发表于 2019-11-25 11:57
) H6 @8 W! k" u% U% J/ y& nThanks!!
/ H: {. w- a8 p* xThe next thing is to download a lab before Exam.
- g Q9 [1 s) d& ^; [By the way: 5 P9 j% K) C. u9 _9 e
If not ping 209.65.200.225 it`s problem in ACL security ( e$ t. t N' K& O$ P
Pings in second column is debug info for me , if I stuck in any TT
2 d5 s; z$ G7 W3 ~. j; NI recommended do the ping too for better understanding how labs work.
2 k9 i1 k" C6 c% w( n! A7 ]2 @It`s help me in TT portchannel .! `: ^/ m' Y; i2 u/ \% ]" y0 |0 |
I liitle confused, when in TT portchannel don`t work command show port-channel.
6 s: m8 Y: ^1 l+ r1 MThen ping from DSW2 => DSW1(10.2.1.1) not pass. 4 Q3 o, W4 C/ ^9 M: n
Show interface trunk=> NONE.
2 a" H8 p5 ] D+ D" f# V, D. a7 o$ ?show run; C0 {! S& C+ j! t, Z4 v- ]
I recommended do the ping too for better understanding how lab operates.
+ i# n# d1 C7 C9 e! I+ P4 P# A5 d; e+ i: e0 j+ r& b; Z+ I2 F2 x
I try explain tickets NAT : x2 H. X' G$ J- L
ping 209.65.200.241 -no pass: S6 g$ o& l& c! G. y) V0 T+ d
ping 10.1.1.10 - pass
/ J; R7 b* p% T% `- {# ~! fping 10.1.1.1 -pass
: k/ @; p X( P5 TSo problem is on R1
% w! t& U0 W P. }7 r8 T0 d
+ b4 V/ R. s7 x# G3 m
2 i1 o# w7 ?" ?5 cR1>show ip route
( ]' _6 t5 R, ?5 |5 F: c- oGateway of last resort is 209.65.200.226 to network 0.0.0.0# S+ Z0 {0 U) M, q) U
% `' n: H9 ? k! V3 N1 ^) X0 Z3 C/ Y5 }4 E/ }2 U' y
B* 0.0.0.0/0 [20/0] via 209.65.200.226, 00:00:01
! ~% Z r+ u3 e& h 1.0.0.0/32 is subnetted, 1 subnets: Q6 y8 d; H% R" z+ p# i# ]
C 1.1.1.1 is directly connected, Loopback0! }6 ]5 B. `; ]8 h- N
2.0.0.0/32 is subnetted, 1 subnets
$ a/ ] s% v9 ], {+ gO IA 2.2.2.2 [110/65] via 10.1.1.2, 00:00:34, Serial1/0.12
+ O5 }, m5 _" V8 i- H/ c+ X If BGP route consist in route table -problem not BGP or ACL security4 U* B# u2 h6 b' E+ ?6 J D
5 l" Y9 a9 d: C) B# ^' W
problem probably NAT% U! B; G" K+ z c5 f
X: i4 m X9 x
R1>sh ip nat stat
* o) o+ E! Q! |, e/ fTotal active translations: 0 (0 static, 0 dynamic; 0 extended). ?3 q1 {2 w6 p6 n9 ]
Peak translations: 0
4 p" v6 K+ A1 k, \Outside interfaces:
5 l! W3 O' o5 n' Y0 C1 l: Z0 }Inside interfaces:
4 ~* y" r( @/ ~& T Serial1/0.12, Serial1/1. k& y/ l# W% M
Hits: 0 Misses: 0* I( T% }* Q) M$ e/ w1 n
, `3 W" k' @4 [6 }
If TT is NAT-ACL contunue our trip, z: {: h4 z% b1 h2 N9 e9 V
Unfortunately, commands show access-list is absent.: e, p5 q5 {* H5 D
- C$ m. k! \' Y# R
going to config' ` W# q Y# U/ y/ ^! H8 N5 e
ip access-list extended acl.nat
$ O) f1 ^$ y% ^3 b) E. A% E' a0 }permit ip 10.1.0.0 0.0.255.255 any7 q/ X* L1 D5 U7 ~1 z
permit ip 192.168.0.0 0.0.255.255 any
7 y! t; o: X5 c! C; { |
18#
2019-11-25 19:30:47
回复(0)
收起回复
|