CCNP Ticket

You might also like

Download as docx or pdf
Download as docx or pdf
You are on page 1of 8
1 Home > Tike 1 = OSPF Authentication Ticket 1 - OSPF Authentication i varen zon, 2089 Gaim rswoor v2 560m comments 1.clent i unable to ping R's sel interface fom the een: ‘Problem was dsnble authentication on Ri, chesk where authentication is not pen under router os oF RA. (use inv ayers) ‘Configuration of 1: Incorface Sea}/0/0 desciption Link to RZ ip eddress 10:1.1.1 755.255.255.257 'p matinee encapsulation ramo-elay ip cept message digest key 1 mds TSHOOT ip oxpi network point-to-point router oso outer id 1.1.1 gradjaceney-changes retwork 10.1.10.00.0.0.288 aren 12 detaut-nformaton ongmate ainays {Configuration of 2 interface Seral/0/0.12 point-to-point ip address 10.1.1.2 255.255.255.252 ‘> capt authentication messoge digest ip cept message digest key 1 mds TSHOOT ‘Answer: on Ri need command “ip ospf authentication message-cia ans) a2 ‘Ane2) IP OSPF Routing ‘ans3) Enable OSPF authentiation on the s0/0/0 intertace using the “ip ospf authentication message digest” command © Home > Ticket 16 -IPv5 Pg OSPF Rediatnbuton Ticket 16 - IPv6 RIPng OSPF v3 Redistribution merch te, 205 yin TSHOOT v2 12 ot comments Problem: Loopback address on Rt (2026::114:1) not able to ping the loopback address on OSW2 (2026::102:1). ‘configuration of 4: inve router acpt 6 Tog-adjacency-changes ‘edicuibute osp 6 metic 2 incude-connected 1082) Ipws OSPF Routing ‘n083) Under ipv6 ospf process add the vedistibute rip RIP_Zone indude-connected command " Home > Teket 2 ~ HSRP Track Ticket 2—HSRP Track isons arm, 2015 Gaim rsHOOT v2 {0 Gow comment SRP was configured on DSW1 & 05W2. DSW1 is configured to be active but & does not become active Configuration of DSW1: track 1p oute 102.25.128 255.255.255.224 metic tveshold threshold metricup 1 down 2 track 10 ip route 10:1.21.128 265.265.295.224 metric threshold threshold metric up 63 down 64 interface Mento ‘peddrexe 10.2.1.1 755.255.2550 Standby 10 9 102.1.258 standby 10 prirty 200 standby 10 precmet standby 10 rack 1 docement 60 Answer: (ure Ped Layer 3 Topology) (on DSW interface van 20 rade, type these commands fo standby 10 track 1 decrement 60 Standby 10 track 10 decerent 60 (ip for track command not exact for real exam) Note: 10.1.21.129 x the IP addreas ofa loopback interface on RA. Thi IP belongs to subnet 10.1.21.120/27, net) DSW |ane2) HSA [Ane3) delete the command with tack 1 and enter the command with tack 10 (standhy 10 tack 10 decrement 60) Note: For more information about 1P route tracking and why the command “Uweshold metic up 63 down 64” is used hee please read this tatorial: htp:furww.networdut Tike 9 = BGP Neighbor Ticket 3 - BGP Neighbor ‘Toren 20m, 20:5 ie reHOOT v2 S52 Go comments Problem: Cheot ix able to ping 208.65.200.226 but cant ping the Web Server 209.65.200.244 Configuration of 1: router bap 65001 to synchronization ‘bap log-neighbor changes network 209.65 200.224 mask 295.258.255.282 ‘neighbor 209.56.200.226 remote-as 65002 check bap neighborship. **** show ip bap sum*==* ‘The nelghtor®e addreas in the neighbor command ie rong under router BCP (use inv Layer'3) ‘Answer: nesé change on router mode on Ri neighbor 209.65.200.226 fans) Rt ‘ns2) 86? ‘ans3) delote the wrong neighbor statomont and entarthe correct neighbor addresa in the neighbor command (changs “neighbor 209.56.200.226 ramete-26 65002" to “neighbor 209.65.200.226 ramote 35 65002") 9 Home > Tikat 4 — MAT ACL, Ticket 4 — NAT ACL Si merch anh, 201s Gin Tenor v2 ecw annem Cchent 2 6.2 are notable to ping the web server 209.65.200.241, but al the routers & DSW1,2 can ping the server. NAT problem. (ure put Layer 3) problem on RE Nat ac Configuration of Rt ipnat inside source bt nat_pool interface s0/0/1 overload ip accens-at standard nat_post Interface serl0/0/2 ip adaress 209,65.200.225 255.255.255.252 ib natoutside interface Serialayojo.12 ip address 10... 