CCNAX Cag

You might also like

You are on page 1of 130
CCNAX| Interconnecting Cisco Networking Devices: Accelerated Course Administration Guide Version 3.0 Part Number. 97-3636-03, 97-3637-03, 97-3638-03, 97-3639-03) Americas Headquarters Asia Pacific Headquarters Europe Headquarters Gisce Systers, Ie Cisse Systes (USA) Pie Lid isc Syste Irtemstional BV Sandoae, CA Singapore Arstedars The Neterands Ciscahas more than 200 oftces wordude,Aadesses, phone nuribers, and fox numbers ae sted on the Cisco Website at wma cissa.comigoloces. Cisco andthe isco logo are trademarks or repstored ademas of Cisco andr ts alates inthe U.S. and oer counts. To | view a Ist of Cisco traderars, go his URL wn. cscocomgolrademarks.Thic-party trademarks that are mertioned ar the rope ofthe respective ouners. The use othe wo partner doesnot imply a pares elatnship between Cisco and any Ger coreeary. (11105). DISCLAIMER WARRANTY: THIS CONTENT IS BEING PROVIDED “AS IS" AND AS SUCH MAY INCLUDE TYPOGRAPHICAL, GRAPHICS, OR FORMATTING ERRORS. CISCO MANES AND YOU RECEIVE NO WARRANTIES IN CONNECTION Wits THE CONTENT PROVIDED HEREUNDER, EXPRESS. IMPLIED. STATUTORY OR INANY OTHER PROVISION OF THIS CONTENT GR.COMMUNICATION BETWEEN CISCO ANG YOU, CISCO SPECIFICALLY DISCLAINS ALL IMPUED WARRANTIES, INCLUDING WARRANTIES OF MERCHANTABILTY, NOWNFRINGENENT AND ETTNEES FOR A PARTICULAR PURPOSE, (GRARISING FRON A COURSE OF DEALING, USAGE OR TRADE PRACTICE. Tis Warn proauc may cota sty release Contant nd whe Cisco Gebaves tt be accurate, # fas subject othe dclamer above 82017 Cisco Syste, no, ©2017 Cisco Systems, Inc. Table of Contents Course Management 1 Course Description .. - : : - 4 Course Descriptors. - - - - - 4 Curricula. : . : . : . 2 Course Goal... : . : . 2 Prerequisite Skills and Knowledge. : . : . 2 3 3 3 4 Course Instruction Detail... : - : - Instructor Certification Requirements, : - : - Required Classroom Environment. : - : - Detailed Course Flow... : - : - Course Outlines. Detailed Course Outine.. Course Introduction., : ‘Module 1: Building a Simple Network - - - - "1 ‘Module 2: Establishing internet Connectivity... - - - 6 ‘Module 3: Summary Challenge - - 23 ‘Module 4: Implementing Scalable Medium-Sized Networks . - 23 ‘Module 5: Introducing IPV6... - - - 29 ‘Module 6: Troubleshooting Basic Connectivity. - - - 3 ‘Module 7: Implementing Network Device Security. - - - 3 ‘Module 8: Implementing an EIGRP-Based Solution... . - 36 ‘Module 9: Summary Challenge - - 38 ‘Module 10: Implementing a Scalable OSPF-Based Solution . - 38 ‘Module 11: Implementing Wide-Area Networks. - . - 4 ‘Module 12: Network Device Management... - - - 43 ‘Module 13: Summary Challenge. - - - - aT Lab Setup 2 Delivery Lab information... - - : - 49 Lab Equipment Changes... - - - - 50 Lab Details : . - . - 51 Discovery 1: Get Started with Cisco CL... - . - 51 Discovery 2: Perform Basic Switch Configuration. - - - 51 Discovery 3: Observe How a Switch Operates - - - 53. Discovery 4: Troubleshoot Switch Media and Port Issues.. - - 54] Discovery 5: Inspect TCP/P Applications... - - - 55 Discovery 6: Start with Cisco Router Configuration... - - 56 Discovery 7: Configure Cisco Discovery Protocol - - - 57 Discovery 8: Configure Default Gateway... - - - 58. Discovery 9: Explore Packet Forwarding... - - - 59 Discovery 10: Configure and Verify Static Routes - - - 60 Discovery 14: Configure and Verify ACLs... - - a Discovery 12: Configure a Provider-Assigned IP Address. - - 62 Discovery 13: Configure Static NAT - - - - 6. Discovery 14: Configure Dynamic NAT and PAT - 7 - 64. Discovery 15: Troubleshoot NAT. 7 i : co 65 Challenge 1: Summary Challenge Lab 1 - - - sn 68 Challenge 2: Summary Challenge Lab 2 - - - so OT Discovery 16: Configure VLAN and Trunk - - . a) Discovery 17: Troubleshoot VLAN and Trunk Issues - . sv 70 Discovery 18: Configure Root Bridge and Analyze STP Topology. = =i) Discovery 19: Troubleshoot STP Issues. - . sn TD Discovery 20: Configure and Verify EtherChannel.. - . sn TB Discovery 21: Configure a Router on a Stick... - . sn TA Discovery 22: Configure a Cisco Router as a DHCP Server... . sn TB Discovery 23: Troubleshoot DHCP Issues - - . cn 18 Discovery 24: Configure and Verify HSRP - - - con TD Discovery 25: Troubleshoot HSRP. - - . cen TB Discovery 26: Configure and Verify RIPV2. - - - cn TD Discovery 27: Troubleshoot RIPV2 - - . sn 80 Challenge 3: Implementing RIPV2 - - - ce 84 Discovery 28: Configure Basic IPv6 Connectivity... - - a 82 Discovery 29: Configure IPv6 Static Routes... - . so 83 Challenge 4: Implement IPv6 Static Routing... = - a 83 Discovery 30: Use Troubleshooting Tools : - sn 85 Discovery 31: Configure and Verify IPv4 Extended Access Lists. . ce 8B Discovery 32: Troubleshoot IPv4 Network Connectivity... - a 88 Challenge 5: Troubleshoot IPv4 Connectivity... - 89 Discovery 23: Configure and Verify IPvé Extended Access Lists. . so 90 Discovery 34: Troubleshoot IPv6 Network Connectivity... - a OF Challenge 6: Troubleshoot IPvé Connectivity... z - a 9 Discovery 35: Enhance Security of Initial Configuration... - so 9 Discovery 36: Limit Remote Access Connectivity... - - a 94 Challenge 7: Securing Device Administrative Access - . cn 94 Discovery 37: Configure and Verify Port Security... - - 96 Discovery 38: Configure and Verify NTP. - - - a Challenge 8: Implementing Device Hardening... a Discovery 29: Configure External Authentication Using RADIUS and TACACS+ sn 99 Discovery 40: Configure and Verify EIGRP : - - so 100 Discovery 41: Configure and Verify EIGRP for IPV6. - - sn 104 Discovery 42: Troubleshoot EIGRP Issues. - - . sn 102 Challenge 9: Troubleshoot EIGRP. . . - ao 109, Challenge 10: Summary Challenge Lab 3 - - . cn 104 Challenge 11: Summary Challenge Lab 4 - - - sn 105 Discovery 43: Configure and Verify Single-Area OSPF... - so 107 Discovery 44: Configure and Verify Multiarea OSPF - : ce 108 Discovery 45: Configure and Verify OSPF¥3....... - - co 109 Discovery 46: Troubleshoot Multiarea OSPF... . : on 110 Challenge 12: Troubleshoot OSPF. . : co 4 Discovery 47: Configure Serial interface and PPP . - : son 12 Discovery 48: Configure and Verify MLP : - : oe 13 Discovery 49: Configure and Verify a PPPoE Client. - : cn 14 Discovery 50: Configure and Verify a GRE Tunnel. - : on 15 Discovery 51: Configure and Verify Single-Homed EBGP....... : oo 16 Challenge 13: Implement Single-Homed EBGP. - . 116 Discovery 52: Configure Syslog . - 118, Discovery 53: Configure SNMP - - 119, Challenge 14: Summary Challenge Lab 5 - - 119 Challenge 15: Summary Challenge Lab 6 - - 121 ©2017 Cisco Systems, ne Course Adrian Gu Course Management Course Description Course Descriptors Full Tite of Course Intercomecting Cisco Networking Devices: Accelerated Course Onder Code coNax Course Type ur Course Version Number 30 New Course? 10 Replaces Version 2.017 ‘The Cisco CCNA" curriculum includes a third course, Intercomnecting Cisco Networking Devices:| Accelerated (CCNAX), a derivative works course consisting of Interconnecting Cisco Networking Devices, ‘Acuttetate (UNA), 4 UELVGLVE WOIKS CouISe CLESISUI UL ANIEICOMMECUN LASCO INEWWUIRINE LEVIES, Pat | (ICND1) and Intercomnecting Cisco Networking Devices, Part 2 (ICND2) content in its entirety, but ‘with the content merged into a single course. Overlapping content between ICND1 and ICND? is eliminated and content is rearranged for the purpose of the course flow. Interconnecting Cisco Networking Devices: Accelerated (CCNAN), is an instructor led training course that teaches leamers how to install, operate, configure, and verify a basic [Pv and IPv6 network, imeluding configuring a LAN switch, configuring an IP router, connecting to 2 WAN, and identifying basic security threats Italso covers topics in more depth and teaches leamers how to perform basic troubleshooting steps in enterprise branch office networks, preparing learers for Cisco CCNA certification. Curricula ‘The course is used in the following curricula, certifications, or specializations: + Cisco CCENTT + Cisco CCNA Routing and Switching* + Cisco CCD" Course Goal To provide the student with the knowledge, skills, and attitudes required + Install, operate, and troubleshoot medium-sized network, including comecting to a WAN and implementing network security + Describe the effects of new technologies such as IoE, IoT, IWAN, and SDN on network evolution. Prerequisite Skills and Knowledge ‘This topic lists the skills and knowledge that leamers must possess to benefit fully from the course. It includes recommended Cisco leaming offerings that the leamer may complete to benefit fully from this course Recommended Prerequisite Skills ‘The leamer is expected to have the following skills and lmowledge before attending this couse! + Basic computer literacy + Basic PC operating system navigation skills + Basic Intemet usage sills + Basic IP address knowledge + Good understanding of network fundamentals (conan Course Instruction Details Instructor Certifica’ n Requirements Course Instruction Details Instructor Certification Requirements To teach this course, instructors must have attended the following training or completed the following requirements: + New Instructor: = Cartfied Cisco Systems Instructor (CCSD) in good standing, = Cisco CCNA R&S certified — Completed one of the following: + Attended CCNAX v3.0 course + Attended INDI v3.0 and ICND2 v3.0 comes — Pass either the CCNA exam or both the INCD 1 and ICND 2 exams. + Cument CCNAX Instructor: = Certified Cisco Systems Instructor (CSI) in good standing, — Gisco CCNA R&S certified = Complete one of the follow: + Attend CCNAX v3.0 course «Attend ICND1 v3.0 and IGND? v3.0 courses + Attend ICND4 v3.0 and ICND? v3.0 TTT + Complete ICND1 v3.0 and ICND2v3.0 On-demand TTT Review Required Classroom Environment This information describes recommended class size and classroom setup + Room large enough for 16 leamers, set up classroom-style with chairs and tables + Approjector capable of displaying slides + Projection screen, as needed + Whiteboard with surface area of 4x 8 feet or greater] + Usable dry-erase pens in multiple colors + Climate control ‘+ Sufficient power forall equipment + Forlab delivery, access tothe Internet for all leamers and the instructor Detailed Course Flow ‘The course schedule specifies the recommended teaching time for each module. Optionally, indicate breaks and starting and ending times for each day Note CCNAX v3.0 ineludes all content from ICND1 and ICND2 v3.0. tis assumed that i would take 50 hours to complete this course. The level of instruction and the number of hours of instruction is customized to the needs of each class. The actual level of coverage, daily low, and timing are atthe discretion ofthe instructor. They should be set to meet the student's needs. The course flow is described below with the suggested number of hours that should be alloted for each module. Dete led Course Flow Course Introduction {8:90-8:46 (15 min) Module 1: Building a Simple Network Lesson 1: Exploring the Functions of Networking 5:45-2:45 (60 min) Break (2:45-10:00 (15 min) Lesson 2: Understanding the Host-te-Hest Communications Model 10000-10:20 (20 min) Lesson 3: Intreducing LANS 1030-11-00 (30 min) Lesson 4: Operating Cisco IOS Software Discovery 1: Get Started with Cisco CLI 11:09-11:20 (80 min) Lesson 5: Starting = Switch Discovery 2: Perform Basie Switch Configuration 11120-1200 (20 min) Lunch 1200-1230 (30 min) Lesson 8: Understanding Ethernet and Switch Operation Discovery 3: Observe How 2 Switch Operates 12:20-1:00 20 min) Lesson 7: Troubleshooting Common Switch Media sues Discovery 4 Troubleshoot Switch Medie and Pot Issues 4:00-1:20 (20 min) Module 2: Establishing Internet Connectivity Lesson 1: Understanding the TCRIIF internet Layer 1:30-2:00 (20 min) Lesson 2; Understanding IP Addressing and Subnets 2:00-2:00 (20 min) Break 3:00-3:15 (15 min) Lesson 3: Understanding the TCPIIP Transped Layer 3:16-2:45 (20 min) Discovery 5: Inspect TCPIP Applications Lesson 4: Exploring the Functions of Routing 3:45-4:15 (30 min) Lesson 5: Coniiguring @ Cisco Router 4:16-4:45 (20 min) Discovery 6: Start with Cisco Router Configuration Discovery 7: Configure Cisoo Discovery Pretecol Lesson 6: Exploring the Packet Delivery Process, 4:45-6:25 (40 min) Discovery 8 Configure Defauit Gatewsy Discovery & Explore Packet Formarding Break 5:25-5:25 (10 min) Lesson 7: Enabling State Routing 5:36-6:10 (36 min) Discovery 10: Configure and Verity State Routes Lesson 8: Lesming Basics of ACL 610-60 (40 min) Discovery 11: Configure and Verify ACLs Day ends Module 2: Establishing Intemet Connectivity (Cont) Lesson @: Enabling Intemet Connectivity 8:30-10:30 (120 min) Discovery 12: Configure # Provider Assigned IP Address Discovery 13: Configure Stafc NAT Discovery 16: Configure Dynamic NAT and PAT Discovery 16: Troubleshoot NAT Break Module 3: Summary Challenge Lesson 1: Establish Intamat Connectivity rir) Chellenge 1: Surmsry Challenge Leb 1 10:60-11:25 (35 min) Lesson 2: Troubleshoot Intemat Connesivity 11.28611:36 (10 min) Challenge 2: Summary Challenge Lab 2 11-35-1206 (80 min) Lune 1205-12:35 (30 min) srinsration Gude Module 4: Implementing Scalable Medium-Sized Networks Lesson ‘+ Implementing and Troubleshooting VLANs and Trunks Discovery 18: Configure VLAN and Trunks Discovery 17. Troubleshoo! VLAN and Trunk issues 1295-1218 (40 min) Lesson 2: Buleing Redundant Switched Topelogies Discovery 18: Configure Root Bridge and Anelyze STP Topology Discovery 18: Troubleshoot STP Issues 115-209 (45 min) Lesson 3 Improving Redundant Suitched Tapelogies with EtherChnnal Discovery 20: Configure and Verity EtherChnnel 2:00-2:20 (30 min) Lesson 4; Routing between VLANS Discovery 21: Configure @ Router on 8 Stick 230-2100 (30 min} Lesson & Using 2 Cisco 10S Network Device as & DHCP Server Discovery 22: Configure a Cisoo Router as = CHCP Server Discovery 23: Troubleshoot DHCP Issues 3:00-8:35 (36 min) Break 3:36-8:40 (6 min) Lesson 6: Understanding Layer 3 Redundancy Discovery 24: Configure and Verify HERP Discovery 25: Troubleshoot HSRP 3:40-4:10 (80 min) Lesson 7: Implementing FIPV2 Discovery 22: Configure and Verity RIPY2 Discovery 27. Troubleshoot RIPV2 4:10-4:49 (30 min) Challenge 3: Implementing RIPV2 4:40-6:10 (30 min) Module §: Introducing IPv6 Lesson 1: Infreducing Basic IPS 5:10-8:40 (20 min) Lesson 2: Understanding IFV8 Operation Discovery 28: Configure Basic IFvé Connectivity 5:40-8:10 (20 min) Lesson 3: Configuring IPvé Static Routes Discovery 28: Configure IPv6 Static Routes 6:10-6:40 (30 min) Challenge 4: Implement IV@ Static Routing (8:49-7:19 (90 min) Day ends Module 6: Troubleshooting Basie Connectivity Lesson 1: Troubleshooting Pv Network