Professional Documents
Culture Documents
Hardrock Hallelujah3 v4.0
Hardrock Hallelujah3 v4.0
Scenario
Yoshida Heavy Industries (YHI) requires a network setup for a new branch office. The
network design calls for Layer 2 EtherChannels, trunk ports, access ports, and routed ports
using Catalyst 2950 and 3550 switches and Cisco 2600 series routers. YHI also requires a
fault tolerant Internet link. Therefore, a backup link to the ISP is required. The backup link
will become active only if access to the Internet through the 3550 switch is lost due to
failures.
The branch office staff consists of an accountant, a secretary, a manager, delivery drivers,
and salespeople. Yoshida management expects staffing at this branch office to double in
the first year of operation. The accountant, the secretary, and the manager will have their
PCs connected to VLAN 10 on Access1. The delivery drivers and the salespeople will have
their PCs connected to VLAN 20 on Access2. The branch office servers will be connected
to VLAN 30 on Collapsed-Core. All Layer 2 control protocol traffic is sent and received on
default management VLAN 1.
1 - 82 CCNP 3: Multilayer Switching v 4.0 – Skills-Based Assessment Version 1 - Solutions Copyright © 2004, Cisco Systems, Inc.
Multiple Instance Spanning Tree Protocol (MST) will be used in combination with PortFast
and BPDU Guard. Multiple HSRP groups will be implemented so that exactly one router is
active at any given time for all VLANs. Router-on-a-stick will be implemented to allow inter-
VLAN routing when Backup is the active HSRP router.
Redundancy will be implemented by using Spanning Tree, HSRP, and independent
connections to the ISP.
Generic Tasks
• Physically connect the network devices according to the network diagram. Ensure that
the correct cables are connected to the appropriate ports.
• On all devices, configure the following:
− Telnet support with the password cisco
− The privileged EXEC mode password cisco
YHI requires VLANs and VTP to be configured within the switched network.
3. Configure the VLAN 1 management VLAN on all the switches using the network
10.0.1.0/24.
− Ensure that the switches can ping each other using their management VLAN IP
addresses and troubleshoot if necessary.
Fa0/9 - 12,
Collapsed-Core Fa0/1 - 2 Fa0/3 - 4
Fa0/14 – 24
2 - 82 CCNP 3: Multilayer Switching v 4.0 – Skills-Based Assessment Version 1 - Solutions Copyright © 2004, Cisco Systems, Inc.
Spanning-Tree
YHI requires Spanning-Tree protection to prevent switching loops. They also want PortFast
configured on all access ports:
2. Configure PortFast:
− Enable PortFast for all non-trunk access ports.
− Configure each PortFast enabled port in the network so that it will transition to
error-disabled state if an unauthorized device generating BPDUs is attached.
To enable inter-VLAN routing, YHI requires that the Collapsed-Core switch be configured to
support SVIs and that the Backup router be configured as a router-on-a-stick. Finally, HSRP
will be configured on Backup and Collapsed-Core:
4. Configure a valid IP address for Host 1 in VLAN 10, Host 2 in VLAN 20, and Server
in VLAN 30.
6. Configure HSRP interface tracking so that Backup becomes the active router if the
FastEthernet link between Collapsed-Core and ISP goes down.
3 - 82 CCNP 3: Multilayer Switching v 4.0 – Skills-Based Assessment Version 1 - Solutions Copyright © 2004, Cisco Systems, Inc.
Check List
2 Ensure that Host 1, Host 2, and Server can ping each other.
Verify HSRP with continuous pings to test that Host 1 and Host 2 can reach the
loopback address 1.1.1.1/24 whenever any combination of cables is
disconnected from the following ports on Collapsed-Core:
− Fa0/5
3
− Fa0/6
− Fa0/7
− Fa0/8
− Fa0/13
4 - 82 CCNP 3: Multilayer Switching v 4.0 – Skills-Based Assessment Version 1 - Solutions Copyright © 2004, Cisco Systems, Inc.
CCNP 3 Skills-Based Final Exam 1 – Sample Final
Configurations
Sample Router Configurations
The following is configuration output for each networking device. It includes a sample
running configuration:
ISP#show running-config
Building configuration...
5 - 82 CCNP 3: Multilayer Switching v 4.0 – Skills-Based Assessment Version 1 - Solutions Copyright © 2004, Cisco Systems, Inc.
!
interface Serial0/1
no ip address
shutdown
!
ip classless
ip route 10.0.0.0 255.0.0.0 192.168.1.2 10
ip route 10.0.0.0 255.0.0.0 192.168.0.2 20
ip http server
!
!
!
dial-peer cor custom
!
!
!
!
!
line con 0
line aux 0
line vty 0 4
login
!
end
ISP#
ISP#show ip route
Codes: C - connected, S - static, I - IGRP, R - RIP, M - mobile, B - BGP
D - EIGRP, EX - EIGRP external, O - OSPF, IA - OSPF inter area
N1 - OSPF NSSA external type 1, N2 - OSPF NSSA external type 2
E1 - OSPF external type 1, E2 - OSPF external type 2, E - EGP
i - IS-IS, L1 - IS-IS level-1, L2 - IS-IS level-2, ia - IS-IS inter
area
* - candidate default, U - per-user static route, o - ODR
P - periodic downloaded static route
6 - 82 CCNP 3: Multilayer Switching v 4.0 – Skills-Based Assessment Version 1 - Solutions Copyright © 2004, Cisco Systems, Inc.
Backup#show running-config
Building configuration...
7 - 82 CCNP 3: Multilayer Switching v 4.0 – Skills-Based Assessment Version 1 - Solutions Copyright © 2004, Cisco Systems, Inc.
interface Serial0/0
ip address 192.168.0.2 255.255.255.0
no fair-queue
!
interface BRI0/0
no ip address
encapsulation hdlc
shutdown
!
interface Serial0/1
no ip address
shutdown
!
ip classless
ip route 0.0.0.0 0.0.0.0 192.168.0.1
ip http server
!
!
!
dial-peer cor custom
!
!
!
!
!
line con 0
exec-timeout 0 0
line aux 0
line vty 0 4
login
!
end
Backup#show ip route
Codes: C - connected, S - static, I - IGRP, R - RIP, M - mobile, B - BGP
D - EIGRP, EX - EIGRP external, O - OSPF, IA - OSPF inter area
N1 - OSPF NSSA external type 1, N2 - OSPF NSSA external type 2
E1 - OSPF external type 1, E2 - OSPF external type 2, E - EGP
i - IS-IS, L1 - IS-IS level-1, L2 - IS-IS level-2, ia - IS-IS inter
area
* - candidate default, U - per-user static route, o - ODR
P - periodic downloaded static route
Backup#
8 - 82 CCNP 3: Multilayer Switching v 4.0 – Skills-Based Assessment Version 1 - Solutions Copyright © 2004, Cisco Systems, Inc.
Collapsed-Core#show running-config
Building configuration...
9 - 82 CCNP 3: Multilayer Switching v 4.0 – Skills-Based Assessment Version 1 - Solutions Copyright © 2004, Cisco Systems, Inc.
switchport access vlan 20
no ip address
duplex full
speed 100
spanning-tree portfast
spanning-tree bpduguard enable
!
interface FastEthernet0/4
switchport access vlan 20
no ip address
duplex full
speed 100
spanning-tree portfast
spanning-tree bpduguard enable
!
interface FastEthernet0/5
switchport trunk encapsulation dot1q
switchport mode trunk
no ip address
duplex full
speed 100
channel-group 1 mode on
!
interface FastEthernet0/6
switchport trunk encapsulation dot1q
switchport mode trunk
no ip address
duplex full
speed 100
channel-group 1 mode on
!
interface FastEthernet0/7
switchport trunk encapsulation dot1q
switchport mode trunk
no ip address
duplex full
speed 100
channel-group 2 mode on
!
interface FastEthernet0/8
switchport trunk encapsulation dot1q
switchport mode trunk
no ip address
duplex full
speed 100
channel-group 2 mode on
!
interface FastEthernet0/9
switchport access vlan 30
no ip address
duplex full
speed 100
spanning-tree portfast
spanning-tree bpduguard enable
!
interface FastEthernet0/10
switchport access vlan 30
no ip address
duplex full
speed 100
10 - 82 CCNP 3: Multilayer Switching v 4.0 – Skills-Based Assessment Version 1 - Solutions Copyright © 2004, Cisco Systems, Inc.
spanning-tree portfast
spanning-tree bpduguard enable
!
interface FastEthernet0/11
switchport access vlan 30
no ip address
duplex full
speed 100
spanning-tree portfast
spanning-tree bpduguard enable
!
interface FastEthernet0/12
switchport access vlan 30
no ip address
duplex full
speed 100
spanning-tree portfast
spanning-tree bpduguard enable
!
interface FastEthernet0/13
no switchport
ip address 192.168.1.2 255.255.255.0
duplex full
speed 100
spanning-tree portfast
spanning-tree bpduguard enable
!
interface FastEthernet0/14
switchport access vlan 30
no ip address
duplex full
speed 100
spanning-tree portfast
spanning-tree bpduguard enable
!
interface FastEthernet0/15
switchport access vlan 30
no ip address
duplex full
speed 100
spanning-tree portfast
spanning-tree bpduguard enable
!
interface FastEthernet0/16
switchport access vlan 30
no ip address
duplex full
speed 100
spanning-tree portfast
spanning-tree bpduguard enable
!