255.255.255.252 pf meseage-digest-key 1 mls TSHOOT pf authentication mestage-digest anes) RL ‘nng2) NAT ‘nngs) Ad the commend permit 10.2.0.0in the nat_pool acess ist 9 Howe > Teket 5 =AL ACL Ticket 5- R1 ACL Simerh ach, 2015 yin ToHOOT v2 (Gee comments CCentis not able to ping the server. Except for Ri, no one elee can ping the server: (use ipwa Layer 3) Prablomon Ri ad backing ip ‘Configuration on Rt interface Seriatorort ‘eserption Link to ISP ip address 209 65.200.224 255.255.255.252 ipnat outside ip access-group edge_tecunty ix ip aconse-et extended edge_secuty ‘deny ip 172.16.0.00.15.255.255 any ‘deny ip 192.168.0.00.0.255.255 any ‘deny 127.0.0.00,255.255.255 any permitip host 209.65.200.241 any ‘newer: add pormut wp 209.65.200.224 0.0.0.3 any command to fs ACL Ans) RE ‘ans2) IPs Layer 3 Security ‘angs) Under the ip access list extended edge: securty configuration add the permit ip 209.65.200.224 0.0.0.3 any command Note: Ths the only ticket the extended access-et edge_secunty exists. In other tickets, the acess-Ist 30 is applied tothe mound arection of SO//1 of RT 19 Home > Ticket 6 ~ VLAN iter Ticket 6 — VLAN filter merch 2m 2015 sin TsHOOT 2 50 to comments (Gone ia not able to ping the server. Unable te ping OSW1 or the FIP Serve(use L2 Diagram), van Aosess map i apnied on DSW! biodking the p address of lent 10.2.2.9 Configuration on DSW Vian access-map testt 10 action drop rmateh ip addrese 10 Van accoss-map toctt 20, aaion drop match paddrese 20, an aczess-map testt 30 ‘acion foward rratch padiress 30, ae aczens-rmp teat 40 dation fomara on fier tests vlan 20 access-ist 10 permt 10.2.1. ict 20 permit 102.108 ict 30 pormit 1.2.1.0 00.0255, interface WANS ipeddrexe 10.7.1.1 255.255.2550 ‘nex) DSW ‘ans2) VIAN ACL/Port ACL ‘ang3) Under the global configuration mode enter no Van iter testi vent 10 command. Nota: Afar choosing DSW for Ans1, next page (fr Anc2) you have to sealldawn te find the VLAN ACL/POF® ACL option. ‘he seal bar only appoara inthis ticket and & very diffiltto be eaen. © tome >Teket 7 ~ Port Security Ticket 7 — Port Security merch 2mm, 2015 Sain TsHOOT 2 Ores cent ic unable to ping Chent 2 as well as DSW. The commend sh interfaces fe1/0/1"willshow folowing message in the fst tie “FastEthernet/0/1 = down, ine protoca in down (er~diabledy ‘on ASW! port-ancuily mee 000.000.0004, inesface in er-nnble state Configuration of ASW interacefanjo/t ‘Swtchport access vlan 10 Switchport mode acsees swrtchpost port-securty “Swiechport port secunty mac address 0000,0000.0001 ‘Answer: on ASW delele port security & do on iterfaces shutdown, no shutlown oat) asw 1032) Port security ‘083) 8 Configuration mode, using the interface range F21/0/1 ~2, then no ewitchportport-secutty, flowed by ‘thutdown, ao shutdown interface configuration commands, © ome > Teket 8 ~ Switchport WAN 10 Ticket 8 — Switchport VLAN 10 Sl merch 2a 2015 Sain TSHOOT v2 Ores Gone 1.2 cant ping OsW1 or FIP Server but thay are able to sing each athe sStuaton: in port chan ‘Configuration of ASW. interface Fastethemeti/o/t Swichport mode acsoss Switchport acess van 1 configuration of ASW: van 10/6 not allowad. (us interface FastEthemett/0/2 wichport made accee= ‘swichport acoess van 1 (On ASW, om interfaces fa/t,F0/2 switchport access wnt ASV change swrtchport access vlan 1 to switchport access van 10 poatysina pean ‘essai command: interface range f91/0/1-/2 &ewitehport access vlan 10 Home > Tekot 9 - Switcher rank Ticket 9 — Switchport trunk march an 2013 Gj rShoor v2 (2G ts comments ‘chent 18 2 can ping each other but they are unable to ping DSW or FIP Server (Use L2/ Diagram) ‘Configuration of ASW intertoe Portchannell3 ‘twzhpert mode trunk Swtchport trunk allowed van 3-9 interfce PoriChanne23 wchport made trank wichport trunk alowed van 3-9 interce FastEthemett (0/1 ‘wechpert mode acces swichport acsose van 10 interface Fastethemett/0/2 swichport made acces wichport acceas vlan 10 port channel 13,23 disables al vans and give switcyport trunk allowed vlan 10,200 moss pswa ‘032}5witah to ewitch connectivity ‘pos3}int range portchannell3,portchannel2s ‘witzhport trunk allowed Van none wichport trunk alowed van 10,200 19 Home > Ticket 10 ~ EIGRP AS Ticket 10 - EIGRP AS Simerch ais 2015 Sym ToHOOT v2 52 60 9 comments Cent sie not able to ping the Webserver DSW cen ping fa0/t of Ra but cant ping 30/0/0.34 ‘chodk' ciao neiahbore from USW you wil not see R# 28 neighbor {ueeipv4 Layer 3) "Show ip route" on DSW3 you will not tee any 10.xa0% network route (on OSW1 & DWSZ the EIGRP AS number if 10 (router egrp 10) but on itis 2 (router sigrp 1) ‘newer: change router AS on R4from 1 to 10 nes) Ra ‘ans2) EIGRP ‘ans3) Change EIGRP AS numbertrom to 10 © ome > Teket 11 - OSPF to ELGRP Ticket 11 —- OSPF to EIGRP- Smack 202015 Sain TaHOOT 2 Sires Gone 1 ie not abo to ping the webesrver [BSW: can ping fa0/s of Ra, However csnte and DSW can ping Ra's $0/0/0.3 interface (40.4.1.10) (On fA in router ciorst router cig 10 network 10.1.4.5 0.0.00 Fedistrbute opt metric 100 10 255 1 1500 routesnap OSPF to EIGRP redistribute eigrp £0 subnets Imotch address 2 esi) 4 ‘3ns2} IP va Route Redistribution ‘ans3) Under the EIGRP process, delete the redistribute ospf 4 route-map OSPF. to EIGRP command and enter the redistribute ospf 1 route-map OSPF->EIGRP coinmand. 1 Home > Tket 12 — IPs OSPF Ticket 12 — IPv6 OSPF SA merch sth 2018 yin TsHoor ve ae Dswa & 4 ant ping 82's loopback interface or £0/0/0.12 W's addres fae not an OSP#v3 neighbor on R SStuation:fov6 ospf wae not enabled on R's serial interface connecting to R3. (use ipvs Layer 3) ‘conhguration of 2 inv router asp outer! 2222 sanz Configuration of RS ‘px router oxpl 6 intertace 20/0/0223 ‘pve aderoas 2026: love osef 6 area 0 Answer: Ininterface onfgutation made of =0/0/0.25 on 82: inv ospF 6 area 12 pont) 2 4022) TP OSPF Routing {ns8) on the terial interface of R2, enter the command ipvG amp 6 area 0 (notice that tix rea 0°, notYeren 12°) 1 ome > Tikot 19 - BHCP Range Ticket 13 - DHCP Range Sth march som, 2035 yn 15H00r 2 \S Got comments In thin ticket, you see the “ip dhep exch 10.2.11-1.10.2.1.259° then the DHCP range hes been misconfigured Configuration on RA: ip dhep exchuded-address 102.1.1 102.1.253 net) a4 ‘Ane2) IP DHCP Server ‘ane3) on Ré delete fp dhep exchided-addvess £0.24.4 10.2.1.259 and apply ip chen exched-address 10.2.1.1 10.2.1.2 1 Nome Ticket 14 ~ EIGRP Passive Interface Ticket 14 — EIGRP Passive Interface vrch:7m, 2085 Gin Tenor 2 Dehn the neighborship between RA and OSW1 wasnt estabied Chant 1 cant ping RA ‘Configuration on RA: routereigm 10 Dessive terface default redistribute ospF 1 route-rap OSPF->E1GRP network 10.144 0.0.0.3 network 10.148 0.0.0.3 hetwork 10.1.21.128 0.0.0.8 ‘efauk-metic 10000 100 255 4 10000 fo auto-summary poawort) Re ‘peawer 2) 14 EIGRP Routing ‘nawer 2) enter no pasehve terface for interfaces connected to DSW under EIGRP proces {ofo, something tke this) (erin interface fo/t and Note: There is 2 loopback interface on this device which has an 1? adres network £0.4.21.128 0.0.0.3" command ‘of 10..23.129 20 we have te indude the + jst for your information, in fac Clients 1 & 2m this cket CANNOT receive IP addresses from DHCP Server beenuse DSW: cannot reach 10.1.21.129 (an loopback interface on RA) because ofthe “passive-nterfacedefout” comand. But in the examyou willsce that Cents 1 8 2 can stl get thet IP addresses! Its a bug nthe exam. 1 Home > Tidet 45 ~1Pv6 GRE Tunnel Ticket 15 —IPv6 GRE Tunnel Stmeren tem 2018 querstoor 2 Gauaenae Problem: Loopback address on RI. (2026i:111:1) isnot able to ping the loopback address on DSW? (202 Configuration of 5: Interface Tunnel no ip address Ipv6 address 2026::34:1/122 Ibv6 enable ibve osof e area 34 tunnel source Serisi0/0/0.34 tunnel destination 10.14.20 tunnel mode ipvs 02:1). Configuration of 4: interface Tunnel34 no ip address ipve address 2026::34:2/122 ipvs enable ipve ospf 6 area 34 funnel source SerilO/O/0 tunnel destination 10.4.9 dns) 83 ‘ane2) Ind and Tove interoperability ‘ane3) Under the interface Tunne!34, remove tunnel made pv command

You might also like