Connectivity Discovery 30: Use Troubleshosting Tools Discovery 31: Configure SPAN Discovery 32: Configure and Verify IPv4 Extended Access Lists Discovery 29: Trouslashact IPs Network Connsctvy 8:30-10:00 (00 min) Challenge 5: Troubleshoot IFwt Connectivity 40200-10:20 (20 min) Break Lesson 2: Troubleshooting IPV8 Network Connectivity Discovery 34: Configure and Verity IPve Extended Access Lists Discovery 26: Trouslashact IPvd Network Connscty 10-40-1140 (80 min) Challenge 6: Troubleshoot IFW Connectivity 1149-12-10 (20 min) Lune 1210-12-40 (20 min) Module 7: Implementing Network Device Security Lesson 1: Securing Administrative Access Discovery 36: Enhance Security of Initial Configurtion Discovery 27 Limit Remote Access Connectivity 1240-10 (20 min) Challenge 7: Securing Device Administrative Access 4210-1:40 (80 min) Lesson 2: Implementing Device Hardening Discovery 38: Configure and Verity Port Security Discovery 38: Configure and Verify NTF ‘r80-2:10 (20 min) Challenge 8: Implamenting Devise Hardening 240-240 (80 min) Lesson 3: Implementing Advanced Security Discovery 40: Configure Extemal Authentication Using RADIUS and TACACS+ 2:40-3:40 (60 min} Break 3:40-3:80 (10 min) Module 8: Implementing an EIGRP-Based Solution Lesson 1: Implementing EIGRP Discovery 41: Configure and Verity EIGRP 3:50-6:20 (90 min) Lesson 2: Implementing EIGRP for IPS Discovery «2: Configure and Verify EIGRF for IPVO 5:20-6:60 (30 min) Break 5:50-8:00 (10 min) Lesson'3 Troubleshooting EIGRP (6:00-6:20 (30 min) Discovery 48: Troubleshoot EIGRP Issues Challenge ©: Troubleshoot EIGRP 630-7100 (30 min) Day ends Module 9: Summary Challenge Lesson 1: Troubleshooting a Medium-Sized Network 8:30-8:46 (16 min) Challenge 10: Summary Challenge Leb 3 5:45-2:20 (45 min) Lesson 2: Troubleshooting Scalable Medium Sized Network 2:30-8:49 (10 min) Challenge 11: Summary Challenge Leb 4 2:40-0:30 (60 min) Break 1030-40-40 (10 min) Module 10: Implementing a Scalable OSPF-Based Solution Lesson 1: Understanding OSPF 1040-11-20 (40 min) Discovery 44: Configure and Verity Single Ares OS Lesson 2: Implementing Multisres GSPF [Pus 11120-1220 (60 min) Discovery 48: Configure and Verity Muitisres OSPF Break 1220-1260 (20 min) Lesson 3: Implementing OSPF for Pv 1250-1:50 40 min) Discovery 48: Configure and Verily O8FRV3 Lesson 4 Troubleshooting Multires OSPF 1:30-2:20 (60 min) Discovery 47: Troubleshoot Muligres CSP Challenge 12: Troubleshoot OSPF 230-8000 (30 min) Break 3:00-2:10 (10 min) Module 11: Implementing Wide-Area Networks Lesson 1: Understanding WAN Technologies 3:10-4:40 (80 min) Lesson 2: Understanding Point-to-Point Protocols 4:40-6:60 (190 min) Discovery 48: Configure Sea Intefsoe and PPP Discovery 48: Configure and Verity MLP Discovery 60: Configure and Verity @ PPPSE Cient Day ends Module 11: Implementing Wide-Area Networks (Cont) Lesson 3: Configuring GRE Tunnals 8:30-10,00 (99 min) Discovery 51: Configure and Verity @ GRE Tunnel Break 10200-10:18 (15 min) Lesson 4: Ceniguring Single Hemed EBGP 10415-11:20 (75 min) Discovery 82: Configure and Verity Single Homed EBGP Challenge 12: Implement Single Homed EBGP 11-30-12.00 (60 min) Lune 12200-1230 (60 min) Module 12: Network Device Management Lesson 1: Implementing Basic Network Device Management 12:90-1:30 (60 min) Discovery 82: Configure Syslog Discovery 58: Configure SNMP Lesson 2: Learring Abou the Evolution af Intligent Networks 430-20 60 min) Lesson 3: Introducing Qos 2:30-300 (20 min) Lesson 4: Managing Cisco Devices 300-320 (30 min) Lesson 5: Licensing 3:90-4:20 (60 min) Breake 490-445 (15 min| Module 13: Summary Challenge Lesson t: Troubleshooting Scalable Multiares Network 448-600 (18 min) Chellange 14: Summary Chelenge Lab 5 500-845 48 min) Lesson 2: Implaranting and Troubleshooting Scalable Mulares Network 845-800 (15 min) Challenge 15: Summary Challenge Leb 6 0:00-645 (69min) Day ends srinsration Gude jevoas:Accaloratad (CCNA (© 2017 Cisco Systems ne Course Outlines Detailed Course Outline This in-depth outline of the course structure lists each module, lesson, and topic. Course Introduction ‘The Course Introduction provides leamers with the course objectives and prerequisite leaner skills and knowledge. The Course Introduction presents the course flow diagram and the icons that are used in the course illustrations and figures. This course component also describes the curriculum for this course, providing leamers with the information that they need to make decisions regarding their specific leaming path. + Overview + Course Goal and Objectives + Course Flow + Your Training Curriculum + Additional References Module 1: Building a Simple Network Objective: Describe network findamentals and implement a simple LAN.| Lesson 1: Exploring the Functions of Networking Objective: Identify the components of a computer network and describe their basic characteristics This lesson includes these topics: + What Isa Computer Network? — Objective: Define e network and describe examples of networks + Physical Components of a Network = Objective: Identify common network components by fimction + Characteristics of a Network ~ Objective: List the characteristics of a network + Physical versus Logical Topologies ~ Objective: Compare and contrast logical and physical topologies, + Interpreting a Network Diagram ~ Objective: Interpret network diagrams ‘+ Impact of User Applications on the Network = Objective: Describe the impact of user applications on the network + Challenge Lesson 2: Understanding the Host-to-Host Communications Model Objective: Understand the model of host-to-host communications ‘This lesson includes these topics: «+ Introducing Host-to- Host Communications ~ Objective: Identify the requirements of a host-to-host communications model + OSIReference Model = Objective: Describe the OSI reference model + TOPAP Protocol Suite ~ Objective: Deseribe the fumetions and purposes of the TCP IP layers + Peer-to-Peer Communications = Objective: Describe how peer-to-peer communication works + Encapsulation and De-encapsulation ~ Objective: Describe the process of encapsulation and de-encapsulation + Challenge Lesson 3: Introducing LANs| Objective: Describe LANs and the role of stitches within LANs This lesson includes these topics: + Local Area Networks = Objective: Define LAN + LAN Components ~ Objective: Identify the components of 2 LAN + Need for Switches (isco Networking Davies: Objective: Identify the need for the switches in aLAN + Switches Objective: List the characteristics and features of switches + Challenge co IOS Software Objective: Describe the features and functions of Cisco 108 Software ‘This lesson includes these topics: Lesson 4: Operating + Cisco IOS Software Features and Functions Objective: List the features and fimctions of Cisco IOS Software + Cisco 10S CLI Functions: Objective: Lists the fimetions and usage of the Cisco CLI + Cisco 10S Software Modes Objective: Identify IOS Software modes on Cisco devices + Discovery 1: Get Started with Cisco CLI Objective: This is the frst lab lesson in the course, and it will help you become familiar with the Cisco CLL Topology Aids Task 1: Navigate Between EXEC Modes Task 2: Explore CLI Help = Task 3: Manage Cisco IOS Configuration Task 4: Improve User Experience in the CLI + Challenge Lesson 5: Starting a Switch] Objective: Install a switch and perform the initial configuration This lesson includes these topics: + Sositch Installation Objective: Identify physical installation requirements + Switch LED Indicators Objective: Identify te conditions that are reflected by the LEDs on switches + Connecting to 2 Console Port — Objective: Comect to a switch console port + Basic show Commands and Information tion Gade co Syste ne. Course Ai = Objective: List fimdamental show commands + Discovery 2: Perform Basic Switch Configuration ~ Objective: Configure the switch ffom the command line and verify the configuration. = Topology = Tob Aids ‘Tesk 1: Configure a Switch from the Command Line ~ Task2: Verify the Switch Initial Startup Status + Challenge Lesson 6: Understanding Ethernet and Switch Operation Objective: Describe Ethemet as the network access layer of TCP/IP and describe the operation of switches This lesson inckudes these topics: + Ethemet LAN Comnection Media = Objective: Describe the types of Ethemet LAN connection media + Ethemet Frame Structure = Objective: Describe the fields of am Ethemet frame + MAC Addresses ~ Objective: Define the structure and fimotion of MAC addresses + Frame Switching ~ Objective: Explain the basic concept of avitching + Discovery 3: Observe How a Switch Operates = Objective: Describe how switches operate and build the CAM table - Topology = Job Aids = Task 1: Observe How a Switch Operates + Duplex Communication ~ Objective: Compare half-duplex and full-duplex operation and also configure it on an interface] + Challenge Lesson 7: Troubleshooting Common Switch Media Issues Objective: Identify and resolve common switched network issues This lesson inctues these topics: Networking + Troubleshooting Methods Objective: Describe the troubleshooting methods + Troubleshooting Tools Objective: Describe common troubleshooting tools + Troubleshooting Common Switch Media Issues, Objective: Identify common switched network media issues + Troubleshooting Common Switeh Port Issues Objective: Identify common access port issues + General Troubleshooting Process = Objective: Describe how to troubleshoot duplex issues + Discovery 4: Troubleshoot Switch Media and Port Issues Objective: Troubleshoot switch media and port issues Topology Aids Task 1: Troubleshoot Port Issues + Challenge Module 2: Establishing Internet Connectivity Objective: Establish Intemet connectivity Lesson 1: Understanding the TCP/IP Internet Layer Objective: Describe [Pv and its addressing scheme This lesson includes these topics: + TP Characteristios Objective: List the characteristics of P + Prd Address Representation = Objective: Describe the components of an [Pv addres + [Ped Header Address Fields Objective: Identify the fields within the IP header + Decimal and Binary Systems = Objective: Describe the decimal and binary mmiber systems + Decimal-to-Binary Conversion = Objective: Convert a decimal mumber to a binary number + DP Address Classes Objective: List the classes of IPvt addresses + Reserved IPod Addresses = Objective: Describe reserved IPv addresses + Private ws. Public IP Addresses ~ Objective: Describe and differentiate between public and private addresses + Domain Name System ~ Objective: Define the fumction of DNS + Verifying the [Pr Adress of a Host ~ Objective: Verify the IP adress of a host + Challenge Lesson 2: Understanding IP Addressing and Subnets Objective: Describe subnets, subnetting, and the role of submet masks This lesson inckudes these topics: + Subnets = Objective: Describe the purposes and functions of subnets and their addressing schemes + Subnet Masks ~ Objective: Explain the role ofa submet mask + Implementing Subnetting: Borrowing Bits ~ Objective: Understand how subnetting is implemented. + Implementing Subnetting: Determining the Addressing Scheme ~ Objective: Understand subnetting + Benefits of VLSM and Implementing VLSM ~ Objective: Describe the role of VLSM and also how to implement it, + Challenge Lesson 3: Understanding the TCP/IP Transport Layer Objective: Describe the TCP IP transport layer This lesson inctues these topics: + TCPAP Transport Layer Functions ~ Objective: Explain the purpose and major functions of the TCPAP transport layer + Reliable vs. Best-Effort Transport ~ Objective: Contrast comnection-oriented transport with connectionless transport + TOP vs, UDP Analogy ~ Objective: Explain the basic difference between TCP and UDP + TCP Characteristics (conan = Objective: Explain the characteristics of TOP in brief + UDP Characteristics Objective: Describe the characteristics of UDP in brief + TCPIP Applicetions = Objective: List the common applications that are provided by TCP1P + Discovery 5: Inspect TCPP Applications Objeotive: List the common applications that are provided by TCPP Topology Aids — Task I: Inspect TCP/IP Applications + Challenge Lesson 4: Exploring the Functions of Routing Objective: Define the role, components and fimetion of a router Understand how a routing table conveys information Understand how a router chooses a path or route Understand how dynamic routing protocols calculate and communicate routing information This lesson includes these topics: + Roleof Router Objective: Describe the role of a router in the IP packet delivery process + Router Components = Objective: Describe the physical characteristics of a router + Router Function = Objective: Describe the fimetions of a router + Routing Table = Objective: Describe the components of a routing table + Dynamic Routing Protocol, Objective: Describe the fimction of dynamic routing protocols] + Path Determination = Objective: Describe router path determination + Route Selection Objective: Describe how router selects the best path + Challenge @20 Lesson 5: Configuring a Cisco Router Objective: Implement basic configuration om a Cisco router This lesson includes these topics: + Initial Router Setup ~ Objective: Describe router startup + Configuring Router Interfaces ~ Objective: Describe how to configuring router interfaces + IP Addresses on Router Interfaces = Objective: Explain how to configure IP address on an interface and why + Checking Interface Configuration and Status ~ Objective: Explain how to check interface configuration + Discovery 6: Start with Cisco Router Configuration ~ Objective: Perform basic Cisco router configuration = Topology Job Aids ~ Task 1: Configure an IP Adéress on the Router Interfaces ~ Toske2: Verify Interface Configuration and Status, + Exploring Connected Devices ~ Objective: Describe the need for a network discovery protocol + Using Cisco Discovery Protocol ~ Objective: Explain how Cisco Discovery Protocol operates + Discovery 7: Configure Cisco Discovery Protocol ~ Objective: Configure and verify Cisco Discovery Protocol and LLDP - Topology = Job Aids = Task 1: Discover Neighbors Using Cisco Discovery Protocol + Configuring LDA ~ Objective: Describe LDP configuration + Challenge Lesson 6: Exploring the Packet Delivery Process Objective: Understand host-to-host communications across switches and routers ‘This lesson includes these topics: (isco Networking Davies: Lesson 7: Enal Address Resolution Protocol Objective: Explain the role of ARP Default Gateways = Objective: Explain what a default gateway is and why its used Discovery 8: Configure Default Gateway Objective: Describe how end systems use submet masks and default