interface FastEthernet0/17
switchport access vlan 30
no ip address
duplex full
speed 100
spanning-tree portfast
spanning-tree bpduguard enable
!
interface FastEthernet0/18
11 - 82 CCNP 3: Multilayer Switching v 4.0 – Skills-Based Assessment Version 1 - Solutions Copyright © 2004, Cisco Systems, Inc.
switchport access vlan 30
no ip address
duplex full
speed 100
spanning-tree portfast
spanning-tree bpduguard enable
!
interface FastEthernet0/19
switchport access vlan 30
no ip address
duplex full
speed 100
spanning-tree portfast
spanning-tree bpduguard enable
!
interface FastEthernet0/20
switchport access vlan 30
no ip address
duplex full
speed 100
spanning-tree portfast
spanning-tree bpduguard enable
!
interface FastEthernet0/21
switchport access vlan 30
no ip address
duplex full
speed 100
spanning-tree portfast
spanning-tree bpduguard enable
!
interface FastEthernet0/22
switchport access vlan 30
no ip address
duplex full
speed 100
spanning-tree portfast
spanning-tree bpduguard enable
!
interface FastEthernet0/23
switchport access vlan 30
no ip address
duplex full
speed 100
spanning-tree portfast
spanning-tree bpduguard enable
!
interface FastEthernet0/24
switchport access vlan 30
no ip address
duplex full
speed 100
spanning-tree portfast
spanning-tree bpduguard enable
!
interface GigabitEthernet0/1
no ip address
!
interface GigabitEthernet0/2
no ip address
12 - 82 CCNP 3: Multilayer Switching v 4.0 – Skills-Based Assessment Version 1 - Solutions Copyright © 2004, Cisco Systems, Inc.
!
interface Vlan1
ip address 10.0.1.2 255.255.255.0
no ip redirects
standby 1 ip 10.0.1.1
standby 1 priority 200
standby 1 preempt
standby 1 track FastEthernet0/13 150
!
interface Vlan10
ip address 10.0.10.2 255.255.255.0
no ip redirects
standby 10 ip 10.0.10.1
standby 10 priority 200
standby 10 preempt
standby 10 track FastEthernet0/13 150
!
interface Vlan20
ip address 10.0.20.2 255.255.255.0
no ip redirects
standby 20 ip 10.0.20.1
standby 20 priority 200
standby 20 preempt
standby 20 track FastEthernet0/13 150
!
interface Vlan30
ip address 10.0.30.2 255.255.255.0
no ip redirects
standby 30 ip 10.0.30.1
standby 30 priority 200
standby 30 preempt
standby 30 track FastEthernet0/13 150
!
ip classless
ip route 0.0.0.0 0.0.0.0 192.168.1.1
ip http server
!
!
!
line con 0
line vty 0 4
login
line vty 5 15
login
!
end
Collapsed-Core#
Collapsed-Core#show ip route
Codes: C - connected, S - static, I - IGRP, R - RIP, M - mobile, B - BGP
D - EIGRP, EX - EIGRP external, O - OSPF, IA - OSPF inter area
N1 - OSPF NSSA external type 1, N2 - OSPF NSSA external type 2
E1 - OSPF external type 1, E2 - OSPF external type 2, E - EGP
i - IS-IS, L1 - IS-IS level-1, L2 - IS-IS level-2, ia - IS-IS inter area
* - candidate default, U - per-user static route, o - ODR
P - periodic downloaded static route
13 - 82 CCNP 3: Multilayer Switching v 4.0 – Skills-Based Assessment Version 1 - Solutions Copyright © 2004, Cisco Systems, Inc.
C 10.0.10.0 is directly connected, Vlan10
C 10.0.1.0 is directly connected, Vlan1
C 10.0.30.0 is directly connected, Vlan30
C 10.0.20.0 is directly connected, Vlan20
C 192.168.1.0/24 is directly connected, FastEthernet0/13
S* 0.0.0.0/0 [1/0] via 192.168.1.1
Collapsed-Core#
14 - 82 CCNP 3: Multilayer Switching v 4.0 – Skills-Based Assessment Version 1 - Solutions Copyright © 2004, Cisco Systems, Inc.
Access1#show running-config
Building configuration...
Access1#show run
Building configuration...
15 - 82 CCNP 3: Multilayer Switching v 4.0 – Skills-Based Assessment Version 1 - Solutions Copyright © 2004, Cisco Systems, Inc.
channel-group 1 mode on
!
interface FastEthernet0/4
switchport mode trunk
duplex full
speed 100
channel-group 1 mode on
!
interface FastEthernet0/5
switchport mode trunk
duplex full
speed 100
channel-group 2 mode on
!
interface FastEthernet0/6
switchport mode trunk
duplex full
speed 100
channel-group 2 mode on
!
interface FastEthernet0/7
switchport mode trunk
duplex full
speed 100
spanning-tree portfast
spanning-tree bpduguard enable
!
interface FastEthernet0/8
switchport access vlan 30
duplex full
speed 100
spanning-tree portfast
spanning-tree bpduguard enable
!
interface FastEthernet0/9
switchport access vlan 30
duplex full
speed 100
spanning-tree portfast
spanning-tree bpduguard enable
!
interface FastEthernet0/10
switchport access vlan 10
duplex full
speed 100
spanning-tree portfast
spanning-tree bpduguard enable
!
interface FastEthernet0/11
switchport access vlan 10
duplex full
speed 100
spanning-tree portfast
spanning-tree bpduguard enable
!
interface FastEthernet0/12
switchport access vlan 10
duplex full
speed 100
spanning-tree portfast
16 - 82 CCNP 3: Multilayer Switching v 4.0 – Skills-Based Assessment Version 1 - Solutions Copyright © 2004, Cisco Systems, Inc.
spanning-tree bpduguard enable
!
interface FastEthernet0/13
duplex full
speed 100
spanning-tree portfast
spanning-tree bpduguard enable
!
interface FastEthernet0/14
duplex full
speed 100
spanning-tree portfast
spanning-tree bpduguard enable
!
interface FastEthernet0/15
duplex full
speed 100
spanning-tree portfast
spanning-tree bpduguard enable
!
interface FastEthernet0/16
duplex full
speed 100
spanning-tree portfast
spanning-tree bpduguard enable
!
interface FastEthernet0/17
duplex full
speed 100
spanning-tree portfast
spanning-tree bpduguard enable
!
interface FastEthernet0/18
duplex full
speed 100
spanning-tree portfast
spanning-tree bpduguard enable
!
interface FastEthernet0/19
duplex full
speed 100
spanning-tree portfast
spanning-tree bpduguard enable
!
interface FastEthernet0/20
duplex full
speed 100
spanning-tree portfast
spanning-tree bpduguard enable
!
interface FastEthernet0/21
duplex full
speed 100
spanning-tree portfast
spanning-tree bpduguard enable
!
interface FastEthernet0/22
duplex full
speed 100
spanning-tree portfast
17 - 82 CCNP 3: Multilayer Switching v 4.0 – Skills-Based Assessment Version 1 - Solutions Copyright © 2004, Cisco Systems, Inc.
spanning-tree bpduguard enable
!
interface FastEthernet0/23
duplex full
speed 100
spanning-tree portfast
spanning-tree bpduguard enable
!
interface FastEthernet0/24
duplex full
speed 100
spanning-tree portfast
spanning-tree bpduguard enable
!
interface GigabitEthernet0/1
!
interface GigabitEthernet0/2
!
interface Vlan1
ip address 10.0.1.11 255.255.255.0
no ip route-cache
!
ip http server
!
!
line con 0
line vty 0 4
login
line vty 5 15
login
!
end
Access1#
18 - 82 CCNP 3: Multilayer Switching v 4.0 – Skills-Based Assessment Version 1 - Solutions Copyright © 2004, Cisco Systems, Inc.
Access2#show running-config
Building configuration...
19 - 82 CCNP 3: Multilayer Switching v 4.0 – Skills-Based Assessment Version 1 - Solutions Copyright © 2004, Cisco Systems, Inc.
duplex full
speed 100
channel-group 1 mode on
!
interface FastEthernet0/5
switchport mode trunk
duplex full
speed 100
channel-group 2 mode on
!
interface FastEthernet0/6
switchport mode trunk
duplex full
speed 100
channel-group 2 mode on
!
interface FastEthernet0/7
switchport access vlan 30
duplex full
speed 100
spanning-tree portfast
spanning-tree bpduguard enable
!
interface FastEthernet0/8
switchport access vlan 30
duplex full
speed 100
spanning-tree portfast
spanning-tree bpduguard enable
!
interface FastEthernet0/9
switchport access vlan 30
duplex full
speed 100
spanning-tree portfast
spanning-tree bpduguard enable
!
interface FastEthernet0/10
switchport access vlan 20
duplex full
speed 100
spanning-tree portfast
spanning-tree bpduguard enable
!
interface FastEthernet0/11
switchport access vlan 20
duplex full
speed 100
spanning-tree portfast
spanning-tree bpduguard enable
!
interface FastEthernet0/12
switchport access vlan 20
duplex full
speed 100
spanning-tree portfast
spanning-tree bpduguard enable
!
interface FastEthernet0/13
duplex full
20 - 82 CCNP 3: Multilayer Switching v 4.0 – Skills-Based Assessment Version 1 - Solutions Copyright © 2004, Cisco Systems, Inc.
speed 100
spanning-tree portfast
spanning-tree bpduguard enable
!
interface FastEthernet0/14
duplex full
speed 100
spanning-tree portfast
spanning-tree bpduguard enable
!
