TT832 final.docx

上传人:b****6 文档编号:3730856 上传时间:2022-11-25 格式:DOCX 页数:7 大小:17.58KB
下载 相关 举报
TT832 final.docx_第1页
第1页 / 共7页
TT832 final.docx_第2页
第2页 / 共7页
TT832 final.docx_第3页
第3页 / 共7页
TT832 final.docx_第4页
第4页 / 共7页
TT832 final.docx_第5页
第5页 / 共7页
点击查看更多>>
下载资源
资源描述

TT832 final.docx

《TT832 final.docx》由会员分享,可在线阅读,更多相关《TT832 final.docx(7页珍藏版)》请在冰豆网上搜索。

TT832 final.docx

TT832final

Ticket1

1.ClientisunabletopingR1’sserialinterfacefromtheclient.

ProblemwasdisableauthentificationonR1,checkwhereauthenticationisnotgivenunderrouterospfofR1.(useipv4Layer3)

confR1was:

interfaceSerial0/0.12point-to-point

ipaddress10.1.1.1255.255.255.252

ipnatinside

ipospfmessage-digest-key1md5TSHOOT

routerospf1

log-adjacency-changes

network10.1.1.00.0.0.3area12

default-informationoriginatealways

confR2was:

interfaceSerial0/0.12point-to-point

ipaddress10.1.1.2255.255.255.252

ipospfauthenticationmessage-digest

ipospfmessage-digest-key1md5TSHOOT

Answer:

onR1needcomandinroutermode

area12authenticationmessage-digest

Ans1)R1

Ans2)ipv4OSPF

Ans3)ipospfauthenticationmessage-digestcommandmustbegivenons0/0/0

Replacethe‘Answer’withfollowingstatement

OnR1needthecommandininterfaceconfigurationmodeofS0/0/0(notinroutermode)

Symptomsofaboveticketareasbelow:

-

1-Nooneisabletoping10.1.1.1(R1’sS0/0/0int)exceptR2.

2-Client1isabletopingupto10.1.1.2(R2’sS0/0.12int).

3-‘Shipospfneighbor’commandonR1willnotshowanyneighbor

4-‘shiprouteospf’commandonR1willnotshowanyOSPFroute

Ticket2

HSRP:

DSW1doesnotbecomeactive.

confondw1:

track1iproute10.28.123.123255.255.0.0metricthreshold

thresholdmetricup1down2

!

track10iproute11.11.11.11255.255.255.0metricthreshold

thresholdmetricup63down64

interfaceVlan10

ipaddress10.2.1.1255.255.255.0

standby10ip10.2.1.254

standby10priority200

standby10preempt

standby10track1decrement60

Answer:

(useIPv4Layer3Topology)

Ondsw1interfacevlan10moderun:

nostandby10track1decrement60

standby10track10decrement60

(ipfortrackcommandnotexactforrealexam)

Ans1)DSW1

Ans2)HSRP

Ans3)deletethecommandwithtrack1andenterthecommandwithtrack10.

 

Ticket3

configurationonR1:

routerbgp65001

nosynchronization

bgplog-neighbor-changes

network209.65.200.224mask255.255.255.252

neighbor209.56.200.226remote-as65002

noauto-summary

checkbgpneighborship.****showipbgpsum****

Theneighbor’saddressintheneighborcommandiswrongunderrouterBGP.(useipv4Layer3)

Answer:

needchangeonroutermodeonR1neighbor209.65.200.226

Ans1)R1

Ans2)BGP

Ans3)deletethewrongneighborstatementandenterthecorrectneighboraddressintheneighborcommand(change209.56.200.226to209.65.200.226)

Correctioninproblemstatement:

-

IntheaboveticketR1andallothersareabletoping209.65.200.226butnottheWebServeronly.ThisisbecauseR1isdirectlyconnectedto209.65.200.226andBGPisnotrequiredinordertopingdirectlyconnectednetworkandassoonasR1knowsabout209.65.200.224networkallotherdevicesarealsoabletoping209.65.200.226,sincetheyarecomingtoR1foranyunknownroute,becauseofdefaultroutepropagatethroughR1′sOSPF(using‘default-informationoriginatealways’command).HoweverWebServerisnotaccessibleuntilBGPconfiguredproperlybetweenR1andISP(209.65.200.226)becauseonlythenR1willreceivetheinformationaboutWebServer’snetwork.