gateways Topology Job Aids Task 1: Configure Defauit Gateway ‘Host-to-Host Packet Delivery Objective: Describe host-to-host packet delivery Discovery 9: Explore Packet Forwarding Objective: This discovery will show how packet forwarding happens through devices by observing through show commands and debugs, = Topology = Job Aids — Task 1: Explore Packet Forwarding ‘Troubleshooting Common Problems Associated with IP Addressing Objective: Describe the common common troubleshooting tools ‘Challenge 19 Static Routing Objective: Describe the operation, benefits, and limitations of static routing This lesson includes these topics: Routing Operation Objective: Describe the basic characteristics of routing operations Static and Dynamic Routing Comparison] = Objective: Explain the differences between static and dynamic routing ‘When to Use Static Routing = Objective: Explain when to use static routing Static Route Configuration = Objective: Describe how to configure static routes Default Routes = Objective: Describe how to configure defauit routes ‘Verifying Static Route Configuration @20 = Objective: Describe how to verify static route configuration + Verifying Default Route Configuration ~ Objective: Describe how to verify defauit route configuration + Discovery 10: Configure and Verify Static Routes ~ Objective: Configure and verify static routes = Topology ~ Job Aids = Task 1: Verify Device Reachability ~ Task2: Configure and Verify Static Routes ~ Task 3: Demonstrate State Route Drawbacks = Task-4: Configure and Verify the Backup Static Route ~ Task 5: Configure and Verify the Default Route + Challenge Lesson 8: Learning Basics of ACL Objective: Describe the operation of ACLs and their applications in the network This lesson inctues these topics: + ACL Overview = Objective: Describe ACLs + ACL Operation = Objective: Explain how ACLs operate + ACL Wildcard Masking ~ Objective: Deseribe ACL wildeard masking + Wildcard Bit Mask Abbreviations = Objective: Describe ACL wildcard bit mask abbreviations + Types of ACLs ~ Objective: Describe the types of ACL] + Testing an IP Packet Against a Numbered Standard Access List ~ Objective: Describe how to test an IP packet against a mumbered standard access list + Configuring Standard IPv4 ACLs = Objective: Explain mumbered [Pv ACLs + Discovery 11: Configure and Verify ACLs ae (conan Objective: Configure named and standard ACLs Topology Job Aids = Task 1: Configure Numbered Standard [Pv ACLs Task: Filter Traffic Using ACLs + Using ACLs to Filter Network Traftic — Objective: Describe traffic filtering with ACLs + Applying ACLs to Interfaces Objective: Apply an ACL to an interface + Configuring Named ACLs Objective: Configure and edit named [Pvt ACLs + Challenge Lesson 9: Enabling Internet Connectivity Objective: Configure Internet access using DHCP clients, NAT, and PAT on Cisco routers This lesson includes these topics: + Demarcation Point = Objective: Explain the demarcation point + Provider-Assigned IP Addresses Objective: Explain DHCP and static addressing + Public vs. Private [Prt Addresses, Objective: Explain public versus private [Pv addresses + Discovery 12: Configure a Provider- Assigned IP Address Objective: Configure a static provider-assigmed IP address = Topology Job Aids Task 1: Configure a Provider-Assigned IP Addresd + Introducing NAT = Objective: Describe the features and benefits of NAT «Types of Addresses in NAT = Objective: Describe the types of NAT addresses + Types of NAT = Objective: Describe the types of NAT + Understanding Static NAT ©2017 Cisco Systems, ne Course Adrian Gu = Objective: Explain static NAT + Configuring and Verifying Static NAT = Objective: Explain how to configure and verify static NAT + Discovery 13: Configure Static NAT = Objective: Configure static NAT and explain its operation = Topology ~ Job Aids = Task 1: Configure Static NAT + Understanding Dynamic NAT = Objective: Explain dynamic NAT + Configuring and Verifying Dynamic NAT ~ Objective: Explain how to configure dynamic NAT + Understanding PAT = Objective: Introduce and explain PAT + Configuring and Verifying PAT = Objective: Explain how to configure and verify PAT + Discovery 14: Configure Dynamic NAT and PAT = Objective: Understand how dynamic NAT works and how to configure it = Topology = Job Aids = Task 1: Configure Dynamic NAT and PAT + Troubleshooting NAT = Objective: Explain how to troubleshoot NAT + Discovery 15: Troubleshoot NAT ~ Objective: Troubleshoot NAT-related issues = Topology ~ Job Aids = Task 1: Troubleshoot NAT] + Challenge (isco Networking Davies: Module 3: Summary Challenge (Objective: Establish and troubleshoot internet comsectvity Lesson 1: Establish Internet Connectivity Objective: Establish Intemet connectivity This lesson includes these topics: + Challenge = Challenge 1: Summary Challenge Lab 1 + Objective: Summary Challenge lab on topics from Mod ! and Mod 2. + Topology + Tob Aids + Task {: Summary Chall ge Lab 1 Procedure Lesson 2: Troubleshoot Internet Connectivity Objective: Troubleshoot Internet comnectivity This lesson includes these topics: + Challenge = Challenge 2: Summary Challenge Lab 2 + Objective: Summary Challenge lab on topics from Mod ! and Mod 2. + Topology + Tob Aids + Task 1: Summary Challenge Lab 2 Procedure Module 4: Implementing Scalable Medium-Sized Networks Objective: Lesson 1: Implementing and Troubleshooting VLANs and Trunks| Objective: Implementing and troubleshooting VLANs and trunks, This lesson includes these topics: + Enterprise Network Design Objective: Describe the enterprise network design «Issues ina Poorly Designed Network = Objective: Describe the issues in poorly designed LANs + VLAN Introduction = Objective: Describe the purpose and functions of VLANs + Creating a VLAN = Objective: Explain how to create 2 VLAN + Assigning a Portto a VLAN ~ Objective: Describe how to assign a port toa VLAN + Trmking with 8021 ~ Objective: Define the purpose and fimetion of trunking ‘+ Configuring an 802.1Q Trunk ~ Objective: Describe how to configure an 802.1@ trunk: + Discovery 16: Configure VLAN and Trunk ~ Objective: Configure, verify, and troubleshoot VLANs and trunks, = Topology ~ Job Aids Task 1: Configure VLAN and Trumk + Dynamic Trunking Protocol = Objective: Describe DTP + VLAN Tnumking Protocol = Objective: Describe and Configure VIP + Discovery 17: Troubleshoot VLAN and Trunk Issues ~ Objective: Describe steps to troubleshoot VLAN and trunking through lab, = Topology = Tob Aids ~ Task 1: Troubleshoot VLAN Issues ‘Task 2: Troubleshoot Trunk Issues + VLAN Design Consideration = Objective: Describe VLAN design and creation guidelines + Challenge Lesson 2: Building Redundant Switched Topologies Objective: Build redundant switched topologies This lesson inchudes these topics + Physical Redundancy in a LAN = Objective: Describe physical redundancy in LAN «Issues in Redundant Topologies (conan = Objective: Describe problems that may arise in redundant switched topologies + Loop Resolution with STP = Objective: Describe how loop is resolved with Spamning Tree Protocol + Spanning-Tree Operation, Objective: Describe STP operation + Spamning-Tree Operation Example = Objective: Describe STP operation in the sample topology + Types of Spamiing-Tree Protocols Objective: Describe variants of STP + Comparison of Spanning-Tree Protocols Objective: Describe differences between STPs + Per VLAN Spamning Tree Plus = Objective: Explain how PVST+ improves on the concept of STP + PVST+Extended Bridge ID Objective: Explain PVST+ extended bridge ID + Discovery 18: Configure Root Bridge and Analyze STP Topology — Objective: Describe how to use Cisco IOS commands to analyze the spanning-tree topology and verify the proper operation of STP. = Topology = Job Aids Task 1: Modify the Bridge ID = Task2: Analyze STP Topology + PortFast and BPDU Guard Objective: Demonstrate why PortFast and BPDU guard are important technologies, + Configuring PorfFast and BPDU Guard Objective: Describe how to configure and verify PortFast and BPDU guard + Discovery 19: Troubleshoot STP Issues Objective: Describe the consequences of STP failure and how to troubleshoot STP loops| Topology Job Aids — Task 1: Spanning-Tree Failure Consequences + Challenge ©2017 Cisco Systems, ne Course Adrian Gu Lesson 3: Improving Redundant Switched Topologies with EtherChannel Objective: Configure link aggregation using EtherChannel This lesson includes these topics + Introducing EtherChamne! ~ Objective: Describe the idea behind EtherChamnel technology + EtherChannel Protocols ~ Objective: Identify the two EtherChannel protocols and their modes + Discovery 20: Configure and Verify EtherChannel = Objective: Configure and verify EtherChannel configuration = Topology = Job Aids ~ Task 1: Configure and Verify EtherChannel + Challenge Lesson 4: Routing Between VLANs Objective: Describe the application and configuration of inter-VLAN routing This lesson inckudes these topics: + Purpose of Inter-VLAN Routing ~ Objective: Deseribe the need for inter.VLAN routing + Options for Inter- VLAN Routing = Objective: Describe options for inter-VLAN routing + Discovery 21: Configure « Router on a Stick = Objective: Configure router on a stick - Topology = Tob Aids| Tesk 1: Configure a Router with a Trunk Link + Challenge Lesson 5: Using a Cisco IOS Network Device as a DHCP Server Objective: Configure a Cisco 10S DHCP 14 server om a Cisco router and switch ‘This lesson includes these topics: + Need fora DHCP Server = Objective: Describe the need for dynamic host IP address assignment, + Understanding DHCP Note This topic focuses on DHCP address allocation. Students should already be familiar with general DHCP properties and other DHGP allocation methods. = Objective: Describe DHCP operation + Configuring a DHCP Server = Objective: Configue DHCP server + Discovery 22: Configure a Cisco Router as a DHCP Server = Objective: Configure and verify Cisco routers as DHCP servers = Topology = Job Aids = Task 1: Config + Understanding DNS = Objective: Describe how DNS lookup works + Discovery 23: Troubleshoot DHCP Issues = Objective: Troubleshoot DHCP and DNS issues Topology = Job Aid = Task 1: Troubleshooting DHCP Issues + Challenge ‘Cisco Router as a DHCP Server Lesson 6: Understanding Layer 3 Redundancy Objective: Describe the purpose of Layer 3 redundancy protocols This lesson includes these topics] + Need for Default Gateway Redmdancy Objective: Describe routing issues in connection to redundancy + Understanding FHRP Objective: Describe the router redundancy process and what happens when a failover occurs +) Understanding HSRP = Objective: + Discovery 24: Configure and Verify HSRP Objective: Configure and verify HSRP Topology = Job Aids Task 1: Cor and Verify HSRP + Discovery 25: Troubleshoot HSRP = Objective: Troubleshoot HSRP = Topology = Job Aids = Task 1: Troubleshoot HSRP + Challenge Lesson 7: Implementing RIPv2 Objective: Describe the operation and configuration of RIPY2 This lesson inctues these topics: + Overview of Routing Protocols = Objective: Describe the need for dynamic routing protocols + Distance Vector and Link-State Routing Protocols = Objective: Describe the distance vector and link-state routing protocols + Understanding RIPV2 ~ Objective: Deseribe RIPV2 + Configure RIPV2 = Objective: Describe how to configure RIPV2 + Verify RIP = Objective: Describe how to verify RIPS2 + Discovery 26: Configure and Verify RIPV2 (isco Networking Davies: = Objective: Configure and verify RIPe2 = Topology Job Aids Task 1: Configure and Verify RIPY2 Task: Adjust RIP Timers Task 3: Disable RIP Autosummary — Task 4: Configure a RIP Passive Interface Task 5: Generate a Defauit RIP Route + Discovery 27: Troubleshoot RIPV2 Objective: Troubleshoot RIPY2 = Topology = Job Aids — Task 1: Troubleshoot RIPV2 + Challenge Challenge 3: Implementing RIPV2 + Objective: Configure and troubleshoot RIPY2 + Topology + Tob Aids + Task 1: Evaluation Lab Procedure + Command List Module 5: Introducing IPv6 (Objective: Describe IPv6 basies Lesson 1: Introducing Basic IPv6é Objective: Describe the IPv6 main features and addresses This lesson includes these topics: + [Ped Adéress Exhaustion Workaround Objective: Identify IPv4 addressing exhaustion workarounds + Po6 Features Objective: Identify the main IPv6 features + Pv6 Addresses, Objective: Describe IPv6 addresses and address types + IPv6 Address Scopes and Prefixes ©2017 Cisco Systems, ne Aariisration Gace 29 Objective: Describe the IPv6 unicast addresses + IPv6 Address Allocation Objective: Describe manual address assignment, stateless autoconfiguration, and DHCPv6 © Challenge Lesson 2: Understanding IPvé Operation Objective: Describe IPv6 operations and basic TPv6 configuration This lesson inctues these topics: + Comparison of Pv and IPvé Headers ~ Objective: Compare the [Pv and IPv6 headers + Intemet Control Message Protocol Version 6 = Objective: Describe ICMPvé + Neighbor Discovery = Objective: Describe the neighbor discovery process: and mapping from IPv6 addresses to Layer 2 addresses + Stateless Adress Autoconfiguration. ~ Objective: Describe and configure stateless autoconfiguration + Discovery 28: Configure Basic IPv6 Connectivity ~ Objective: Configure basic IPv6 commands = Topology ~ Job Aids ~ Task 1: Configure IPv6 Addresses ~ Task2: Configure IPV6 Stateless Autoconfiguration + Challenge Lesson 3: Configuring IPv6 Static Routes| Objective: Identify routing protocols for IPu6 This lesson includes these topics: + Routing for Ps ~ Objective: Deseribe routing types for IPv6 + Configuring IPv6 Static Routes oe (conan Objective: Describe how to configure and verify IPv6 static routes + Discovery 29: Conflgue IPv6 Static Routes Objective: Configure and verify IPvG static routes, = Topology Aids Task 1: Configure IPv6 Default Routes — Task2: Configure IPv6 Static Routes + Challenge — Challenge 4: Implement IPV6 Static Routing + Objective: Troubleshoot IPv6 routing + Topology + Tob Aid + Task I: Evaluation Lab Procedure + Command List Module 6: Troubleshooting Basic Connectivity Objective: Troubleshoot IP connectivity Lesson 1: Troubleshooting IPv4 Network Connectivity Objective: Troubleshoot end-to-end connectivity in an [Pv network: ‘This lesson includes these topics: + Troubleshooting Guidelines = Objective: Show various components of troubleshooting IP comnectivity + Discovery 30: Use Troubleshooting Tools = Objective: Describe how troubleshooting tools cam be used to verify connectivity issue = Topology = Job Aid| = Task 1: Use Troubleshooting Tools + Troubleshooting Physical Comectivity Issue — Objective: Explain how to identify and fix physical connectivity issues + Identification of