interface FastEthernet0/15
duplex full
speed 100
spanning-tree portfast
spanning-tree bpduguard enable
!
interface FastEthernet0/16
duplex full
speed 100
spanning-tree portfast
spanning-tree bpduguard enable
!
interface FastEthernet0/17
duplex full
speed 100
spanning-tree portfast
spanning-tree bpduguard enable
!
interface FastEthernet0/18
duplex full
speed 100
spanning-tree portfast
spanning-tree bpduguard enable
!
interface FastEthernet0/19
duplex full
speed 100
spanning-tree portfast
spanning-tree bpduguard enable
!
interface FastEthernet0/20
duplex full
speed 100
spanning-tree portfast
spanning-tree bpduguard enable
!
interface FastEthernet0/21
duplex full
speed 100
spanning-tree portfast
spanning-tree bpduguard enable
!
interface FastEthernet0/22
duplex full
speed 100
spanning-tree portfast
spanning-tree bpduguard enable
!
interface FastEthernet0/23
duplex full
21 - 82 CCNP 3: Multilayer Switching v 4.0 – Skills-Based Assessment Version 1 - Solutions Copyright © 2004, Cisco Systems, Inc.
speed 100
spanning-tree portfast
spanning-tree bpduguard enable
!
interface FastEthernet0/24
duplex full
speed 100
spanning-tree portfast
spanning-tree bpduguard enable
!
interface GigabitEthernet0/1
!
interface GigabitEthernet0/2
!
interface Vlan1
ip address 10.0.1.12 255.255.255.0
no ip route-cache
!
ip http server
!
!
line con 0
line vty 0 4
login
line vty 5 15
login
!
end
Access2#
22 - 82 CCNP 3: Multilayer Switching v 4.0 – Skills-Based Assessment Version 1 - Solutions Copyright © 2004, Cisco Systems, Inc.
Verifying Spanning Tree
Verify the status of STP with the show spanning-tree command:
Collapsed-Core#show spanning-tree
MST00
Spanning tree enabled protocol mstp
Root ID Priority 24576
Address 000d.ed5f.8e00
This bridge is the root
Hello Time 2 sec Max Age 20 sec Forward Delay 15 sec
MST01
Spanning tree enabled protocol mstp
Root ID Priority 24577
Address 000d.ed5f.8e00
This bridge is the root
Hello Time 2 sec Max Age 20 sec Forward Delay 15 sec
Collapsed-Core#
Access1#show spanning-tree
MST00
Spanning tree enabled protocol mstp
Root ID Priority 24576
Address 000d.ed5f.8e00
Cost 0
Port 65 (Port-channel1)
Hello Time 2 sec Max Age 20 sec Forward Delay 15 sec
23 - 82 CCNP 3: Multilayer Switching v 4.0 – Skills-Based Assessment Version 1 - Solutions Copyright © 2004, Cisco Systems, Inc.
MST01
Spanning tree enabled protocol mstp
Root ID Priority 24577
Address 000d.ed5f.8e00
Cost 100000
Port 65 (Port-channel1)
Hello Time 2 sec Max Age 20 sec Forward Delay 15 sec
Access1#
Access2#show spanning-tree
MST00
Spanning tree enabled protocol mstp
Root ID Priority 24576
Address 000d.ed5f.8e00
Cost 0
Port 65 (Port-channel1)
Hello Time 2 sec Max Age 20 sec Forward Delay 15 sec
MST01
Spanning tree enabled protocol mstp
Root ID Priority 24577
Address 000d.ed5f.8e00
Cost 100000
Port 65 (Port-channel1)
Hello Time 2 sec Max Age 20 sec Forward Delay 15 sec
Access2#
24 - 82 CCNP 3: Multilayer Switching v 4.0 – Skills-Based Assessment Version 1 - Solutions Copyright © 2004, Cisco Systems, Inc.
Verifying VTP
Verify the status of VTP on all switches with the show vlan brief and the show vtp
status command:
25 - 82 CCNP 3: Multilayer Switching v 4.0 – Skills-Based Assessment Version 1 - Solutions Copyright © 2004, Cisco Systems, Inc.
Maximum VLANs supported locally : 250
Number of existing VLANs : 8
VTP Operating Mode : Server
VTP Domain Name : CISCO
VTP Pruning Mode : Disabled
VTP V2 Mode : Disabled
VTP Traps Generation : Disabled
MD5 digest : 0xE5 0xB2 0x0A 0x3B 0x8D 0x58 0xFB 0xC5
Configuration last modified by 10.0.1.2 at 3-1-93 02:19:47
Local updater ID is 10.0.1.11 on interface Vl1 (lowest numbered VLAN
interface found)
Access1#
26 - 82 CCNP 3: Multilayer Switching v 4.0 – Skills-Based Assessment Version 1 - Solutions Copyright © 2004, Cisco Systems, Inc.
Verifying HSRP
Verify the status of HSRP on both Backup and Collapsed-Core with either the show
standby or the show standby brief command:
Collapsed-Core#show standby
Vlan1 - Group 1
Local state is Active, priority 200, may preempt
Hellotime 3 sec, holdtime 10 sec
Next hello sent in 1.256
Virtual IP address is 10.0.1.1 configured
Active router is local
Standby router is 10.0.1.3 expires in 9.240
Virtual mac address is 0000.0c07.ac01
5 state changes, last state change 00:08:16
IP redundancy name is "hsrp-Vl1-1" (default)
Priority tracking 1 interface or object, 1 up:
Interface or object Decrement State
FastEthernet0/13 150 Up
Vlan10 - Group 10
Local state is Active, priority 200, may preempt
Hellotime 3 sec, holdtime 10 sec
Next hello sent in 0.198
Virtual IP address is 10.0.10.1 configured
Active router is local
Standby router is 10.0.10.3 expires in 7.628
Virtual mac address is 0000.0c07.ac0a
5 state changes, last state change 00:08:17
IP redundancy name is "hsrp-Vl10-10" (default)
Priority tracking 1 interface or object, 1 up:
Interface or object Decrement State
FastEthernet0/13 150 Up
Vlan20 - Group 20
Local state is Active, priority 200, may preempt
Hellotime 3 sec, holdtime 10 sec
Next hello sent in 2.208
Virtual IP address is 10.0.20.1 configured
Active router is local
Standby router is 10.0.20.3 expires in 7.544
Virtual mac address is 0000.0c07.ac14
5 state changes, last state change 00:08:20
IP redundancy name is "hsrp-Vl20-20" (default)
Priority tracking 1 interface or object, 1 up:
Interface or object Decrement State
FastEthernet0/13 150 Up
Vlan30 - Group 30
Local state is Active, priority 200, may preempt
Hellotime 3 sec, holdtime 10 sec
Next hello sent in 2.214
Virtual IP address is 10.0.30.1 configured
Active router is local
Standby router is 10.0.30.3 expires in 7.548
Virtual mac address is 0000.0c07.ac1e
5 state changes, last state change 00:08:22
IP redundancy name is "hsrp-Vl30-30" (default)
Priority tracking 1 interface or object, 1 up:
Interface or object Decrement State
27 - 82 CCNP 3: Multilayer Switching v 4.0 – Skills-Based Assessment Version 1 - Solutions Copyright © 2004, Cisco Systems, Inc.
FastEthernet0/13 150 Up
Collapsed-Core#
From a host, initiate a continuous ping to loopback interface 1.1.1.1. While the pings are
active, unplug the Fa0/13 cable. The pings should become unsuccessful while HSRP is
activating the Standby router. When the pings are successful again, re-connect the cable to
Fa0/13 and the Active router should again go into standby mode.
28 - 82 CCNP 3: Multilayer Switching v 4.0 – Skills-Based Assessment Version 1 - Solutions Copyright © 2004, Cisco Systems, Inc.
CCNP 3 Skills-Based Final Exam 2 – Instructor Version
Scenario
DropBear Industries (DBI) requires a network setup for a new branch office. The network
design calls for VLANs, SVIs, Layer 2 EtherChannels, trunk ports, access ports, and routed
ports using Catalyst 2950 and 3550 switches and a Cisco 2600 series router. DropBear has
a low-bandwidth, 64-Kbps link to its ISP.
Voice over IP will also be demonstrated for sales staff, to test the viability of integrating
voice and data traffic in a single topology. Voice channels totaling 16 Kbps must have
priority over non-voice traffic. For this reason, low-latency queuing needs to be configured
on the link to the ISP. Host 2 will be used to simulate Voice over IP traffic that needs to be
classified as time sensitive based on the source IP address.
The branch office staff consists of an accountant, a secretary, a manager, delivery drivers,
and salespeople. DropBear management expects staffing at this branch office to double in
the first year of operation. The accountant, the secretary, and the manager will have their
PCs connected to VLAN 10 on Access1. The salespeople will have their IP phones
connected to VLAN 20 on Access2. The branch office servers will be connected to VLAN
30 on Collapsed-Core. All Layer 2 control protocol traffic is sent and received on VLAN 1.
29 - 82 CCNP 3: Multilayer Switching v 3.0 – Skills-Based Assessment Version 2 - Solutions Copyright © 2004, Cisco Systems, Inc.
Multiple Instance Spanning Tree Protocol (MST) will be used in combination with PortFast,
and BPDU Guard. In the event of a trunk failure for either Access1 or Access2 to the
Collapsed-Core switch, VLAN 20 phone traffic must have uninterrupted access to the
Border router.