Followingarethesymptomsofaboveticket:

-

1-NooneisabletopingWebServer.

2-Client1andallotherscanpingupto209.65.200.226.

3-‘shiprouteBGP’,youwillnotseeanyBGProute.

4-‘shipbgpneighbor’onR1,youwillnotseeanyactiveBGPneighbor.

 

Ticket4

Clientisnotabletopingthewebserver,buttherouterscanpingtheserver.NATproblem.(useipv4Layer3)

problemonR1Natacl

Answer:

addtoacl1permitip10.2.1.00.0.0.255

Ans1)R1

Ans2)IPNAT

Ans3)underNATaccesslist,enterthecommandpermit10.2.0.00.0.255.255

R4,R3,R2canping209.65.200.241

 

Ticket5

Clientisnotabletopingtheserver.ExceptforR1,nooneelsecanpingtheserver.(useipv4Layer3)

Problem:

onR1aclblockingip

aclsomethinglikethis:

deny10.2.1.0

deny10.1.4.0

deny10.1.1.0

Answer:

addpermit209.65.200.241commandtoR1′sACL

Ans1)R1

Ans2)IPv4Layer3Security

Ans3)Addpermit209.65.200.2240.0.0.3toR1′sACL

EvenR1alsowouldnotbeabletopingthewebserverorISP(209.65.200.226).SinceexplicitdenyofthisACLwillnotallowareplytocomebackintoR1(sincethisACLisappliedinthe‘in’direction)fromoutsideuntilapermitentryisincludedinACL.ThiswillalsocausetheBGPneighborrelationshipgetdown.

Youwillseeonepermitentryforwebserveronly,whichisnotenough.YouwillseethecontentsofthisACLasbelow.

ipaccess-listextendededge_security

permitiphost209.65.200.241any

denyip10.2.0.00.0.255.255any

denyip10.1.0.00.0.255.255any

denyiphost127.0.0.1any

Thatswhyanentryof‘permit209.65.200.2240.0.0.3any’isrequiredtosolvethisproblem.Andbytheway,theentriesfor10.x.x.xnetworkisneitherhaveanyeffectnorrequiredinthisACL,theyputtheseuponlytoconfusethecandidates.

R4,R3,R2cannotping209.65.200.226

Ticket6

Client1isnotabletopingtheserver.UnabletopingDSW1(UseL2Diagram).

VlanAccessmapisappliedonDSW1blockingtheipaddressofclient10.2.1.3

Ans1)DSW1

Ans2)Vlanaccessmap

Ans3)Novlanfilter10

Symptomsofthisticket.

1-Client1isgettingthecorrectIPaddressfromDHCP(i.e10.2.1.3)

2-ButClient1isunabletopingDSW1.

3-Client1isunabletopingFTPServer(10.2.2.10)

 

Ticket7

Client1isnotabletopingtheserver

Situation:

UnabletopingDSW1(Userlayer2).

OnASW1portsecuritymac0000.0000.0001,interfaceinerr-disablestate

Answer:

onasw1deleleportsecurity&dooninterfacesshutdown,noshutdown

Ans1)ASW1

Ans2)Portsecurity

Ans3)Onfa1/0/1andfa1/0/2dodisableportsecurityanddoshut,noshut.

Symptomsforthisticket:

-

1-Client1isgetting169.x.x.xipaddress

2-Client1isunabletopingClient2aswellasDSW1.

3-‘shinterfacesfa1/0/1′willshowfollowingmessageinthefirstline

‘enFastEthernet1/0/1isdown,lineprotocolisdown(err-disabled)’

4-‘shrunning-config’,youwillsee‘switchportport-securitymac-address’0000.0000.0001′configuredunderfa1/0/1.

 

Ticket8

Client1isnotabletopingtheserver

Situation:

UnabletopingDSW1&inportchannelconfiguratioinofASW1vlan10isnotallowed.(UseL2Diagram)

OnASW1,oninterfacesfa0/1,fa0/2switchportaccessvlan1

Answer:

onASW1changeswitchportaccessvlan1toswitchportaccessvlan10

Ans1)ASW1

Ans2)Accessvlan

Ans3)givecommand:

interfacerangefa1/0/1-/2switchportaccessvlan10

Kindlycorrectthesituationintheaboveticket.Becauseyouhavementionedsituationofanotherticketandsolutionofanother.Thecorrectsituationis:

-

Situation:

ClientsareunabletopingDSW1,becausetheiraccessportsaren’tconfiguredforVLAN10onASW1(bothportsareinthedefaultVLAN1).