Curent and Desired Path = Objective: Show how the current and desired path can be identified + Using SPAN for Troubleshooting Objective: Describe the use of SPAN for troubleshooting + Troubleshooting Default Gateway Issues = Objective: Describe how a misconfigured gateway affects connectivity + Troubleshooting Name Resolution Issues ~ Objective: Describe how misconfigured name resolution settings affect network: comectivity + Discovery 31: Configure and Verify [Pwd Extended Access Lists ~ Objective: Configure and verify TPv4 extended access lists = Topology ~ Job Aids = Task 1: Configure and Verify IPv4 Extended Access Lists + Troubleshooting ACL Issues ~ Objective: Deseribe how a misconfigured ACL affects network connectivity + Discovery 32: Troubleshoot IP Network Connectivity ~ Objective: Troubleshoot [Pr network comectivity issues - Topology = Job Aids ~ Task 1: Troubleshoot IPv4 Network Connectivity + Challenge ~ Challenge 5: Troubleshoot IPv4 Connectivity + Objective: Perform [Pv connectivity troubleshooting based on the challenge introduction. + Topology + Job Aids «Task 1: Troubleshooting IPv4 Connectivity Lab Procedure + Command List Lesson 2: Troubleshooting IPv6 Network Connectivity Objective: Troubleshoot connectivity in an IPv6 network: ‘This lesson includes these topics: + PUG Unicast Addressed = Objective: Describe IPv6 addressing + Troubleshooting End-to-End IPv6 Comectivity ~ Objective: Describe possible causes of failed IPV6 connectivity + Verification of End-to-End [Pv6 Connectivity ~ Objective: Describe usage of IPv6 end-to-end connectivity verification tools ‘+ dentfication of Curent and Desired IPv6 Path = Objective: Describe how to identify IPv6 paths throughout the network + Troubleshooting Default Gateway Issues in TPV6 (isco Networking Davies: Objective: Describe how to verify thatthe IPv6 default gateway is set correctly + Troubleshooting Name Resolution Issues in IPv6 Objective: Describe how misconfigured DNS settings influence network behavior + Discovery 33: Configure and Verify IPv6 Extended Access Lists = Objective: Configure and verify IPvé extended access lists = Topology Aids Task 1: Configure and Verify IPv6 Extended Access Lists + Troubleshooting ACL Issues in IPV6 = Objective: Describe how a misconfigured IPv6 ACL affects network connectivity + Discovery 34: Troubleshoot IPv6 Network Connectivity = Objective: Troubleshoot IPv6 network connectivity issmes Topology Aids Task 1: Troubleshoot IPv6 Network Connectivity + Challenge Challenge 6: Troubleshoot IPv6 Comectivity + Objective: Perform IPv6 connectivity troubleshooting based on challenge introduction + Topology + Tob Aids «Task I: Troubleshooting IPv6 Connectivity Lab Procedure + Command List Module 7: Implementing Network Device Security Objective: Configure, manage and monitor Cisco devices. Lesson 1: Securing Administrative Access| Objective: Implement a basic security configuration This lesson includes these topics: + Network Device Security Overview Objective: List the actions that are required to secure 2 network device ‘+ Securing Access to Privileged EXEC Mode Objective: Secure access to privileged EXEC mode + Securing Console Access Objective: Secure console access to a network device + Securing Remote Access Course Adrian Gu = Objective: Secure remote access to a network device + Discovery 35: Enhance Security of Initial Configuration ~ Objective: Leam basic configuration to secure initial config = Topology = Tob Aids = Task 1: Secure Access to Privileged EXEC Mode ~ Task 2: Secure Console and Remote Access ~ Tosk:3: Enable SSH + Limiting Remote Access with ACLs ~ Objective: Limit remote access with an ACL + Configuring the Login Banner ~ Objective: Configure the login banner + Discovery 36: Limit Remote Access Comnectivity ~ Objective: Leam how to enable and secure remote access connectivity - Topology - Job Aids ~ Task 1: Limit Remote Access with ACLs = Task 2: Configure the Login and EXEC Banners + Challenge ~ Challenge 7: Securing Device Administrative Access + Objective: Describe how to secure access to devices, + Topology + Job Aids «Task 1: Evaluation Lab Procedure + Command List Lesson 2: Implementing Device Hardening| Objective: Implement basic steps to harden network devices ‘This lesson incbudes these topics: + Securing Unused Ports = Objective: Secure unused ports + Port Security ~ Objective: Describe port security + Configuring Port Security (isco Networking Davies: Objective: Configure port security + Verifying Port Security Objective: Verify port security + Discovery 37: Configure and Verify Port Security Objective: Leam to configure port security and Verify Port Security + Disabling Unused Services Objective: Disable unused services + Network Time Protocol = Objective: Describe NTP + Configuring NTP = Objective: Configure basic NTP + Verifying NTP = Objective: Verify NTP + Discovery 38: Configure and Verify NTP = Objective: Configure and verify NTP in client server mode Topology Job Aids = Task 1: Configure and Verify NTP + Challenge Challenge 8: Implementing Device Hardening + Objective: Leam to configure NTP and port security + Topology + Tob Aids + Task 1: Evaluation Lab Procedure + Command Lis Lesson 3: Implementing Advanced Security Objective: Describe how network security is implemented. This lesson includes these topics: + Mitigating Threats atthe Access Layer = Objective: Describe common access layer threat mitigation techniques + Extemal Authentication Options @20 = Objective: Describe TACACS+ and RADIUS options for external authentication + Discovery 39: Configure External Authentication Using RADIUS and TACACS+ ~ Objective: Configure and verify device management by using AAA with TACACS+ and RADIUS = Topology = Tob Aids ‘Task 1: Configure RADIUS for Console and vty Access ~ Task 2: Configure TACACS+ for Console and vty Access + Challenge Module 8: Implementing an EIGRP-Based Solution Objective: Describe how to configure and troubleshoot EIGRP in an [Pvt environment, and configure EIGRP for Pv6 Lesson 1: Implementing EIGRP Objective: introduce dynamic routing protocols, EIGRP, and its basic configuration This lesson includes these topics: + Dywamie Routing Protocols ~ Objective: Describe the idea behind dymamic routing protocols + Adininisvative Distance ~ Objective: Describe the purpose of administrative distance + EIGRP Features = Objective: Describe EIGRP features: + EIGRP Path Selection ~ Objective: Explain how EIGRP chooses the best path +) EIGRP Metric = Objective: Describe the EIGRP composite metric + Discovery 40: Configure and Verify EIGRF{ = Objective: Configure and verify EIGRP = Topology = Job Aids ~ Task 1: Configure and Verify EIGRP + EIGRP Load Balancing ~ Objective: Explain load balancing with EIGRP + Challenge Lesson 2: Implementing EIGRP for IPv6 Objective: Describe the implementation of EIGRP for IPv6 This lesson includes these topics: + EIGRP for v6 Objective: Describe how EIGRP is used for IPv6 + Discovery 41: Configure and Verify EIGRP for IPvs Objective: Configure and verify EIGRP for IPv6 = Topology = Job Aids Task 1: Configure and Verify EIGRP for IPv6 + Challenge Lesson 3: Troubleshooting EIGRP Objective: Describe how to troubleshoot common EIGRP issues, This lesson includes these topics: + Troubleshooting EIGRP Issues = Objective: Describe the basic components of troubleshooting a network that is running EIGRP + Troubleshooting EIGRP Neighbor Isoues = Objective: Identify and resolve EIGRP neighbor relationship issues + Troubleshooting EIGRP Routing Table Issues Objective: Identify and resolve EIGRP routing table issues + Troubleshooting EIGRP for [Pv Issues Objective: Describe the basic components of troubleshooting a network that is rumning EIGRP for xs + Discovery 42: Troubleshoot EIGRP Issues = Objective: Troubleshoot common EIGRP issues through lat Topology Job Aids Task 1: Troubleshoot EIGRP Issues + Challenge — Challenge 9: Troubleshoot EIGRP + Objective: Troubleshoot common EIGRP-related issues. + Topology + Tob Aids + Task 1: Troubleshooting EIGRP Lab Procedure © Command List Module 9: Summary Challenge Objective: Implement and troubleshoot a scalable medium sized network. Lesson 1: Troubleshooting a Medium-Sized Network Objective: To troubleshoot a medium sized network, This lesson inckudes these topics: + Challenge ~ Challenge 10: Summary Challenge Lab 3 ‘+ Objective: Based on Mod 3 and Mod 4 topics @ summary challenge lab to be created + Topology + Job Aids + Task 1: Summary Challenge Lab 3 Procedure Lesson 2: Troubleshooting Scalable Medium-Sized Network Objective: To troubleshoot a scalable medium sized network. This lesson inckudes these topics: + Challenge ~ Challenge 11: Summary Challenge Lab 4 + Objective: Implement and troubleshoot « medium sized network. + Topology + Job Aids + Task 1: Summary Chall ige Lab 4 Procedure Module 10: Implementing a Scalable OSPF-Based Solution| Objective: Configure and troubleshoot OSPF in an [Pv environment and configure OSPF for Pcé Lesson 1: Understanding OSPF Objective: Describe the basic components and terms of OSPF This lesson inctues these topics: + Link State Routing Protocol ~ Objective: Explain basi facts about link-state protocols «+ Link State Routing Protocol Data Structures Objective: Describe the data structures that are used by linkestate routing protocols + Introducing OSPF Objective: Describe the features of OSPF «Establishing OSPF Neighbor Adjacencies, = Objective: Describe how OSPF neighbor adjacencies are established + OSPF Neighbor States Objective: Describe OSPF neighbor states + SPF Algorithm Objective: Explain how OSPF chooses the best path through the network: + Building 2 Link-State Database = Objective: Describe how routers build and synchronize the link-state database + OSPF Packet Types = Objective: Describe and understand the OSPF packet types + Discovery 43: Configure and Verify Single-Ares OSPF = Objective: Configue and verify the OSPF configuration = Topology Job Aids Task 1: Configure and Verify Single-Area OSPF + Challenge Lesson 2: Implementing Multiarea OSPF IPv4 Objective: Describe how to implement multiarea OSPF This lesson includes these topics: + OSPF Area Structure = Objective: Describe the concept of areas in OSPF and why areas are needed. + Single-Area vs, Multiarea OSPF — Objective: Explain the differences between single-area and multiarea OSPF] «Discovery 44: Configure and Verify Multiarea OSPF = Objective: Describe how to configure multiarea OSPF — Task 1: Configure and Verify Multiarea OSPF + Challenge ©2017 Cisco Systems, ne Course Adrian Gu Lesson 3: Implementing OSPFv3 for IPv6é Objective: Describe how to implement OSPF in an IPv6 network This lesson includes these topics: «© OSPF3 for v6 ~ Objective: Introduce OSPF 13 and describe how itis different from OSPF for Pvt + Discovery 45: Configure and Verify OSPFv3 Objective: Daseribe how to configure OSPFv3 for [Pvé ~ Topology - Job Aids Task 1: Configure and Verify OSPFv3 + Challenge Lesson 4: Troubleshooting Multiarea OSPF Objective: Troubleshoot multiarea, OSPF This lesson inckudes these topics: + Components of Troubleshooting OSPF = Objective: Describe how to troubleshoot OSPF + Troubleshooting OSPF Neighbor Issues = Objective: Describe how to troubleshoot OSPF neighbor issues + Troubleshooting OSPF Routing Table Issues = _ Objective: Describe how to troubleshoot OSPF routing table issues ‘+ Troubleshooting OSPF Path Selection ~ Objective: Describe how to troubleshoot OSPF path selection issues + Troubleshooting OSPF Issues = Objective: Describe how to troubleshoot OSPFv'3 + Discovery 46: Troubleshoot Multiarea OSPF] ~ Objective: Describe how to troubleshoot multiarea OSPF = Topology = Job Aids ~ Task 1: Troubleshoot Multiares OSPF + Challenge ~ Challenge 12: Troubleshoot OSPF ‘+ Objective: Troubleshoot common OSPF elated issues + Topology «Task 1: Troubleshoot OSPF Lab Procedure + Command List Module 11: Implementing Wide-Area Networks Objective: Define characteristics, fimetions, and components of a WAN Lesson 1: Understanding WAN Technologies Objective: Leam basic WAN concepts This lesson includes these topics: «+ Introduetion to WAN Technologies Objective: Explain WAN technologies + WAN Topology Options — Objective: Describe the WAN topology options + WAN Connectivity Options Objective: Describe the major WAN communication link options + Provider-Managed VPNs = Objective: Describe provider-managed VPNs + Enterprise-Managed VPNs Objective: Describe enterprise-managed VPNs + WAN Devices Objective: Describe the WAN devices and their functions in a WAN environment + Challenge Lesson 2: Understanding Point-to-Point Protocols Objective: Configure serial connection using PPP This lesson includes these topics] ‘+ Serial Point-to-Point Communication Links = Objective: Explain the idea behind serial links + Point-to-Point Protocol Objective: Describe point-to-point protocol + Discovery 47: Configure Serial Interface and PPP Objective: Configure serial interfaces with PPP encapsulation and authentication = Topology = Job Aids = Task 1: Configure Serial Interface for PPP ~ Task-2: Configure PAP Authentication for PPP ~ Taske3: Configure CHAP Authentication for PPP Diseovery 48: Configure and Verify MLP = Objective: Configure and verify MLP = Topology - Job Aids ‘Task 1: Configure and Verify MLP Discovery 49: Configure and Verify a PPPoE Client Objective: Configure and verify PPPoE = Topology = Tob Aids = Task 1: Configure and Verify a PPPoE Client Challenge Lesson 3; Configuring GRE Tunnels Objective: Configure GRE tumels This lesson inckudes these topics: GRE Tunnel Overview ~ Objective: Describe GRE tumeling Discovery 50: Configure and Verify a GRE Tmmnel = Objective: Configure and verify a GRE tunnel = Topology = Job Aids| = Task 1: Configure and Verify a GRE Tunnel Challenge Lesson 4: Configuring Single-Homed EBGP Objective: Configure and verify single homed EBGP ‘This lesson includes these topics: + Interdomain Routing Objective: Describe interdomain routing + Introduction to EBGP = Objective: Describe EBGP basics + Discovery 51: Configure and Verify Single Homed EBGP Objective: Configure and verify EBGP Topology Aids ‘Task 1: Configure and Verify Single Homed EBGP + Challenge Challenge 13: Implement Single Homed EBGP + Objective: Configure and verify single-homed EBGP + Topology + Tob Aids + Task 1: plement Single-Homed EBGP Lab Procedure + Command List Module 12: Network Device Management Objective: Describe how device management can be implemented using the traditional and intelligent ways Lesson 1: Implementing Basic Network Device Management Objective: Configure System Message Logging and SNMP. This lesson includes