Generic Tasks
• Physically connect the network devices according to the network diagram. Ensure that
the correct cables are connected to the appropriate ports as labeled in the diagram.
• On all devices, configure the following:
− Telnet support
− The privileged EXEC mode password cisco
DBI requires VLANs and VTP to be configured within their switched network:
4. Configure the VLAN 1 management VLAN on all the switches using the network
10.0.1.0/24:
− Ensure that the switches can ping each other using their management VLAN IP
addresses and troubleshoot if necessary.
Fa0/9 - 12,
Collapsed-Core Fa0/1 - 2 Fa0/3 - 4
Fa0/14 – 24
30 - 82 CCNP 3: Multilayer Switching v 3.0 – Skills-Based Assessment Version 2 - Solutions Copyright © 2004, Cisco Systems, Inc.
Spanning-Tree
DBI requires Spanning-Tree protection to ensure against switching loops. They also want
PortFast configured on all access ports.
1. Configure MST:
− Configure an instance of 1 for VLANs 1 through 30.
− All other VLANs are to share instance 0 of Spanning Tree.
− Collapsed-Core should be the primary MST root bridge
− Access1 should be the secondary MST root bridge.
2. Configure PortFast:
− Enable PortFast for all non-trunk access ports.
− Configure each PortFast enabled port in the network so that it will transition to
error-disabled state if an unauthorized device generating BPDUs is attached.
Inter-VLAN Routing
2. Configure Switched Virtual Interfaces (SVIs) on the Collapsed-Core switch for each
VLAN to enable inter-VLAN routing.
3. Configure a valid IP address for Host 1 in VLAN 10, Host 2 in VLAN 20, and the
Server in VLAN 30.
31 - 82 CCNP 3: Multilayer Switching v 3.0 – Skills-Based Assessment Version 2 - Solutions Copyright © 2004, Cisco Systems, Inc.
QoS – Low-Latency Queuing
To ensure that voice traffic will have priority over non-voice traffic, BDI requires low-latency
queuing (LLQ) to be configured on the link to the ISP. LLQ should guarantee 16 Kbps to VLAN
20 and WFQ for all other traffic:
1. Use EIGRP with an AS of 100 as the routing protocol on the Collapsed-Core switch
and Border router:
− Initially the switches can be left with their default configurations.
− Use a PC to simulate an IP phone connected to interface Fa0/12 of the Access2
switch.
2. Create a policy for the treatment of voice traffic within the LAN on the border router:
− Configure a named standard ACL called PHONE-TRAFFIC to identify the
source network address of VLAN 20.
− Configure a class-map called VOICE-TRAFFIC to classify traffic originating from
VLAN 20 in the 10.0.20.0 network as voice traffic.
− Apply the appropriate commands to a policy-map called VOICE to enable LLQ.
− The policy-map will implement a strict priority 16-Kbps queuing strategy for voice
traffic.
− The policy-map will also implement WFQ for the remaining traffic.
Check List
Verify that the Border router is applying the QoS policy for voice traffic with the
2
show policy-map interface s0/0 command.
Ensure that Host 1 and Host 2 can ping each other and the ISP loopback
3
interface 1.1.1.1.
32 - 82 CCNP 3: Multilayer Switching v 3.0 – Skills-Based Assessment Version 2 - Solutions Copyright © 2004, Cisco Systems, Inc.
CCNP 3 Skills-Based Final Exam 2 – Sample Final
Configurations
Sample Router Configurations
The following is configuration output for each networking device. It includes a sample
running configuration:
ISP#show running-config
ISP#show run
Building configuration...
33 - 82 CCNP 3: Multilayer Switching v 3.0 – Skills-Based Assessment Version 2 - Solutions Copyright © 2004, Cisco Systems, Inc.
encapsulation hdlc
shutdown
!
interface Serial0/1
no ip address
shutdown
!
ip classless
ip route 10.0.0.0 255.0.0.0 192.168.0.2
ip http server
!
!
!
dial-peer cor custom
!
!
!
!
!
line con 0
line aux 0
line vty 0 4
password cisco
login
!
end
ISP#show ip route
34 - 82 CCNP 3: Multilayer Switching v 3.0 – Skills-Based Assessment Version 2 - Solutions Copyright © 2004, Cisco Systems, Inc.
Backup#show running-config
Building configuration...
35 - 82 CCNP 3: Multilayer Switching v 3.0 – Skills-Based Assessment Version 2 - Solutions Copyright © 2004, Cisco Systems, Inc.
!
router eigrp 100
redistribute static
network 192.168.0.0
network 192.168.1.0
auto-summary
no eigrp log-neighbor-changes
!
ip classless
ip route 0.0.0.0 0.0.0.0 192.168.0.1
ip http server
!
!
ip access-list standard PHONE-TRAFFIC
remark - ACL identifies telephone traffic traveling on VLAN 20
permit 10.0.20.0 0.0.0.255
!
!
dial-peer cor custom
!
!
!
!
!
line con 0
exec-timeout 0 0
line aux 0
line vty 0 4
password cisco
login
!
end
Border#
Backup#show ip route
Codes: C - connected, S - static, I - IGRP, R - RIP, M - mobile, B - BGP
D - EIGRP, EX - EIGRP external, O - OSPF, IA - OSPF inter area
N1 - OSPF NSSA external type 1, N2 - OSPF NSSA external type 2
E1 - OSPF external type 1, E2 - OSPF external type 2, E - EGP
i - IS-IS, L1 - IS-IS level-1, L2 - IS-IS level-2, ia - IS-IS inter area
* - candidate default, U - per-user static route, o - ODR
P - periodic downloaded static route
36 - 82 CCNP 3: Multilayer Switching v 3.0 – Skills-Based Assessment Version 2 - Solutions Copyright © 2004, Cisco Systems, Inc.
Collapsed-Core#show running-config
Building configuration...
37 - 82 CCNP 3: Multilayer Switching v 3.0 – Skills-Based Assessment Version 2 - Solutions Copyright © 2004, Cisco Systems, Inc.
interface FastEthernet0/3
switchport access vlan 20
no ip address
duplex full
speed 100
spanning-tree portfast
spanning-tree bpduguard enable
!
interface FastEthernet0/4
switchport access vlan 20
no ip address
duplex full
speed 100
spanning-tree portfast
spanning-tree bpduguard enable
!
interface FastEthernet0/5
switchport trunk encapsulation dot1q
switchport mode trunk
no ip address
duplex full
speed 100
channel-group 1 mode on
!
interface FastEthernet0/6
switchport trunk encapsulation dot1q
switchport mode trunk
no ip address
duplex full
speed 100
channel-group 1 mode on
!
interface FastEthernet0/7
switchport trunk encapsulation dot1q
switchport mode trunk
no ip address
duplex full
speed 100
udld port
channel-group 2 mode on
!
interface FastEthernet0/8
switchport trunk encapsulation dot1q
switchport mode trunk
no ip address
duplex full
speed 100
channel-group 2 mode on
!
interface FastEthernet0/9
switchport access vlan 30
no ip address
duplex full
speed 100
spanning-tree portfast
spanning-tree bpduguard enable
!
interface FastEthernet0/10
switchport access vlan 30
no ip address
38 - 82 CCNP 3: Multilayer Switching v 3.0 – Skills-Based Assessment Version 2 - Solutions Copyright © 2004, Cisco Systems, Inc.
duplex full
speed 100
spanning-tree portfast
spanning-tree bpduguard enable
!
interface FastEthernet0/11
switchport access vlan 30
no ip address
duplex full
speed 100
spanning-tree portfast
spanning-tree bpduguard enable
!
interface FastEthernet0/12
switchport access vlan 30
no ip address
duplex full
speed 100
spanning-tree portfast
spanning-tree bpduguard enable
!
interface FastEthernet0/13
description - Switch port connecting to the Border router
no switchport
ip address 192.168.1.2 255.255.255.0
duplex full
speed 100
!
interface FastEthernet0/14
switchport access vlan 30
no ip address
duplex full
speed 100
spanning-tree portfast
spanning-tree bpduguard enable
!
interface FastEthernet0/15
switchport access vlan 30
no ip address
duplex full
speed 100
spanning-tree bpduguard enable
!
interface FastEthernet0/16
switchport access vlan 30
no ip address
duplex full
speed 100
spanning-tree portfast
spanning-tree bpduguard enable
!
interface FastEthernet0/17
no ip address
duplex full
speed 100
!
interface FastEthernet0/18
no ip address
duplex full
speed 100
39 - 82 CCNP 3: Multilayer Switching v 3.0 – Skills-Based Assessment Version 2 - Solutions Copyright © 2004, Cisco Systems, Inc.
!
interface FastEthernet0/19
no ip address
duplex full
speed 100
!
interface FastEthernet0/20
no ip address
duplex full
speed 100
!
interface FastEthernet0/21
no ip address
duplex full
speed 100
!
interface FastEthernet0/22
no ip address
duplex full
speed 100
!
interface FastEthernet0/23
no ip address
duplex full
speed 100
!
interface FastEthernet0/24
switchport access vlan 30
no ip address
duplex full
speed 100
spanning-tree portfast
!
interface GigabitEthernet0/1
no ip address
!
interface GigabitEthernet0/2
no ip address
!
interface Vlan1
ip address 10.0.1.1 255.255.255.0
!
interface Vlan10
ip address 10.0.10.1 255.255.255.0
!
interface Vlan20
ip address 10.0.20.1 255.255.255.0
!
interface Vlan30
ip address 10.0.30.1 255.255.255.0
!
router eigrp 100
network 10.0.0.0
network 192.168.1.0
auto-summary
no eigrp log-neighbor-changes
!
ip classless
ip http server
!