Symptoms:

-

1-Clinetsaregetting169.x.x.xIpaddress.

2-Clinet1canpingClient2andviceversa.

3-‘shrunning-config’commandwillnotdisplay‘switchportaccessvlan10′undertheinterfacesfa1/0/1andfa1/0/2.

 

Ticket9

cantpingtowebserver209.65.200.241

Situation:

UnabletopingDSW1&inportchannelconfiguratioinofASW1vlan10isnotallowed.(UseL2Diagram)questionwasaboutEtherChanel

clientcan’tobtainipaddress(169.x.x.x)

onASW1trunksallowvlan20,200

Answ:

onportchannel23giveswitchporttrunkallowedvlan10,200

Ans1)ASW1

Ans2)Switchtoswitchconnectivity

Ans3)onportchannel23giveswitchporttrunkallowedvlan10,200

Symptomsofaboveticket:

-

1-Client1isgetting169.x.x.xipaddress.

2-Clinet1canpingClient2andviceversa.

3-‘shinterfacestrunk’youwillnotseevlan10inPO13andPO23underallowedVlansontrunk

 

Ticket10

Client1isnotabletopingtheserver

Situation:

UnabletopingR4fastethernetportfromdsw1.

CheckipeigrpneighborsfromDSW1youwillnotseeR4asneighbor.(useipv4Layer3)

OnDSW1&DWS2theEIGRPASnumberis10(routereigrp10)butonR4itis1(routereigrp1)

Answ:

changerouterASonR4from1to10

Ans1)R4

Ans2)IP4EIGRP

Ans3)ChangeeigrpASnumberfrom1to10

Kindlycorrecttheabovesituationasperfollowing:

-

DSW1isstillabletopingR4′sfastEthernetinterface,becausethisinterfaceisdirectlyconnectedtoDSW1,sonomatterEIGRPisconfiguredcorrectlyornotDSW1canpingfa0/0interface(10.1.4.5).HoweverclientsandDSW1willnotbeabletopingR4′sS0/0/0.34interface(10.1.1.10).Becausetoreachthatside,itisrequiredtoworkEIGRPproperly.Followingarethesymptomsforaboveticket:

-

1-ClientsandDSW1isunabletopingR4′sS0/0/0/0.34interface

2-ClientsandDSW1canpinguptoR4′sFa0/0interface.

3-‘shipeigrpneighbor’onDSW1youwillnotseeR4asneighbor.

4-‘shiproute’onDSW1youwillnotseeany10.x.x.xnetworkroute.

 

Ticket11

Client1isnotabletopingtheserver

Situation:

UnabletopingserialinterfaceofR4fromtheclients.

OnR4inroutereigrp:

redistributeospf1route-mapEIGRP_to_OSPF

BUTroute-mapwasnamed:

route-mapEIGRP->OSPF

Answer:

changeinroutereigrprouter-mapname

Ans1)R4

Ans2)routeredistribution

Ans3)changethenameoftheroute-mapundertherouterEIGRPorrouterOSPFprocessfrom‘to’to‘->’.

 

Ticket12

IPV6loopbackofR2cannotbepingedfromDSW1’sloopback.

Situation:

ipv6ospfwasnotenabledonR2’sserialinterfaceconnectingtoR3.(useipv6Layer3)

Answer:

interfaceconfigurationmode:

ipv6ospf6area12

Ans1)R2

Ans2)IPV6ospf

Ans3)ontheserialinterfaceofR2,enterthecommandipv6ospf6area0(makesuretochecktheIPV6topologybeforechooseAnswer3becausetheoptionslooksimilar)

Kindlyupdatethequestionstatement.Theabovementionednotaspertheexam.Althought

展开阅读全文
相关资源
猜你喜欢
相关搜索

当前位置:首页 > 高中教育 > 语文

copyright@ 2008-2022 冰豆网网站版权所有

经营许可证编号:鄂ICP备2022015515号-1