these topics: + Introducing Syslog Objective: Explain why syslog is used + Syslog Message Fomnat — Objective: Describe the format of syslog messazes| + Syslog Configuration = Objective: Configure syslog on a Cisco device + Discovery 52: Configure Syslog Objective: Describe Syslog Configuration = Topology Job Aids Task 1: Configure Syslog + SNMP Overview = Objective: Explain why SNMP is used and how it works and its different versions + Discovery 53: Configure SNMP = Objective: Configure and verify SNMP = Topology = Tob Aids ‘Tesk 1: Configure SNMP + Challenge Lesson 2: Learning About the Evolution of Intelligent Networks Objective: Describe smart network: management solutions like Cisco APIC-EM and Cisco IWAN ‘This lesson includes these topics: + Suitch Stacking = Objective: Describe switch stacking and chassis aggregation + Cloud Computing and Its Effect on Enterprise Networks = Objective: Describe the effect of cloud computing on enterprise networks + Overview of Network Programmability in Enterprise Networks = Objective: Describe the basics of SDN and its role in enterprise networks + Application Programming Interfaces = Objective: Describe northbound and southbound APIs + Ciseo APICEM ~ Objective: Describe Cisco APIC-EM and its features + Cisco Intelligent WAN ~ Objective: Deseribe Ciseo WAN + Challenge Lesson 3: Introducing Qos| Objective: Describe basic QoS concepts This lesson inckudes these topics: + Traffic Characteristics ~ Objective: Identify different traffic types within an enterprise network and how those relate to QoS + Need for QoS = Objective: Describe the need for Qos in an enterprise network + QoS Mechanisms Overview (conan Objective: Identify basic groups of QoS mechanisms + Trust Boundary Objective: Describe the significance of a Qos trust boundary + QoS Mechanisms—Classification and Marking = Objective: Describe the idea behind classification and marking + Classification Tools — Objective: Identify QoS classification tools + QoS Mechanisms—Policing, Shaping, and Re-Marking Objective: Describe the idea behind policing and shaping + Tools for Managing Congestion = Objective: Describe QoS scheduling and queuing mechanims + Tools for Congestion Avoidance — Objective: Describe the idea of QoS congestion avoidance + Challenge Lesson 4: Managing Cisco Devices Objective: Describe the management of Cisco devices This lesson includes these topics: + Router Intemal Components Objective: Describe the major intemal components of a Cisco router + ROM Functions Objective: Describe the fumctions of ROM ina Cisco router + Stages ofthe Router Power-On Boot Sequence Objective: Describe the sequence of events that occurs during a router boot + Configuration Register = Objective: Describe how to display the boot information in the configuration register + Locating Cisco 10S Image File Objective: Describe the process of locating Cisco 10S images + Loading Cisco 10S Image Files = Objective: Describe the process of loading Cisco TOS images, + Loading Cisco 10S Configuration Files = Objective: Describe the process of loading Cisco IOS configuration files + Cisco IOS Integrated File System and Devices = Objective: Describe the file systems that are used by a Cisco router + Managing Cisco IOS Images @20 = Objective: Describe why itis important to create a backup of Cisco 10S images and configuration files + Deciphering Ciseo JOS Image Filenames ~ Objective: Describe how to decipher Cisco IOS image filenames +) Managing Device Configuration Files ~ Objective: Describe the configuration fles and their location + Password Recovery = Objective: Describe how to perform a password recovery on a Cisco router + Challenge Lesson 5: Licensing Objective: Describe licensing under Cisco IOS 15 In this lesson, you can use EAI to demonstrate license installation and verification. This lesson includes these topics: + Introducing Licensing = Objective: Explain Cisco 10S image licensing + Livensing Verification ~ Objective: Explain how a current version ofthe license can be identified + Permanent License Installation ~ Objective: Explain how to installa permanent license + Evaluation License Installation = Objective: Explain how to install an evaluation License + Backing Up the License ~ Objective: Explain how to back up a license + Uninstalling the License ~ Objective: Explain how to uninstall a license + Cisco Smart Software Manager| ~ Objective: Describe Ciseo Smart Software Manager + Challenge 8 (isco Networking Davies: Module 13: Summary Challenge (Objective: Implement and troubleshoot 2 scalable multiarea network Lesson 1: Troubleshooting Scalable Multiarea Network Objective: Implement and troubleshoot a scalable multiarea network This lesson includes these topics: + Challenge = Challenge 14: Summary Challenge Lab 5 + Objective: Implement and troubleshoot 2 scalable multiarea network: + Topology + Tob Aids + Task 1: Summary Challenge Lab 5 Procedure Lesson 2: Implementing and Troubleshooting Scalable Multiarea Network (Objective: Implement and troubleshoot a scalable multiarea network: This lesson includes these topics: + Challenge Challenge 15: Summary Challenge Lab 6 + Objective: Complete the summary troubleshooting lab + Topology + Tob Aids + Task 1: Summary Challenge Lab 6 Procedure (© 2017 Cisco Systems ne Lab Setup Delivery Lab Information CCNAX labs for the instructor-led course are integrated into this training and available through Learning Partner Cisco Leaming Labs (LP CLL). The LP CLL offers a virtual prectice lab bundle that replaces, hardware-based labs. Learners are provided with hands-on Cisco 10S Software lab practice for both routing and core switching. The lab guides for the LP CLL labs are available in both PDF format and through the LPCLL GUL. The LP CLL labs are delivered though the Leaming Partner Cisco Leaming Labs portal. The student needs only a PC and Intemet access. This delivery method removes the need for a training partner to provide hardware and access to that hardware CCNAX labs introduce equipment to the student step-by-step, aligned with the course content according to the following scenario. Labs in the frst module start with a single switch, which enables connectivity between netivork: devices. The second module introduces a router to the topology, which enables students to configure everything needed to comect the office to the Internet. The third module has two summary challenge labs based on the topics described so far. To satisfy the growth of the local network with many VANS, labs inthe fourth module introduce routing between VLANs and introduces RIPV2 The fifth module introduces IPv6 comnectivity between different networks. In the next module students will implement and troubleshoot issues in the medium-sized networks. Students will continue to troubleshoot basic IP and IPvé issues. In the eighth and tenth modules, students will implement EIGRP-based solutions and in module five, OSPF-based solutions. Students will implement different WAN solutions in module eleven, and will implement network device management in the last module ‘A solution is provided at the end of the Lab Guide for each lab exercise. The instructor should reference the Course Administration Guide and employ the Lab Guide to mentor learners during labs, maximizing their hhands-on experience For the instructor-led training class delivered using Cisco LP CLLs, aa individual pod for each student is | recommended Note ‘Summary challenges should be allotted 60 minutes. The expectation is that only an Note ‘Summary challenges should be allotted 60 minutes. The expectation is that only an advanced student will be able to complete all tasks in the challenge within this time, The average stucient may only be able to complete 50% of the challenge, which is fine, The instructor should discuss the challenge lab after this. This will help prepare them for the Lab Equipment Changes CCNAX will be developed using all virtual labs for both challenges and discoveries. To order the Cisco Leaming Labs, the administrator or instructor should review the Cisco Learning Labs scheduler tool policy and procedures document for the lab ordering process. After the lab is ordered, the administrator and instructor will receive lab access instructions on the Friday before class. The email will also include student lab credentials Instructors are encouraged to spend time practicing new discovery and challenge labs. ‘When dealing with virtal lbs, there area few specifics you should be familiar with: 4+ Network devices like routers and switches mun a special Cisco IOS Software build for virtual environments. + AILPCs are simulated by using the same software image as routers. This is sufficient to perform basic comnectivity tests using ping and traceroute or to verify DHCP assignments +All switches are actually routers, simulated by using a Layer 2 software image. +The interface state on one device does not reflect a disebled interface on the other side of the link. The interface wall always be inthe up‘up state as soom as the interface is administratively enabled. For additional information on how to operate and customize Cisco Leaming Labs, refer to the "Frequently Asked Questions” section available in the Cisco Learning Labs portal ‘The overall instructional design of the new CCNAX training is now heavily focused on lab-based leaming, The discovery and challenge labs that are used throughout this training were designed to be conducted using ‘virtua lab environment that provides a capability for each student to complete the exercises independently and to move back and forth between labs as needed to reinforce the training topics and to maximize the effectiveness of the trainin (isco Networking Davies: Lab Details This topic contains the auto-generated list of all labs (Learning and Evaluation) in the course, Discovery 1: Get Started with Cisco CLI This topic details the lab activity for Discovery 1: Get Started with Cisco CLI. Objective: This is the first lab lesson in the course, and it will help you become familiar with the Cisco CLL In this discovery lab, you will leam about EXEC modes, CLI help, and the CLI eor message. You will also eam how to manage Cisco IOS configuration and how to improve user experience in CLI Topology Topology Discovery 2: Perform Basic Switch Configuration This topic details the lab activity for Discovery 2: Perform Basie Switch Configuration. Objective: Configure the switch from the command line and verify the configuration] This discovery session guides you through the inital configuration of a switch with Cisco 10S Software. ‘The lab is prepared with the devices that are represented in the topology diagram, with the IP addresses depicted inthe table. Note that PCI, PC2, SW2, and R1 are filly configured. In this discovery session, your task will be to provide an initial configuration for SWI. During the session, you will configure and verify cach ofthe following settings on SWT: + Hostname + address + Default gateway ‘You will also verify switch settings by using different show commands Topology Topology Ri 52 ___Interconnectng Cisco Networking Davies: Acoserated (CCNA) (© 2017 Cisco Systems ne Discovery 3: Observe How a Switch Operates ‘This topic details the lab activity for Discovery 3: Observe How a Switch Operates. Objective: Describe how switches operate and build the CAM table This discovery session will let you observe how a switch maintain its MAC address table, which it uses to control the forwarding of ftames. The lab is prepared with the devices that are represented in the topology diagram with the IP addresses, as depicted in the table, All devices are filly configured. Topology Topology (©2017 Cisco Systems, ne Course Adrnistration Gace eo Discovery 4: Troubleshoot Switch Media and Port Issues ‘This topic details the lab activity for Discovery 4: Troubleshoot Switch Media and Port Issues. Objective: Troubleshoot snitch media and pott issues In this activity, you will use troubleshooting guidelines to isolate and comect switch media issues. You will, follow troubleshooting guidelines to determine the source of connectivity problems between 2 computer and a switch and between a router and a switeh and fix them, Topology Topology sway EthOrT EtnOv0' Ethor2 jevoas:Accaloratad (CCNA (© 2017 Cisco Systems ne 54 —_lnteroonneding Cisco Networ Discovery 5: Inspect TCP/IP Applications| This topic details the lab activity for Discovery 5: Inspect TCP/IP Applications Objective: List the common applications that are provided by TCP/IP ‘This discovery lab will help you explore TCP and UDP sockets—that is, how TCP and UDP servers listen on particular ports that are made available on particular interfaces, and how clients connect to the servers using their ovin IP addresses and their owm ports. The lab is prepared with the devices that ae represented in the topology diagram with the IP addresses as depicted in the table. Topology Topology (©2017 Gace Stone, ne se haiti Gade Discovery 6: Start with Cisco Router Configuration| ‘This topic details the lab activity for Discovery 6: Start with Cisco Router Configuration. Objective: Perform basic Cisco router configuration Objective: Perform basic Cisco router configuration ‘This discovery lab will guide you through the configuration of an interface on a Cisco 10S router. The lab is prepared with the devices that are represented in the topology diagram and in the connectivity table. In general, the devices are filly configured. An exception isthe interface Ethemet0/O on R1. You will Configure that interface now. Topology Topology Ethort o" im EthOV0 EthOrT thor 3 __lteroannasting Gece Networking Devices: Acalaratad (CCNAX) Discovery 7: Configure Cisco This topic details the lab activity for Discovery 7: Configure Cisco Discovery Protocol Objective: Configure and wef Cisco Discovery Protocol and LLDP During this discovery lab, you will use Cisco Discovery Protocol to map the connectivity within an iar uattsnck Th ” foe toalaans and sb Bhaicconesla. ‘opology, you donot inow hov they are connected. Using Cisco Bisovery Protocol commands, you will detenaine ‘the actual topology Topology Topology ——"* sw = = 82017 Gisco Systems, ne Couse Administration Gude 57 Discovery 8: Configure Default Gateway| This topic details the lb activity for Discovery 8: Configure Default Gateway Objective: Describe how end systems use suimet marks and default gateways This discovery lab will help you explore how ARP maps IP addresses to MAC addresses and how dafault gateways allow access to hosts on remote subnets. The lab is prepared with the devices that are represented, inthe topology Glagram with the IP