40 - 82 CCNP 3: Multilayer Switching v 3.0 – Skills-Based Assessment Version 2 - Solutions Copyright © 2004, Cisco Systems, Inc.
!
!
line con 0
line vty 0 4
login
line vty 5 15
password cisco
login
!
end
Collapsed-Core#
Collapsed-Core#show ip route
Collapsed-Core#show ip route
Codes: C - connected, S - static, I - IGRP, R - RIP, M - mobile, B - BGP
D - EIGRP, EX - EIGRP external, O - OSPF, IA - OSPF inter area
N1 - OSPF NSSA external type 1, N2 - OSPF NSSA external type 2
E1 - OSPF external type 1, E2 - OSPF external type 2, E - EGP
i - IS-IS, L1 - IS-IS level-1, L2 - IS-IS level-2, ia - IS-IS inter area
* - candidate default, U - per-user static route, o - ODR
P - periodic downloaded static route
41 - 82 CCNP 3: Multilayer Switching v 3.0 – Skills-Based Assessment Version 2 - Solutions Copyright © 2004, Cisco Systems, Inc.
Access1#show running-config
Access1#show run
Building configuration...
42 - 82 CCNP 3: Multilayer Switching v 3.0 – Skills-Based Assessment Version 2 - Solutions Copyright © 2004, Cisco Systems, Inc.
interface FastEthernet0/4
switchport mode trunk
duplex full
speed 100
channel-group 1 mode on
!
interface FastEthernet0/5
switchport mode trunk
duplex full
speed 100
channel-group 2 mode on
!
interface FastEthernet0/6
switchport mode trunk
duplex full
speed 100
channel-group 2 mode on
!
interface FastEthernet0/7
switchport access vlan 30
duplex full
speed 100
spanning-tree portfast
spanning-tree bpduguard enable
!
interface FastEthernet0/8
switchport access vlan 30
duplex full
speed 100
spanning-tree portfast
spanning-tree bpduguard enable
!
interface FastEthernet0/9
switchport access vlan 30
duplex full
speed 100
spanning-tree portfast
spanning-tree bpduguard enable
!
interface FastEthernet0/10
switchport access vlan 10
duplex full
speed 100
spanning-tree portfast
spanning-tree bpduguard enable
!
interface FastEthernet0/11
switchport access vlan 10
duplex full
speed 100
spanning-tree portfast
spanning-tree bpduguard enable
!
interface FastEthernet0/12
switchport access vlan 10
duplex full
speed 100
spanning-tree portfast
spanning-tree bpduguard enable
!
43 - 82 CCNP 3: Multilayer Switching v 3.0 – Skills-Based Assessment Version 2 - Solutions Copyright © 2004, Cisco Systems, Inc.
interface FastEthernet0/13
duplex full
speed 100
spanning-tree portfast
spanning-tree bpduguard enable
!
interface FastEthernet0/14
duplex full
speed 100
spanning-tree portfast
spanning-tree bpduguard enable
!
interface FastEthernet0/15
duplex full
speed 100
spanning-tree portfast
spanning-tree bpduguard enable
!
interface FastEthernet0/16
duplex full
speed 100
spanning-tree portfast
spanning-tree bpduguard enable
!
interface FastEthernet0/17
duplex full
speed 100
spanning-tree portfast
spanning-tree bpduguard enable
!
interface FastEthernet0/18
duplex full
speed 100
spanning-tree portfast
spanning-tree bpduguard enable
!
interface FastEthernet0/19
duplex full
speed 100
spanning-tree portfast
spanning-tree bpduguard enable
!
interface FastEthernet0/20
duplex full
speed 100
spanning-tree portfast
spanning-tree bpduguard enable
!
interface FastEthernet0/21
duplex full
speed 100
spanning-tree portfast
spanning-tree bpduguard enable
!
interface FastEthernet0/22
duplex full
speed 100
spanning-tree portfast
spanning-tree bpduguard enable
!
44 - 82 CCNP 3: Multilayer Switching v 3.0 – Skills-Based Assessment Version 2 - Solutions Copyright © 2004, Cisco Systems, Inc.
interface FastEthernet0/23
duplex full
speed 100
spanning-tree portfast
spanning-tree bpduguard enable
!
interface FastEthernet0/24
duplex full
speed 100
spanning-tree portfast
spanning-tree bpduguard enable
!
interface GigabitEthernet0/1
!
interface GigabitEthernet0/2
!
interface Vlan1
ip address 10.0.1.11 255.255.255.0
no ip route-cache
!
ip default-gateway 10.0.1.1
ip http server
!
!
line con 0
line vty 0 4
password cisco
login
line vty 5 15
password cisco
login
!
end
Access1#
45 - 82 CCNP 3: Multilayer Switching v 3.0 – Skills-Based Assessment Version 2 - Solutions Copyright © 2004, Cisco Systems, Inc.
Access2#show running-config
Building configuration...
46 - 82 CCNP 3: Multilayer Switching v 3.0 – Skills-Based Assessment Version 2 - Solutions Copyright © 2004, Cisco Systems, Inc.
switchport mode trunk
duplex full
speed 100
channel-group 1 mode on
!
interface FastEthernet0/5
switchport mode trunk
duplex full
speed 100
channel-group 2 mode on
!
interface FastEthernet0/6
switchport mode trunk
duplex full
speed 100
channel-group 2 mode on
!
interface FastEthernet0/7
switchport access vlan 30
duplex full
speed 100
spanning-tree portfast
spanning-tree bpduguard enable
!
interface FastEthernet0/8
switchport access vlan 30
duplex full
speed 100
spanning-tree portfast
spanning-tree bpduguard enable
!
interface FastEthernet0/9
switchport access vlan 30
duplex full
speed 100
spanning-tree portfast
spanning-tree bpduguard enable
!
interface FastEthernet0/10
switchport access vlan 20
duplex full
speed 100
spanning-tree portfast
spanning-tree bpduguard enable
!
interface FastEthernet0/11
switchport access vlan 20
duplex full
speed 100
spanning-tree portfast
spanning-tree bpduguard enable
!
interface FastEthernet0/12
switchport access vlan 20
duplex full
speed 100
spanning-tree portfast
spanning-tree bpduguard enable
!
interface FastEthernet0/13
47 - 82 CCNP 3: Multilayer Switching v 3.0 – Skills-Based Assessment Version 2 - Solutions Copyright © 2004, Cisco Systems, Inc.
duplex full
speed 100
spanning-tree portfast
spanning-tree bpduguard enable
!
interface FastEthernet0/14
duplex full
speed 100
spanning-tree portfast
spanning-tree bpduguard enable
!
interface FastEthernet0/15
duplex full
speed 100
spanning-tree portfast
spanning-tree bpduguard enable
!
interface FastEthernet0/16
duplex full
speed 100
spanning-tree portfast
spanning-tree bpduguard enable
!
interface FastEthernet0/17
duplex full
speed 100
spanning-tree portfast
spanning-tree bpduguard enable
!
interface FastEthernet0/18
duplex full
speed 100
spanning-tree portfast
spanning-tree bpduguard enable
!
interface FastEthernet0/19
duplex full
speed 100
spanning-tree portfast
spanning-tree bpduguard enable
!
interface FastEthernet0/20
duplex full
speed 100
spanning-tree portfast
spanning-tree bpduguard enable
!
interface FastEthernet0/21
duplex full
speed 100
spanning-tree portfast
spanning-tree bpduguard enable
!
interface FastEthernet0/22
duplex full
speed 100
spanning-tree portfast
spanning-tree bpduguard enable
!
interface FastEthernet0/23
48 - 82 CCNP 3: Multilayer Switching v 3.0 – Skills-Based Assessment Version 2 - Solutions Copyright © 2004, Cisco Systems, Inc.
duplex full
speed 100
spanning-tree portfast
spanning-tree bpduguard enable
!
interface FastEthernet0/24
duplex full
speed 100
spanning-tree portfast
spanning-tree bpduguard enable
!
interface GigabitEthernet0/1
!
interface GigabitEthernet0/2
!
interface Vlan1
ip address 10.0.1.12 255.255.255.0
no ip route-cache
!
ip default-gateway 10.0.1.1
ip http server
!
!
line con 0
line vty 0 4
password cisco
login
line vty 5 15
password cisco
login
!
end
Access2#
49 - 82 CCNP 3: Multilayer Switching v 3.0 – Skills-Based Assessment Version 2 - Solutions Copyright © 2004, Cisco Systems, Inc.
Verifying Spanning Tree
Verify the status of STP with the show spanning-tree command:
Collapsed-Core#show spanning-tree
MST00
Spanning tree enabled protocol mstp
Root ID Priority 24576
Address 000d.ed5f.8e00
This bridge is the root
Hello Time 2 sec Max Age 20 sec Forward Delay 15 sec
MST01
Spanning tree enabled protocol mstp
Root ID Priority 24577
Address 000d.ed5f.8e00
This bridge is the root
Hello Time 2 sec Max Age 20 sec Forward Delay 15 sec
Collapsed-Core#
Access1#show spanning-tree
MST00
Spanning tree enabled protocol mstp
Root ID Priority 24576
Address 000d.ed5f.8e00
Cost 0
Port 65 (Port-channel1)
Hello Time 2 sec Max Age 20 sec Forward Delay 15 sec
50 - 82 CCNP 3: Multilayer Switching v 3.0 – Skills-Based Assessment Version 2 - Solutions Copyright © 2004, Cisco Systems, Inc.