adresses as depicted inthe table. Note that PCI, PC2,PC3, SW, and RL Configured. Topology Topology = (© 2017 Coo Syste, re yeces: Acclerated (OOH Intarconnecing Cisco Neto Discovery 9: Explore Packet Forwarding] This topic details the lab activity for Discovery 9: Explore Packet Forwarding, (Objective: This discovery will show how packet forwarding happens through devices by observing through show commands and debugs. This discovery lab will guide you through the exploration of packet forwarding. The lab is prepared with the devices as represented inthe topology diagram. The devices are fully configured, including static routing on the routers. MAC addresses in your output may be different from what is shown in Show Me. Tanalacu Topology Topology 20 Sytem, ne. Course Adrnistraton Guise Discovery 10: Configure and Verify Static Routes| ‘This topic details the lab activity for Discovery 10: Configure and Verify Static Routes. Objective: Configure and verify static routes Inthis discovery lab, you will explore IP routing, focusing on static routing. You will configure and verify static routes and observe the packet forwarding behavior that is associated with various routing configurations, including the use ofa statically defined default route ‘The lab is prepared with the devices as represented inthe topology diagram and connectivity table. All devices have their basic configurations in place, including hostnames and IP adévesses. Default gateways are defined on PC1, PC), and SRV, but no other routing has been configured Topology Topology (Conan ©2017 Ci Discovery 11: Configure and Verify ACLs| This topic details the lab activity for Discovery 11: Configure and Verify ACLs. Objective: Configure named and standard ACLs Inthis discovery lab, you will explore the basics of ACLs. ACLs are also commonly referred to simply as access lists. The lab is prepared with the devices that ae represented inthe topology diagram and the connectivity table. All devices have their basic configurations in plac, including hortmames and IP adresses. Note that nether routing nor NAT has yet been implemented, so there is no connectivity between the private IP address space and the public IP address epace This discovery lab is broken into twvo main sections. The frst section makes use of an access list that has already been prepared on RI to demonstrate the importance of statement order in an access list and to demonstrate the effectiveness of using wildcard masks to specify ranges of IP adézesses. Inthe second section of the diseovery, you Will create a new access list yourself. In both sections, you will demonstrate SELUUU UE WHE MLDLULGLY, YOM WL USAIE @EMY LESS Li YUULSGLL A ULL SLL YuAE Mi UMA the function of the ACLs by applying them to the vty line of the R.1 router, using the access-class command. When applied in this fashion, the ACL controls which IP addresses are allowed to initiate connections to the EXEC of the router. You will use other devices as the source of Telnet comnection attempts to the EXEC of RI. Topology Topology (©2017 Cisco Systems, ne Course Administration Gace 1 Discovery 12: Configure a Provider-Assigned IP Address| This topic details the lab activity for Discovery 12: Configure a Provider- Assi Objective: Configure static provider-assigmed IP address ‘This discovery lab will guide you through the aspects of comnecting a small network to the IntemetYou vill implement the simplest of Intemet connections where router Fi will receive its [P address via DHCP. Topology Topology eooo ce See ay eo a (isco Networking Davies: Discovery 13: Configure Static NAT| This topic details the lab activity for Discovery 13: Configure Static NAT. Objective: Configure static NAT and explain its operation This discovery lab will quide you through the aspects of connecting a small network tothe Internet. NAT is a very important concept for Intemet connectivity. The private IP addresses that are used on most internal networks are nt routable on the public Intemet. Because they are not routable, the private IP addresses rust be translated to assigned public IP aderesses at the border tothe Internet. ‘The lab is prepared with the devices that are represented in the topology diagram, All the devices have their basic configurations in place, including hostnames and IP addrestes, Router RI receives the default route from R2 vie DHCP, but NAT has not been implemented. Implementing NAT will be your job during this discovery lab. You vill implementa static NAT translation for SRV. Static NAT, which can maintain persistent IP addxesses for servers, facilitates inbound comnectvity Topology Topology Poca Ads { Pi Adtoee (©2017 Cisco Systems, ne Course Adrinistaton Gace 63 Discovery 14: Configure Dynamic NAT and PAT| This topic details the lab activity for Discovery 14: Configure Dynamic NAT and PAT. Objective: Understand how dynamic NAT works and how to configure it Inthis discovery lb, you will implement a dynamic NAT pool tht ather systems on the intemal network can share for outbourd connectivity. Topology Topology Intesconnectng Cisco Netw jevoas:Accaloratad (CCNA (© 2017 Cisco Systems ne Discovery 15: Troubleshoot NAT| This topic details the lab activity for Discovery 15: Troubleshoot NAT. Objective: Troubleshoot NAT-telated issues In this discovery lab, you will use different show commands to troubleshoot common NAT-related issues. Topology Topology —_ ©2017 Gace Systems, ne ion ade Challenge 1: Summary Challenge Lab 1 This topic details the lab activity for Challenge 1: Summary Challenge Lab 1 Objective: Summary Challenge lab on topics from Mod 1 and Mod 2 A supermarket in your neighborhood has decided to expand into franchises. The company also decided to (open an operations headquarters in a small office that is set up ina nearby building. One of its new employees, Mark, has working Inowledge about computers, so he is working as the temporary network administrator of the market. He has set up the basic structure of the network, which includes a couple of servers and a switch. Mari-has knowledge about DSL environments only, and he has not configured a router previously. Therefore, the company has asked you to help. ‘The customer has purchased a router that is still in the box. Youneed to set up the basic conflguration om the router before seting it asa gateway tothe Intemet. The router must receive a DHCP-assigmed IP address from the ISP router. The ISP has also provided a publie IP address for additional use. ‘The customer requires that you must make one of the servers available through the Intemet to POS systems inthe company fanchises using the public IP address, ‘There is also a list of public IP addresses that will be used by those POS systems to which you will be limiting access, In addition, the remaining server and PC must have access to the Internet using the IP address of the interface on the router that faces the Infemet Topology Topology 182 168-1001 wwaieeioos yea tan taoe Cisce Networking Davies Challenge 2: Summary Challenge Lab 2 This topic details the lab activity for Challenge 2: Summary Challenge Lab 2. Objective: Summary Challenge lab on topics from Mod 1 and Mod 2. An application startup company has just received funding and has started setting up its new office. The| network manager, who is out of town, asked a network engineer trainee to rack mount, cable, and configure the routers and switches that are purchased to set up the network. The manager believes that this task is a great leaming opportunity forthe trainee, and it will save time as well ‘The network requirements are as follows: ‘There are four routers: R1, R2, B3, and R4. Interface E0/1 on Ri will be used to comnect a WAN link: ‘that the ISP will provide in a few days, ‘The network must use the static routing atthe initial stage until some of the management decisions are made, After the manazement decisions are made, the dynamic routing protocol must be implemented on ‘the network, The network is expected to perform the following + Rl is connected to the Intemet. The ISP will essign a dynamic IP address to R1, and the PAT is enabled mI + You can click on the internet cloud within the Topology to gain access to Intemet router. Basta the dhatwill hy si fions B2 and D2 ancl that is destined to ssbate 179 16 S004 and + Route the traffic that will be sourced ftom R2 and R3 and that is destined to subuets 172.16.5.0/24 and 172.16.6.024 to RA, and forward all other traffic to the Internet cloud, + Apply filtering on RI to prevent traffie from eubnet 10.0.0.0/8 that might enter the network through Rd + Translate the IP addresses of R2 and R3 when traffic is forwarded to the Intemet. 82017 Gisco Systems, ne Course Adrnistration Guce ‘The trainee has tried to implement the configuration to fulfill these requirements but has committed a few mistakes. Therefore, you must identify the issues and misconfiguration and help the trainee in troubleshooting the Intemet connectivity Topology Topology oe Intrconnecing Cisco Networking Devias: Acrserated (CCNA) (© 2017 Cisco Systane, ne covery 16: Configure VLAN and Trunk This topic details the lab activity for Discovery 16: Configure VLAN and Trunk. Objective: Configure, verify, and troubleshoot VLANs and trunks This discovery lab will guide you through several expects of VLAN operations, including the management of VLANs, and using trunks to camry multiple VLANs across 2 sinzle physical link. The devices are configured as pictured in the topology diagram. Currently. all devices have IP addresses in the 10.10.1.0:24 subnet. Only the default VLAN, VLAN 1, exists initially. You will start by migrating this configuration to one that uses two VLANs| Topology Topology (©2017 Cisco Systems, ne Course Adrinistraton Guce 69 Discovery 17: Troubleshoot VLAN and Trunk Issues This topic details the lab activity for Discovery 17: Troubleshoot VLAN and Trunk Issues. Objective: Describe steps to troubleshoot VLAN and trunking throug lab This discovery will guide you through a scenario involving VLAN configuration, Layer 2 comnectvity, and IP connectivity. The topology diagram is intentionally vague and there is no connectivity table. Imagine you are on your first day at a new job as a network engineer. You are not yet familiar with the nehwork of your organization. A member ofthe security team comes to you because te intrusion prevention system has flagged malicious trafic ftom the IP address 10.10.10.182. You are asked to help in isolating this system and removing it fom the network. This discovery will also guide you through the IP connectivity issue between two hosts| Topology Topology Po2 x Inderconnectng Cisco Netwerkng Davies: Acseraed (CONAN) © 2047 Cisco Systems, ne Discovery 18: Configure Root Bridge and Analyze STP. Topology This topic details the lab activity for Discovery 18: Configure Root Bridge and Analyze STP Topology Objective: Describe how to use Cisco IOS commands to analyze the spanning-tree topology and verify the proper operation of STP. ‘The purpose of this discovery is to demonstrate how to determine the map of a spanning tree across @ topology. The live virtual lb is prepared with the devices that are represented in the topology diagram and the comectivity table. All devices have their basic configurations in place, including hostnames and IP addresses. During the discovery, you will map out the spanning tree for VLAN 20. SRV2is the Server on VLAN 20 and it is connected fo $4. You will observe that the spanning tree does not currently provide optimized paths from the cliets to SRV2. You will then modify the spanning tree and verify the results| Topology Topology ©2017 Cisco Systems, ne parison Gute 77 Discovery 19: Troubleshoot STP Issues ‘This topic details the lb activity for Discovery 19: Troubleshoot STP Issues, Objective: Describe the consequences of STP failure and how to troubleshoot STP loops ‘The biggest problem with STP isnot the fat that it can ful, because any protocol can. Infact, STP is one of the most reliable protocols available. However, opposed to many other protocols, the main concer is that ‘when 2 problem that is related to STP exists, there are generally major negative consequences. For instance, if the routing protocol is malfmctioning on one of your routers; you might lose connectivity to networks that are reachable throuch thet particular route. However, this loss generally does not affect the rest of your network. If you have some way' to conmect to that outer, you can still perform your troubleshooting routines to diagnose and fix the problem. Inthis discovery, you will demonstrate how to use different commands to troubleshoot STP. Topology| Topology C2 ‘SRV2 Inteconnactng isco Networking Davies: Accslerated (CCNA) (© 2017 Cisco Systems ne covery 20: Configure and Verify EtherChannel This topic details the lab activity for Discovery 20: Configure and Verify EtherChamnel. Objective: Configure and verify EtherChannel configuration ‘The purpose of this discovery is to provide you with some experience working with EtherChannel. The live virtual lb is prepared with the switches represented in the topology diagram and the connectivity table. All devices have their basic configurations in place, including hostnames and IP addresses. Note that all the links between the switches use pairs of connections. You will see that this fact does not lead to doubling the bandwidth by default. You wall configure EtherChamel on some of the links and verify the results Topology Topology fa? __n07_ peer, oA 3 pa Z2 ecco Pca. SRVZ (©2017 Cisco Systems, ne (Course Aeinisration Gude 73 Discovery 21: Configure a Router on a Stick This topic details the lab activity for Discovery 21: Configure @ Router on a Stick. Objective: Configure router ona stick: This discovery lab will guide you through routing between VLANs. The devices are configured as pictured inthe topology diagram. Currently, devices have IP addresses in the 10.10.1.0/24 or 10.10:2.0:24 subnets ‘You will start by migrating this configuration to one that uses two VLANs and twvo physical interfaces on Ri to zoute between thems. You will then continue the migration to implement three VLANs andthe use of ‘trunking on RI to allow one physical interface to have a logical presence on multiple VLANs. Inthe end, ‘the switches will maintain their IP presence on VLAN 1, PC2 and PC4 on VLAN 2, and PC! and PC3 will move to VLAN 3. RI will be the defauit gateway forall of the hosts, and it will route between the VLANs. Topology Topology 4 Interconnectng Cisco Networking Davies: Acoeerated (CCNA) (© 2017 Cisco Systems ne Discovery 22: Configure a Cisco Router as a DHCP Server This topic details the lab activity for Discovery 22: Configure a Cisco Router as a DHCP Server. Objective: Configure and verify Cisco routers as DHCP servers This discovery lab will guide you through DHCP services using Cisco 10S devices. Review the topology diagram. RI is configured to route between VLANs I, 2, and 3. SRVI and PC2 are on VLAN 2, while PC1 and PC3 are on VLAN 3. SRV! is configured with a static IP address. PC1, PC2, and PC3 initially have no IP configuration. During tis discovery lab, you will configure SRV1 as a DHCP server for its local VLAN, VLAN 2. You will then configure PC? as a DHCP client and observe the DHCP process. Next, you will configure a second DHCP pool on SRVI. The poo! will be appliceble to VLAN 3. You will configure a DHCP zelay on R1 so that it will forward DHCP requests from VLAN 3 to SRV. You will then configure PCI and PC3 as DHCP clients and observe the DHCP process with RI as a DHCP relay. Topology Topology (©2017 Cisco Systems, ne (Course Adriistation Gude 78 Discovery 23: Troubleshoot DHCP Issues This topic details the lab activity for Discovery 23: Troubleshoot DHCP Issues. Objective: Troubleshoot DHCP and DNS issues This discovery lab will guide you through DHCP services troubleshooting using Cisco 10S tools. RI is configured to route between VLANs 1, 3, and 3. SRVI and PC2 are on VLAN 3, while PC1 and PC3 are on VLAN 3. SRV1 is configured with a static IP address. PC1, PC2, and PC3 are configured as DHCP clients. SRV1 is configured as 2 DHCP server with two pools, one for its local subnet (VLAN 2) and one for a remote suimet (VLAN 3). RI is configured as a DHCP relay agent to forward DHCP request broadcasts on, VLAN 3 to SRV ‘There are a couple of mistakes inthe initial configuration, and itis up to you to troubleshoot them. Topology Topology 78 Cisce Networking Davies Discovery 24: Configure and Verify HSRP This topic details the lab activity for Discovery 24: Configure and Verify HSRP. Objective: Configure and verify HSRP In this guided discovery, you will work with HSRP. Hosts on IP networks usually only have a single IP address that is configured as their default gateway. HSRP allows two physical routers to work together in an HISRP group to provide a virtual IP address and an associated virtual MAC adress. ‘The end hosts use the virtual IP address as their defanlt gateway and leam the virtual MAC address via ARP. One of the routers in the group is active and responsible for the virtual addresses. The other router is ina standby state and monitors the active router. Tf there is a failure on the active router, the standby router assumes the active state. The virtual addresses, are alays fictional, regardless of which physical router is responsible for them. The end hosts are not aware of any changes in the physical routers. Consult the topology diagram. The live virtual lab is prepared with the devices that are represented in the topology diagram and the connectivity table. All devices have their basic configurations in place, including hostnames and IP addresses. RIP is configured on the three routers, making both R1 and R aware of the 10.10.99.0 subnet that is connected to R3. ‘The two PCs are configured with 10.10.1.1 as their default gateway. Note that this address does not yet exist inthe topology. R1 uses 10.10.1.2 and R2 uses 10.10.1.3. Inthis discovery, you will configure and verify HSRP on RI and R2, using 10.10.1.1 as the virtual IP address. ‘You will stat by verifying the inital state on PC! and R1. You will then configure and verify HSRP on RI. It only takes one functional router in an HSRP group to provide forwarding services forthe end hosts onthe network. You will then configure and verify HSRP on R2. Finally, you will cause a fault in Rl and then verify that R2 takes over the FISRP active role| Topology Topology 82017 Gisco Systems, ne Cowse Administration Gude 77 Discovery 25: Troubleshoot HSRP This topic details the lab activity for Discovery 25: Troubleshoot HSRP. Objective: Troubleshoot HSRP- In this guided discovery, you will work with typical HSRP configuration issues. You will see a duplicated IP address issue on both RI and R2 routers. The reason for this issue is HISRP misconfiguration ‘The desired HSRP configuration uses 10.10.1.1 as the virtual IP address in the HSRP group 1, and RU isthe active HSRP router. This is not the case, so you will perform troubleshooting steps to isolate the configuration issues Topology Topology (© 2017 Cisco Systane, ne IntsconnectingGisoo Networking Davies: Accslerated (OCI Discovery 26: Configure and Verify RIPv2 This topic details the lab activity for Discovery 26: Configure and Verify RIPV2 Objective: Configure and verify RIPV2 Inthis discovery lab, you will configure and verify RIPv2 for IPv4. You will adjust RIP timers, disable szutomatic summarization, configure a passive interface, and generate a dafault route into RIP. ‘The lab is prepared with the devices as represented in the topology diagram and connectivity table. All devices have their basic configurations in place including the hostnames and IP addresses. Default gateways are defined on PCI, PC2, and SRV, but mo other routing has been configured, Topology Topology (©2017 Cisco Systems, ne Course Adrinistaton Gus 70 Discovery 27: Troubleshoot RIPv2 This topic detail the lab activity for Discovery 27: Troubleshoot RIP\2. Objective: Troubleshoot RIPV2 Inthis discovery lab, you will troubleshoot RIP. The lab is prepared with the devices as represented in the ‘and comectivity table. All devices have their basic configurations in place including ‘TP addresses. Default gateways are defined on PCL, PC2, and SRV1. The RIP routing protocol is configured between RI, R2, and R3 routers. Inthe RIP that is configured on the R1, R2, and R3 routers, there are some issues. Topology Topology (ConA ©2017 Ci Challenge implementing RIPv2 This topic details the lab activity for Challenge 3: implementing RIP Objective: Configure and troubleshoot RIPV2 The customer wants to implementa dynamic routing protocol on the network. Until now, static routing was being used, but the static routing needs to be removed to make way for RIP. The customer wants to enable RIPv? and disable zutomatic summarization. Also, itis nota best practice fo all of the routers in the network to point to the ISP router, so itis decided thatthe branch router will retain its default route tothe ISP, and it will advertise a default route tothe network. The customer has one more caveat: There are plans to expand the network by adding routers and comecting them to switch SW2. Until the network-has been stabilize, itis advised that the new routers must not receive the advertisements from the rest ofthe network so that the network expansion does nat send additional trafic to th live network: Topology Topology SONS, vasenien meets ©2017 Cisco Systems, ne ©2017 Cisco Systems, ne Acrinisration Gute 81 Discovery 28: Configure Basic IPv6 Connectivity ‘This topic details the Ieb activity for Discovery 28: Configure Basic IPvs Comnectivity Objective: Configure basic IPvS commands In this discovery lab, you will explore the configuration of v6 in a small network that contains three routers and three end hosts. Consult the topology diagram and address table to understand the network connectivity and addressing. All systems currently are configured with [Pv addresses and RIP routing During migration, [Pv and IPvé are commonly implemented in parallel with dual stacks on IPy6-capable systems, You will leave the [Pw configuration in place during this exercise. Initially, v6 is also fully configured on R2 and PC. This discovery lab will guide you through configuring IPv6 on the rest of the network. First, you will configure static IPv6 addresses on Rl and R3. Note that, for simplicity, all static TPv6 addresses in the topology differ in only 2 bytes. They all start with 2001-0DB8:0000-00. The eighth byte completes the 64-bit prefix and represents the network (OI, 02, 03, 04, 05, or 06) within the topology. The next 7 bytes ae all OD. The final byte specifies the host on the network: in this example, the byte i either 01 or 02. After configuring the TPv6 addresses on RI and R3, you will configure PCI and SRV for TPv6 stateless autoconfiguration. You wll then verify connectivity between PC! and Ru and between SRV and RS. Topology Topology Discovery 29: Configure IPv6 Static Routes This topic details the lab activity for Discovery 29: Configure IPv6 Static Routes. Objective: Configure and verify IPv6 static routes Inthis discovery lab, you will configure IPv6 static routing between R1 and R3 and verify comectivity between PC! and SRW/1. Consult the topology diagram and address table to understand the network connectivity and addressing. All systems are currently configured with [Pv addresses, IPV6 addresses, and RIP routing. You will leave the IPv4 configuration in place during this exercise. Also, you will configure a default static route on PCI Topology Topology Challenge 4: Implement IPvé6 Static Routing This topic details the lab activity for Challenge 4: Implement IPv6 Static Routing| Objective: Troubleshoot IPv6 routing ‘You are piloting the IPv6 implementation along with IPv4. The ISP has provided you with the following IPv6 addresses for testing purposes during the pilot phase to make sure that these addresses are reachable from your network. Here are the [Pv global addresses that are configured on the Intemet router for testing pumposes: + 200:DB80-1A-1164 + 2001:DB8:0:1B-1/64 + 2001:DB8:0:1C--1/64 ©2017 Cisco Systems, ne ‘Youmust implement IPv6 static routing to ensure thatthe these IPv6 addresses are reachable from devices R1,R2,R3, RA, and PCL. — Itis recommended that you use the stateless autoconfiguration method to implement IPv6 addressing and to receive a default route on RA. Youmust configure 2 default route using the [Pv6 global address on Ri to establish connectivity with the Intermet router. Do not use the autoconfiguration methed on Ri ~ You must configure 2 default route using a link-local address on R3 to establish connectivity with the Intemet router. Do not use the autoconfiguration method on R3. ~ IPv6 configurations are already configured on the other devices. However, you need to investigate any incomplete configurations or misconfigurations. Also, ensure thatthe connectivity from all devices ‘exists to the IPv6 addresses that are provided by the ISP. Topology Topology ror Re Ro 4 Iterconnectng Cisco Networking Devices: Acca 1d (CONAN (© 2017 Cisco Systems ne Discovery 30: Use Troubleshooting Tools This topic details the lab activity for Discovery 30: Use Troubleshooting Tools. (Objective: Describe how troubleshooting tools can be used to verify connectivity issue In this discovery, you will leam how to use some basic commands for verifying enc-to-end connectivity in am IP network. The live virtual lab is prepared with the devices that ae represented inthe topology diagram and the connectivity table, All devices have their basic configurations in place, including hostnames and IP addresses, RIP is co on the routers. There are no iseues to troubleshoot with the network. The goal of this discovery isto become familiar with some basic troubleshooting tools, and not to complete troubleshooting tasks Topology Topology swt Ri Ra Pct SRVI Course Adrian Gu ©2017 Cisco Systems, ne Discovery 31: Configure and Verify IPv4 Extended Access sts This topic details the lab activity for Discovery 31: Configure and Verify IPs Extended Access Lists Objective: Configure and verify IP extended access lists ‘A common mechanism that is used for traffic filtering is ACL. ACLs enable you to control access based om Layer 3 packet-header information. Standard ACLs cannot fulfil ll traffic-fitering requirements; they provide only limited options for network traffic filtering A standard ACL can specify only source IP adresses and source networks, so its not possible to filter toa specific destination. For more precise traffic filtering, you should use extended ACLs. Configure and Verify IPv4 Extended Access Lists ‘an Examgl rom a TCPAP Packet Extended ACLs provide a greater range of control. In addition to verifying packet source adresses, extended ACLs also check destination addresses, protocols, and port numbers, as shown in the figure. They: provide more criteria on which to base the ACL. For example, an extended ACL can simultaneously allow email traffic from a network to a specific destination and deny file transfers and web browsing for a specific host. ‘The ability to filter om a protocol and port number allows you to build very specific extended ACLs. Using ‘the appropriate port number, you can Specify an application by configuring either the port mumber or the | name of a well-known por. ‘Youhave two types of extended ACLs + Named: More common. + Numbered: Ranges from 100 to 199, and from 2000 to 2699 (providing a total of $00 possible extended ACLS) 28 ‘interconnecting Cisco Networ (© 2017 Cisco Systems ne This discovery will guide you through the extended [Pv ACL configuration. The virtual lab enviroment is prepared with the devices that are represented in the topology diagram and the comnectivity table, All devices have their basic configurations in place including hostnames and IP adresses. The configuration of both ACL will be on R and if will be applied inbound on the interface Ethernet00 to influence the traffic from PCI Note The policy that is defined in the ACL was chosen to demonstrate how ACLs work. The policy does not reflect any real world application Topology Topology e201 co Syste ne. Course Adrnistration Gace Discovery 32: Troubleshoot IPv4 Network Connectivity ‘This topic details the lab activity for Discovery 32: Troubleshoot IPv4 Network Counectvity Objective: Troubleshoot Pv network connectivity issues This discovery will guide you through troubleshooting comnectivity in an [Pv network. The virtual lab is prepared with the devices that are represented in the topology diagram and the connectivity table. All devices have their basic configurations in place, including hostnames and IP addresses, PIP has been. configured as the dynamic routing protocol Four issues have been introduced on different devices inthe live virtual lab environment. Your job isto find and fix these issues. There are only four steps inthis discovery. The step describes the complaint that you rust address. To get a feeling for troubleshooting activities, ty to uncover and resolve the problems before youuse the Answer Key for each step. Resolve each issue before moving to the next one. Sometimes, you will need to resalve the issue