MST01
Spanning tree enabled protocol mstp
Root ID Priority 24577
Address 000d.ed5f.8e00
Cost 100000
Port 65 (Port-channel1)
Hello Time 2 sec Max Age 20 sec Forward Delay 15 sec
Access1#
Access2#show spanning-tree
MST00
Spanning tree enabled protocol mstp
Root ID Priority 24576
Address 000d.ed5f.8e00
Cost 100000
Port 65 (Port-channel1)
Hello Time 2 sec Max Age 20 sec Forward Delay 15 sec
MST01
Spanning tree enabled protocol mstp
Root ID Priority 32769
Address 000e.838c.57c0
This bridge is the root
Hello Time 2 sec Max Age 20 sec Forward Delay 15 sec
Access2#
51 - 82 CCNP 3: Multilayer Switching v 3.0 – Skills-Based Assessment Version 2 - Solutions Copyright © 2004, Cisco Systems, Inc.
Verifying VTP
Verify the status of VTP on all switches with the show vlan brief and the show vtp
status command:
52 - 82 CCNP 3: Multilayer Switching v 3.0 – Skills-Based Assessment Version 2 - Solutions Copyright © 2004, Cisco Systems, Inc.
Number of existing VLANs : 8
VTP Operating Mode : Server
VTP Domain Name : DROPBEAR
VTP Pruning Mode : Disabled
VTP V2 Mode : Disabled
VTP Traps Generation : Disabled
MD5 digest : 0x95 0xF7 0xEC 0x0B 0xA0 0x7F 0xA3 0xB0
Configuration last modified by 10.0.1.1 at 3-1-93 00:31:54
Local updater ID is 10.0.1.11 on interface Vl1 (lowest numbered VLAN
interface found)
Access1#
53 - 82 CCNP 3: Multilayer Switching v 3.0 – Skills-Based Assessment Version 2 - Solutions Copyright © 2004, Cisco Systems, Inc.
Verifying QoS
Verify the status of QoS on the Border router with the show policy-map interface
s0/0 command:
54 - 82 CCNP 3: Multilayer Switching v 3.0 – Skills-Based Assessment Version 2 - Solutions Copyright © 2004, Cisco Systems, Inc.
CCNP 3 Skills-Based Final Exam 3 – Instructor Version
Scenario
GeoTech Distributors (GTD) requires a network setup for a new branch office. The network
design calls for VLANs, SVIs, Layer 2 EtherChannels, trunk ports, access ports, and routed
ports using Catalyst 2950 and 3550 switches and a Cisco 2600 series router.
The branch office staff consists of an accountant, a secretary, a manager, delivery drivers,
and salespeople. GTD management expects staffing at this branch office to double in the
first year of operation. The accountant, the secretary, and the manager will have their PCs
connected to VLAN 10 on Access1. The delivery drivers and the salespeople will have their
PCs connected to VLAN 20 on Access2. The branch office servers will be connected to
VLAN 30 on Collapsed-Core. All Layer 2 control protocol traffic is sent and received on
VLAN 1.
Multiple Instance Spanning Tree Protocol (MST) will be used in combination with PortFast,
and BPDU Guard.
Due to increasing network usage and reports of performance problems, the sales traffic on
Access2 is being monitored on a port-membership basis by a remote monitor host attached
to the Collapsed-Core switch.
55 - 82 CCNP 3: Multilayer Switching v 3.0 – Skills-Based Assessment Version 3 - Solutions Copyright © 2004, Cisco Systems, Inc.
Security measures are to be implemented on all switches to give Help Desk staff on VLAN
20 low levels of access to console and Telnet sessions using simple passwords. Network
administrators on VLAN 10 will automatically have the highest level of access when
connecting to the switches using either the console or a Telnet session, and will need to
have their passwords well protected.
Generic Tasks
• Physically connect the network devices according to the network diagram. Ensure that
the correct cables are connected to the appropriate ports as labeled in the diagram.
• On all devices, configure the following:
− Telnet support
− The privilege EXEC mode password cisco
GTD requires VLANs and VTP to be configured within their switched network:
4. Configure the VLAN 1 management VLAN on all the switches using the network
10.0.1.0/24:
− Ensure that the switches can ping each other using their management VLAN IP
addresses and troubleshoot if necessary.
Fa0/9 - 12,
Collapsed-Core Fa0/1 - 2 Fa0/3 - 4
Fa0/14 – 24
56 - 82 CCNP 3: Multilayer Switching v 3.0 – Skills-Based Assessment Version 3 - Solutions Copyright © 2004, Cisco Systems, Inc.
Access2 Fa0/1 - 2 Fa0/10 - 12 Fa0/7 – 9
Spanning-Tree
GTD requires Spanning-Tree protection to prevent switching loops. They also want PortFast
configured on all access ports:
1. Configure MST:
− Configure an instance of 1 for VLANs 1 through 99.
− All other VLANs are to share an instance of 0.
− Collapsed-Core should be the primary MST root bridge.
− Access1 should be the secondary MST root bridge.
2. Configure PortFast:
− Enable PortFast for all non-trunk access ports.
− Configure each PortFast enabled port in the network so that it will transition to
error-disabled state if an unauthorized device generating BPDUs is attached.
Inter-VLAN Routing
2. Configure Switched Virtual Interfaces (SVIs) on the Collapsed-Core switch for each
VLAN to enable inter-VLAN routing.
3. Configure a valid IP address for Host 1 in VLAN 10, Host 2 in VLAN 20, and the
Server in VLAN 30.
57 - 82 CCNP 3: Multilayer Switching v 3.0 – Skills-Based Assessment Version 3 - Solutions Copyright © 2004, Cisco Systems, Inc.
RSPAN Monitoring
GTD requires remote monitoring of multiple switches across a network using RSPAN:
1. Protocol analysis software such as the Fluke Protocol Inspector should be loaded
and running on a host that will act as the Remote Monitor (RMON).
3. The destination for the monitoring session will be port Fa0/14 on the Collapsed-
Core switch.
Security
1. Create a logon username and clear text password on each switch for Help Desk
users:
− The Help Desk staff is given user-level access.
2. Create a logon username and clear text password on each switch for
administrators:
− Network administrators must be automatically granted the highest privilege of
access once logged into a switch.
3. Ensure these security measures are applied to all console and virtual terminal
sessions.
58 - 82 CCNP 3: Multilayer Switching v 3.0 – Skills-Based Assessment Version 3 - Solutions Copyright © 2004, Cisco Systems, Inc.
Check List
Verify that the redundant links are operational by disconnecting each of the
4 EtherChannels between Access1, Access2, and Collapsed-Core in turn and
ensuring that connectivity is maintained.
Make sure that the host attached to Port 0/12 on Access1 has connectivity only if
5
the workstation has the appropriate MAC address.
Ensure that Host 1 and Host 2 can ping each other and the ISP loopback
6
interface 1.1.1.1.
59 - 82 CCNP 3: Multilayer Switching v 3.0 – Skills-Based Assessment Version 3 - Solutions Copyright © 2004, Cisco Systems, Inc.
CCNP 3 Skills-Based Final Exam 3 – Sample Final
Configurations
ISP#show running-config
Building configuration...
60 - 82 CCNP 3: Multilayer Switching v 3.0 – Skills-Based Assessment Version 3 - Solutions Copyright © 2004, Cisco Systems, Inc.
no ip address
encapsulation hdlc
shutdown
!
interface Serial0/1
no ip address
shutdown
!
ip classless
ip route 10.0.0.0 255.0.0.0 192.168.1.2
no ip http server
!
!
!
dial-peer cor custom
!
!
!
!
!
line con 0
line aux 0
line vty 0 4
password cisco
login
!
end
ISP#show ip route
Codes: C - connected, S - static, I - IGRP, R - RIP, M - mobile, B - BGP
D - EIGRP, EX - EIGRP external, O - OSPF, IA - OSPF inter area
N1 - OSPF NSSA external type 1, N2 - OSPF NSSA external type 2
E1 - OSPF external type 1, E2 - OSPF external type 2, E - EGP
i - IS-IS, L1 - IS-IS level-1, L2 - IS-IS level-2, ia - IS-IS inter area
* - candidate default, U - per-user static route, o - ODR
P - periodic downloaded static route
61 - 82 CCNP 3: Multilayer Switching v 3.0 – Skills-Based Assessment Version 3 - Solutions Copyright © 2004, Cisco Systems, Inc.
Collapsed-Core#show running-config
Building configuration...
Current configuration : 5506 bytes
!
version 12.1
no service pad
service timestamps debug uptime
service timestamps log uptime
service password-encryption
!
hostname Collapsed-Core
!
enable secret 5 $1$N2K7$65K06nMtvIXTbiAE2OEEA.
!
username helpdesk password 7 121A0C041104
username admin privilege 15 password 7 121A0C041104
ip subnet-zero
ip routing
!
!
!
spanning-tree mode mst
spanning-tree extend system-id
!
spanning-tree mst configuration
instance 1 vlan 1-99
!
spanning-tree mst 0 priority 24576
spanning-tree mst 1 priority 24576
!
!
!
interface Port-channel1
switchport trunk encapsulation dot1q
switchport mode trunk
no ip address
!
interface Port-channel2
switchport trunk encapsulation dot1q
switchport mode trunk
no ip address
!
interface FastEthernet0/1
switchport access vlan 10
switchport mode access
no ip address
duplex full
speed 100
spanning-tree portfast
spanning-tree bpduguard enable
!
interface FastEthernet0/2
switchport access vlan 10
switchport mode access
no ip address
duplex full
speed 100
spanning-tree portfast
62 - 82 CCNP 3: Multilayer Switching v 3.0 – Skills-Based Assessment Version 3 - Solutions Copyright © 2004, Cisco Systems, Inc.
spanning-tree bpduguard enable
!
interface FastEthernet0/3
switchport access vlan 20
switchport mode access
no ip address
duplex full
speed 100
spanning-tree portfast
spanning-tree bpduguard enable
!
interface FastEthernet0/4
switchport access vlan 20
switchport mode access
no ip address
duplex full
speed 100
spanning-tree portfast
spanning-tree bpduguard enable
!
interface FastEthernet0/5
switchport trunk encapsulation dot1q
switchport mode trunk
no ip address
duplex full
speed 100
channel-group 1 mode on
!
interface FastEthernet0/6
switchport trunk encapsulation dot1q
switchport mode trunk
no ip address
duplex full
speed 100
channel-group 1 mode on
!
interface FastEthernet0/7
switchport trunk encapsulation dot1q
switchport mode trunk
no ip address
duplex full
speed 100
udld port
channel-group 2 mode on
!
interface FastEthernet0/8
switchport trunk encapsulation dot1q
switchport mode trunk
no ip address
duplex full
speed 100
channel-group 2 mode on
!
interface FastEthernet0/9
switchport access vlan 30
switchport mode access
no ip address
duplex full
speed 100
spanning-tree portfast
63 - 82 CCNP 3: Multilayer Switching v 3.0 – Skills-Based Assessment Version 3 - Solutions Copyright © 2004, Cisco Systems, Inc.
spanning-tree bpduguard enable
!
interface FastEthernet0/10
switchport access vlan 30
switchport mode access
no ip address
duplex full
speed 100
spanning-tree portfast
spanning-tree bpduguard enable
!
interface FastEthernet0/11
switchport access vlan 30
switchport mode access
no ip address
duplex full
speed 100
spanning-tree portfast
spanning-tree bpduguard enable
!
interface FastEthernet0/12
switchport access vlan 30
switchport mode access
no ip address
duplex full
speed 100
spanning-tree portfast
spanning-tree bpduguard enable
!
interface FastEthernet0/13
description - Switch port connecting to the Border router
no switchport
ip address 192.168.1.2 255.255.255.0
duplex full
speed 100
!
interface FastEthernet0/14
switchport access vlan 30
switchport mode access
no ip address
duplex full
speed 100
spanning-tree portfast
spanning-tree bpduguard enable
!
interface FastEthernet0/15
switchport access vlan 30
switchport mode access
no ip address
duplex full
speed 100
spanning-tree portfast
spanning-tree bpduguard enable
!
interface FastEthernet0/16
switchport access vlan 30
switchport mode access
no ip address
duplex full
speed 100
64 - 82 CCNP 3: Multilayer Switching v 3.0 – Skills-Based Assessment Version 3 - Solutions Copyright © 2004, Cisco Systems, Inc.
spanning-tree portfast
spanning-tree bpduguard enable
!
interface FastEthernet0/17
switchport access vlan 30
switchport mode access
no ip address
duplex full
speed 100
spanning-tree portfast
spanning-tree bpduguard enable
!
interface FastEthernet0/18
switchport access vlan 30
switchport mode access
no ip address
duplex full
speed 100
spanning-tree portfast
spanning-tree bpduguard enable
!
interface FastEthernet0/19
switchport access vlan 30
switchport mode access
no ip address
duplex full
speed 100
spanning-tree portfast
spanning-tree bpduguard enable
!
interface FastEthernet0/20
switchport access vlan 30
switchport mode access
no ip address
duplex full
speed 100
spanning-tree portfast
spanning-tree bpduguard enable
!
interface FastEthernet0/21
switchport access vlan 30
switchport mode access
no ip address
duplex full
speed 100
spanning-tree portfast
spanning-tree bpduguard enable
!
interface FastEthernet0/22
switchport access vlan 30
switchport mode access
no ip address
duplex full
speed 100
spanning-tree portfast
spanning-tree bpduguard enable
!
interface FastEthernet0/23
switchport access vlan 30
switchport mode access
65 - 82 CCNP 3: Multilayer Switching v 3.0 – Skills-Based Assessment Version 3 - Solutions Copyright © 2004, Cisco Systems, Inc.
no ip address
duplex full
speed 100
spanning-tree portfast
spanning-tree bpduguard enable
!
interface FastEthernet0/24
switchport access vlan 30
switchport mode access
no ip address
duplex full
speed 100
spanning-tree portfast
spanning-tree bpduguard enable
!
interface GigabitEthernet0/1
no ip address
!
interface GigabitEthernet0/2
no ip address
!
interface Vlan1
ip address 10.0.1.1 255.255.255.0
!
interface Vlan10
ip address 10.0.10.1 255.255.255.0
!
interface Vlan20
ip address 10.0.20.1 255.255.255.0
!
interface Vlan30
ip address 10.0.30.1 255.255.255.0
!
router eigrp 100
network 10.0.0.0
network 192.168.1.0
auto-summary
no eigrp log-neighbor-changes
!
ip classless
ip route 0.0.0.0 0.0.0.0 192.168.1.1
ip http server
!
!
!
line con 0
login local
line vty 0 4
login local
line vty 5 15
password 7 00071A150754
login local
!
!
monitor session 1 destination interface Fa0/14
monitor session 1 source remote vlan 99
end
Collapsed-Core#
66 - 82 CCNP 3: Multilayer Switching v 3.0 – Skills-Based Assessment Version 3 - Solutions Copyright © 2004, Cisco Systems, Inc.
Collapsed-Core#show ip route
67 - 82 CCNP 3: Multilayer Switching v 3.0 – Skills-Based Assessment Version 3 - Solutions Copyright © 2004, Cisco Systems, Inc.
Access1#show running-config
Building configuration...
68 - 82 CCNP 3: Multilayer Switching v 3.0 – Skills-Based Assessment Version 3 - Solutions Copyright © 2004, Cisco Systems, Inc.
duplex full
speed 100
channel-group 1 mode on
!
interface FastEthernet0/4
switchport mode trunk
duplex full
speed 100
channel-group 1 mode on
!
interface FastEthernet0/5
switchport mode trunk
duplex full
speed 100
channel-group 2 mode on
!
interface FastEthernet0/6
switchport mode trunk
duplex full
speed 100
channel-group 2 mode on
!
interface FastEthernet0/7
switchport access vlan 30
switchport mode access
duplex full
speed 100
spanning-tree portfast
spanning-tree bpduguard enable
!
interface FastEthernet0/8
switchport access vlan 30
switchport mode access
duplex full
speed 100
spanning-tree portfast
spanning-tree bpduguard enable
!
interface FastEthernet0/9
switchport access vlan 30
switchport mode access
duplex full
speed 100
spanning-tree portfast
spanning-tree bpduguard enable
!
interface FastEthernet0/10
switchport access vlan 10
switchport mode access
duplex full
speed 100
spanning-tree portfast
spanning-tree bpduguard enable
!
interface FastEthernet0/11
switchport access vlan 10
switchport mode access
duplex full
speed 100
spanning-tree portfast
69 - 82 CCNP 3: Multilayer Switching v 3.0 – Skills-Based Assessment Version 3 - Solutions Copyright © 2004, Cisco Systems, Inc.
spanning-tree bpduguard enable
!
interface FastEthernet0/12
switchport access vlan 10
switchport mode access
switchport port-security
switchport port-security mac-address 0008.74e2.1a28
duplex full
speed 100
spanning-tree portfast
spanning-tree bpduguard enable
!
interface FastEthernet0/13
switchport mode access
duplex full
speed 100
spanning-tree portfast
spanning-tree bpduguard enable
!
interface FastEthernet0/14
switchport mode access
duplex full
speed 100
spanning-tree portfast
spanning-tree bpduguard enable
!
interface FastEthernet0/15
switchport mode access
duplex full
speed 100
spanning-tree portfast
spanning-tree bpduguard enable
!
interface FastEthernet0/16
switchport mode access
duplex full
speed 100
spanning-tree portfast
spanning-tree bpduguard enable
!
interface FastEthernet0/17
switchport mode access
duplex full
speed 100
spanning-tree portfast
spanning-tree bpduguard enable
!
interface FastEthernet0/18
switchport mode access
duplex full
speed 100
spanning-tree portfast
spanning-tree bpduguard enable
!
interface FastEthernet0/19
switchport mode access
duplex full
speed 100
spanning-tree portfast
spanning-tree bpduguard enable
70 - 82 CCNP 3: Multilayer Switching v 3.0 – Skills-Based Assessment Version 3 - Solutions Copyright © 2004, Cisco Systems, Inc.
!
interface FastEthernet0/20
switchport mode access
duplex full
speed 100
spanning-tree portfast
spanning-tree bpduguard enable
!
interface FastEthernet0/21
switchport mode access
duplex full
speed 100
spanning-tree portfast
spanning-tree bpduguard enable
!
interface FastEthernet0/22
switchport mode access
duplex full
speed 100
spanning-tree portfast
spanning-tree bpduguard enable
!
interface FastEthernet0/23
switchport mode access
duplex full
speed 100
spanning-tree portfast
spanning-tree bpduguard enable
!
interface FastEthernet0/24
switchport mode access
duplex full
speed 100
spanning-tree portfast
spanning-tree bpduguard enable
!
interface GigabitEthernet0/1
!
interface GigabitEthernet0/2
!
interface Vlan1
ip address 10.0.1.11 255.255.255.0
no ip route-cache
!
ip default-gateway 10.0.1.1
ip http server
!
!
line con 0
login local
line vty 0 4
login local
line vty 5 15
login local
!
end
Access1#
71 - 82 CCNP 3: Multilayer Switching v 3.0 – Skills-Based Assessment Version 3 - Solutions Copyright © 2004, Cisco Systems, Inc.
Access2#show running-config
Building configuration...
72 - 82 CCNP 3: Multilayer Switching v 3.0 – Skills-Based Assessment Version 3 - Solutions Copyright © 2004, Cisco Systems, Inc.
duplex full
speed 100
channel-group 1 mode on
!
interface FastEthernet0/4
switchport mode trunk
duplex full
speed 100
channel-group 1 mode on
!
interface FastEthernet0/5
switchport mode trunk
duplex full
speed 100
channel-group 2 mode on
!
interface FastEthernet0/6
switchport mode trunk
duplex full
speed 100
channel-group 2 mode on
!
interface FastEthernet0/7
switchport access vlan 30
switchport mode access
duplex full
speed 100
spanning-tree portfast
spanning-tree bpduguard enable
!
interface FastEthernet0/8
switchport access vlan 30
switchport mode access
duplex full
speed 100
spanning-tree portfast
spanning-tree bpduguard enable
!
interface FastEthernet0/9
switchport access vlan 30
switchport mode access
duplex full
speed 100
spanning-tree portfast
spanning-tree bpduguard enable
!
interface FastEthernet0/10
switchport access vlan 20
switchport mode access
duplex full
speed 100
spanning-tree portfast
spanning-tree bpduguard enable
!
interface FastEthernet0/11
switchport access vlan 20
switchport mode access
duplex full
speed 100
spanning-tree portfast
73 - 82 CCNP 3: Multilayer Switching v 3.0 – Skills-Based Assessment Version 3 - Solutions Copyright © 2004, Cisco Systems, Inc.
spanning-tree bpduguard enable
!
interface FastEthernet0/12
switchport access vlan 20
switchport mode access
duplex full
speed 100
spanning-tree portfast
spanning-tree bpduguard enable
!
interface FastEthernet0/13
switchport mode access
duplex full
speed 100
spanning-tree portfast
spanning-tree bpduguard enable
!
interface FastEthernet0/14
switchport mode access
duplex full
speed 100
spanning-tree portfast
spanning-tree bpduguard enable
!
interface FastEthernet0/15
switchport mode access
duplex full
speed 100
spanning-tree portfast
spanning-tree bpduguard enable
!
interface FastEthernet0/16
switchport mode access
duplex full
speed 100
spanning-tree portfast
spanning-tree bpduguard enable
!
interface FastEthernet0/17
switchport mode access
duplex full
speed 100
spanning-tree portfast
spanning-tree bpduguard enable
!
interface FastEthernet0/18
switchport mode access
duplex full
speed 100
spanning-tree portfast
spanning-tree bpduguard enable
!
interface FastEthernet0/19
switchport mode access
duplex full
speed 100
spanning-tree portfast
spanning-tree bpduguard enable
!
interface FastEthernet0/20
74 - 82 CCNP 3: Multilayer Switching v 3.0 – Skills-Based Assessment Version 3 - Solutions Copyright © 2004, Cisco Systems, Inc.
switchport mode access
duplex full
speed 100
spanning-tree portfast
spanning-tree bpduguard enable
!
interface FastEthernet0/21
switchport mode access
duplex full
speed 100
spanning-tree portfast
spanning-tree bpduguard enable
!
interface FastEthernet0/22
switchport mode access
duplex full
speed 100
spanning-tree portfast
spanning-tree bpduguard enable
!
interface FastEthernet0/23
switchport mode access
duplex full
speed 100
spanning-tree portfast
spanning-tree bpduguard enable
!
interface FastEthernet0/24
switchport mode access
duplex full
speed 100
spanning-tree portfast
spanning-tree bpduguard enable
!
interface GigabitEthernet0/1
!
interface GigabitEthernet0/2
!
interface Vlan1
no ip address
no ip route-cache
!
ip default-gateway 10.0.1.1
ip http server
!
!
line con 0
login local
line vty 0 4
login local
line vty 5 15
login local
!
!
monitor session 1 source interface Fa0/12
monitor session 1 destination remote vlan 99 reflector-port Fa0/24
end
Access2#
75 - 82 CCNP 3: Multilayer Switching v 3.0 – Skills-Based Assessment Version 3 - Solutions Copyright © 2004, Cisco Systems, Inc.
Verifying Spanning Tree
Verify the status of STP with the show spanning-tree command:
Collapsed-Core#show spanning-tree
Collapsed-Core#show spanning-tree
MST00
Spanning tree enabled protocol mstp
Root ID Priority 24576
Address 000d.ed5f.8e00
This bridge is the root
Hello Time 2 sec Max Age 20 sec Forward Delay 15 sec
MST01
Spanning tree enabled protocol mstp
Root ID Priority 24577
Address 000d.ed5f.8e00
This bridge is the root
Hello Time 2 sec Max Age 20 sec Forward Delay 15 sec
Collapsed-Core#
Access1#show spanning-tree
MST00
Spanning tree enabled protocol mstp
Root ID Priority 24576
Address 000d.ed5f.8e00
Cost 100000
Port 65 (Port-channel1)
Hello Time 2 sec Max Age 20 sec Forward Delay 15 sec
76 - 82 CCNP 3: Multilayer Switching v 3.0 – Skills-Based Assessment Version 3 - Solutions Copyright © 2004, Cisco Systems, Inc.
MST01
Spanning tree enabled protocol mstp
Root ID Priority 28673
Address 000e.838c.5800
This bridge is the root
Hello Time 2 sec Max Age 20 sec Forward Delay 15 sec
Access1#
Access2#show spanning-tree
MST00
Spanning tree enabled protocol mstp
Root ID Priority 32768
Address 000e.838c.57c0
This bridge is the root
Hello Time 2 sec Max Age 20 sec Forward Delay 15 sec
MST01
Spanning tree enabled protocol mstp
Root ID Priority 32769
Address 000e.838c.57c0
This bridge is the root
Hello Time 2 sec Max Age 20 sec Forward Delay 15 sec
Access2#
77 - 82 CCNP 3: Multilayer Switching v 3.0 – Skills-Based Assessment Version 3 - Solutions Copyright © 2004, Cisco Systems, Inc.
Verifying VTP
Verify the status of VTP on all switches with the show vlan brief and the show vtp
status command:
78 - 82 CCNP 3: Multilayer Switching v 3.0 – Skills-Based Assessment Version 3 - Solutions Copyright © 2004, Cisco Systems, Inc.
VTP Version : 2
Configuration Revision : 1
Maximum VLANs supported locally : 250
Number of existing VLANs : 8
VTP Operating Mode : Server
VTP Domain Name : GEOTECH
VTP Pruning Mode : Disabled
VTP V2 Mode : Disabled
VTP Traps Generation : Disabled
MD5 digest : 0x76 0xAA 0xA2 0xCD 0x7D 0x53 0x21 0xDC
Configuration last modified by 10.0.1.1 at 3-1-93 02:20:06
Local updater ID is 10.0.1.11 on interface Vl1 (lowest numbered VLAN
interface found)
Access1#
79 - 82 CCNP 3: Multilayer Switching v 3.0 – Skills-Based Assessment Version 3 - Solutions Copyright © 2004, Cisco Systems, Inc.
Verifying Port Security
Verify that the host attached to Port 0/12 on Access1 has connectivity only if the
workstation has the appropriate MAC address with the show port-security
interface Fa 0/12 command:
Access1#
Connect a different host to the Fa0/12 port on Access1. Within a minute, the port should
disable itself since the MAC address of the host has changed. Informational messages
generated should be similar to the following:
Access1#
03:50:21: %PM-4-ERR_DISABLE: psecure-violation error detected on Fa0/12,
putting Fa0/12 in err-disable state
03:50:21: %PORT_SECURITY-2-PSECURE_VIOLATION: Security violation occurred,
caused by MAC address 0050.bab2.1f68 on port FastEthernet0/12.
03:50:22: %LINEPROTO-5-UPDOWN: Line protocol on Interface
FastEthernet0/12, changed state to down
03:50:23: %LINK-3-UPDOWN: Interface FastEthernet0/12, changed state to
down
80 - 82 CCNP 3: Multilayer Switching v 3.0 – Skills-Based Assessment Version 3 - Solutions Copyright © 2004, Cisco Systems, Inc.
Issue the show port-security interface fa0/12 command again. Notice that the
security violation count is now one:
Access1#
81 - 82 CCNP 3: Multilayer Switching v 3.0 – Skills-Based Assessment Version 3 - Solutions Copyright © 2004, Cisco Systems, Inc.
Verifying RSPAN Configuration
Verify the RSPAN configuration with the show monitor session all command:
Collapsed-Core#
Access2#
82 - 82 CCNP 3: Multilayer Switching v 3.0 – Skills-Based Assessment Version 3 - Solutions Copyright © 2004, Cisco Systems, Inc.