to be able to move tothe following issue Topology Topology 28 —_‘lnteroonneding Cisco Networ (© 2017 Cisco Systems ne Challenge 5: Troubleshoot IPv4 Connectivity This topic details the lab activity for Challenge 5: Troubleshoot IPv4 Connectivity Objective: Perform IPvd connectivity troubleshooting based on the challenge introduction. ‘The ABC network has just completed its network implementation and has rum into few issues. You have been contracted to work with ABC to resolve all network issues. They are running RIP%? as the routing protocol. R3 isthe edge router and it should be injecting a default route in RIP. The PCs are in WLAN 10 on switch SWI. The File Server is in VLAN 20 on switch SW2. The router R3 is comected to the ISP gateway. The DNS server isin the ISP cloud. Router R2 is the DHCP server for the PCs in the network. ‘You are allowed to make changes in the access lst if required but not delete any line from the access ist or remove the access lists Following are the network issues that you need to resolve. + PCI cannot get to Intemet. Use IP address, 209.165.202.225 to test Intemet connectivity + PC2 cannot ping the test host iond2.com. + PC3 cannot ping the File Server. + There is intermittent comnectivity tothe Internet at certain times ofthe day. Itis suspected that it could ‘be an issue at the ISP end, You have been asked to set up an IP SLA with mumber | and frequency 15 to perform an ICMP echo test to the ISP default gateway on router, R3. The IP SLA schedule should start ‘mmmediately and nun indafinitely Topology Topology ONS Server 200-185201.1 Fie Server re WLAN 20+ 101.202 Vian 10 104110024 92017 Gam Stora ne Po Discovery 33: Configure and Verify IPv6 Extended Access Liste Discovery 33: Configure and Verify IPv6 Extended Access Lists This topic details the lab activity for Discovery 33: Configure and Verify IPv6 Extended Access Lists Objective: Configure and verify IPv6 extended access lists ‘This discovery will guide you through the extended IPv6 ACLs configuration, The virtual Lab environment is prepared with the devices that are represented in the topology diagram and the connectivity table. All devices have their basic configurations in place including hostames and IPv6 addresses. The configuration of ACL will be on RI and it will be applied inbound on the interface Ethemet00, to influence traffic fom PC2. Note “The policy that fs defined in the ACL was chosen to demonstrate how ACLS work. The policy does not reflect any real world application, Topology Topology (isco Networking Davies: Discovery 34: Troubleshoot IPv6 Network Connectivity This topic details the lab activity for Discovery 34: Troubleshoot IPv6 Network Comnectivity Objective: Troubleshoot IPv6 network connectivity issues This discovery will give you a chance to do some troubleshooting in an IPv6 environment. The live virtual labis prepared with the devices that are represented inthe topology diagram and the comectivity table. All devices have their basic configurations in place, including hostnames and IP adaesses. Pf and IPv6 coexist in thie networkin a dual stack environment. RIP is configured on the routers to provide Pd routing. For IPV6, static routes are configured. Four issues have been introduced on diferent devices. Your job is to find and fix these iseues. There are only four steps in this discovery. A step describes the complaint that you must address. To geta feeling for troubleshooting activities, ry to uncover and resolve the problems before you use the Answer Key for each step. Resolve each issue before moving to the next one. Sometimes, you may have to resolve a previous issue so that the following issues are demonstrated Topology Topology ©2017 Cisco Systems, ne Course Adrian Gu Challenge 6: Troubleshoot IPv6 Connectivity ‘This topic details the lab activity for Challenge 6: Troubleshoot IPv6 Comectivity Objective: Perform IPv6 cormectivity troubleshooting based on challenge introduction. Senior Engineer Chris wants to test your skills in IPv6 troubleshooting. He has set up lab and injected some erors. You are required to resolve the issues in the lab. There are IPv6 static routes in the network. Following ar the iseues that you need to resolve + PCI is unable to use Telnet to the server. The Telnet password for Server is eiscol23, + PC2 cannot ping PCL. Topology Topology Intaconnacting isco Networking Davies: Acca 1d (CONAN (© 2017 Cisco Systems ne Discovery 35: Enhance Security of Initial Configuration This topic details the lab activity for Discovery 35: Enhance Security of Initial Configuration, Objective: Leam basic configuration to secure intial config This discovery lab will guide you through the various aspects of securing administrative access to Cisco TOS devices. You will secure access to the privileged EXEC andl see the difference between enable password and enable secret. You will also secure access to the console port. You will enable remote access to the vty lines via Telnet and SSH. You will set SSH as the only acceptable remote access protocol ‘The devices are configured as represented in the topology diagram, including their IP addresses. This discovery lab will focus on R1. You will use other devices as sources of remote access comections. Topology Topology cron “ia SW Ethort ann Rt thot ©2017 Cisco Systems, ne cristo Guide Discovery 36: it Remote Access Connectivity ‘This topic details the Ib activity for Discovery 36: Limit Remote Access Comnectivity. Objective: Learn how to enable and secure remote access comnectivity ‘This discovery lab will guide you through the remote access limitation by using an ACL. You will ‘implement login and exee banners. ‘The devices are configured as represented in the topology diagram, including IP addresses. This discovery Jab will focus on R1. Other devices will be used as sources of remote access comnections. Topology Topology ~~ Etho/0 Ethort Ethor2 Challenge 7: Securing Device Administrative Access This topic details the lab activity for Challenge 7: Securing Device Administrative Access Objective: Describe how to secure access to devices Basic network security policy was configured on the devices by your colleague, but you can still see thatthe configurations are incomplete per the standard basic security policy that was adopted by CCS ir the customer environment. Identify and fix the issues with the configurations ‘The security policy that is adopted by CCS for router R1, the branch router, and switch SW! follows ~ Access to the privilege mode must be secured using a password on all devices. ~ Passwords must be encrypted on all devices = Access to the console and uty lines must be secured on all devices, ~ Remote access must be secured by enabling SSH on vty Oto 4. ~ A standard IP ACL must be use to restrict remote access ~ A login banner must be present on all devices. (isco Networking Davies: Refer to the Job Aid section for login credential Information, Refer to the Job Ald section for login credential Information. Topology Topology imisssos24 rasan sae waysipene anc (©2017 Cisco Systems, ne (Course Aerinisration Gude Discovery 37: Configure and Verify Port Security ‘This topic details the eb activity for Discovery 37: Configure and Verify Port Security. Objective: Learn to configure port security Port security restricts a switch port to a specific set of MAC addresses. You should configure it on all ports that comaect to end devices. Inthis discovery lab, you will configure and verify port security. You will also set enor-disabled port automatic recovery Topology Topology EthOrT eEtnor2 8 (© 2017 Cisco Systems ne Discovery 38: Configure and Verify NTP This topic details the lab activity for Discovery 38: Configure and Verify NTP. Objective: Configure and verify NIP in client server mode ‘Network devices generate syslog messages to convey important information about events within the network. Syslog messages have time stamps thet are associated with them. For these time stamps to be of value for security analysis, the clocks on all ofthe network devices must bein sync. NTP is the preferred method to achieve synchronization This discovery lab will guide you through configuring and verifying NTP services on Cisco IOS routers ‘The lab is prepared as depicted in the topology diagram and the connectivity table. Topology Topology Challenge 8: Implementing Device Hardening This topic details the lab activity for Challenge &: Implementing Device Hardening. Objective: Leam to configure NTP and port security Ona previous tip, you successfully added basic security to the metwork ofthe law firm, and Li has asked You come bac and ad adstonl sear. Bob tls you tht you wil edo perform the follwing] The tasks follow: — Enable the border router as an NTP client of the Internet router. = Configure switch SW1 as follows: ©2017 Cisco Systems, ne cristo Guide ~ Bhable sovite SW1 as an NTP client of the border router. = Secure all unused ports ~ Enable switch SW1 23 an NTP client ofthe border router. = Secure all unused ports = Configure dynamic (sticky) port security = Disable Cisco Discovery Protocol on the port that is connected to the inventory server. ‘oie Adevice may take from 60 f0 240 seconds to gets clock synchronized withthe NTP sewer or with ts peers Topology Topology - 102 968 100.254 aim = vmniebicos —teatebtane Ge nduconading Gis Newring Daves: Aaland (GONG (2047 Gi Sr Discovery 39: Configure External Authentication Using RADIUS and TACACS+ This topic details the lab activity for Discovery 39: Configure External Authentication Using RADIUS and TACACS+, Objective: Configure and verify device management by using AAA with TACACS~ and RADIUS, This discovery will guide you through the configuration of external authentication by using RADIUS and TACACS+. The live virtual lab is prepared with the router, PC, and server that are represented in the topology diagram and the connectivity table. The devices have their basic configurations in place, including hostnames and IP addresses. Inthe discovery, you will configure a console and vty access on the router by using RADIUS and TACACS+ servers. Topology Topology Rt cristo Guide ©2017 Cisco Systems, ne Discovery 40: Configure and Verify EIGRP This topic details the lab activity for Discovery 40: Configure and Verify EIGRP. Objective: Configure and verify EIGRP This discovery will guide you through the configuration and verification of EIGRP om a Cisco 10S router. ‘The virtual lab is prepared with the devices represented in the topology diagram and the comnectivity table. All devices have their basic configurations in place, including hostnames and IP addresses. R2 and R3 are also configured with EIGRP using AS number 1. In this discovery, you will configure EIGRP on RI and verify the results, Topology Topology 22017 Gi Discovery 41: Configure and Verify EIGRP for IPv6 | This topic details the lab activity for Discovery 41: Configure and Verify EIGRP for IPv6 Objective: Configure and verify EIGRP for IPvé This discovery will guide you through the configuration and verification of EIGRP for IPv6 on an IOS router. The virtual lab is prepared with the devices that are represented in the topology diagram and the connectivity table. All devices have their basic configurations in place, including hostnames and IP addresses. Both [Pvt and IPv6 are configured in this dual-stack environment. R2 and R3 are also configured twith EIGRP for IPv6 using the autonomous system mumber 100. In this discovery, you will configure EIGRP for IPv6 on Ri and verify the results. Topology Topology e207 Discovery 42: Troubleshoot EIGRP: Issues| ‘This topic details the Inb activity for Discovery 42: Troubleshoot EIGRP Issues, Objective: Troubleshoot common EIGRP issues through lab, Objective: Troubleshoot common EIGRP issues through lab ‘This discovery will guide you through the troubleshooting of various EIGRP coufiguration issues. The Virtual lb is prepared with the devices that are represented in the topology diagram and the “Device Information” table. All devices have their basic configurations in place, including hostnames and IP addresses. EIGRP AS 10 has been configured on all seven routers, but there are problems with the router configurations. Each router has a loopback interface with the IP address 192.168.R 1/24 (where is the router number). The routing table on Ri is missing routes tothe loopback interface networks for each of its peers, In this discovery, you will troubleshoot and fix the problems that are associated withthe routing of cach ofthese networks. ‘You will start with the R2 loopback network and proceed one ata time, finishing with R7, which is also configured for EIGRP IPv6 routing. In each case, you will first determine the root cause. You will then fix the issue and verify that the route is properly defined in the routing table of Rl. Topology Topology (isco Networking Devious: Challenge 9: Troubleshoot EIGRP| This topic details the lab activity for Challenge 9: Troubleshoot EIGRP. Objective: Troubleshoot common EIGRP related issues. Rahul, who is anetwork engineer at CCS, has recently completed an EIGRP implementation for a new sor Natok Scat a Vou need in isolate and Network connectivity v all issues before leaving the site. Here are the issues thet you need to resolve + Apping from GR. to the loopback interface on BIR2 (192.168.1.2) fail. + Aping from CR1 to the loopback interface on B2RL (192.168.1.4) fail. + There is mo IPv6 comnectivity between BIR3 and CRI. You should be able to ping 2001:0DB8:A:C1::1/64 from B1R3, +The end users have no IPv6 connectivity between B2R1 and BIR2. You should be able to ping: 200/DBS:A:Bi=1 fom BURL Topology Topology Copoate once 82017 Gisco Systems, ne ‘Course Adiistatin Gude 108 Challenge 10: Summary Challenge Lab 3| This topic details the lab activity for Challenge 10: Summary Challenge Lab 3. Objective: Based on Mod 3 and Mod 4 topics a summary challenge lab tobe created. CCS has been contracted by’ trading company’. As per the contract, the engineer has configured the network, but the customer has reported issues that are related to the connectivity. You must identify and fix the issues ‘The network implementation details that are provided by the customer are as follows: + The PCs and servers are configured in their respective VLANs, and the default gateway for the VLANs is configured on router R2 using the router-on-2-stick method. + Ril connects to the Internet, and the PAT is enabled on RL + RIPr2is enabled between Ri, R2, and B3. Topology Topology seat — Jeoo foo =e vu 100 aso 104 _Intercomecng Cisco Networking Devices: Acoslrated (CONAK) Challenge 11: Summary Challenge Lab 4| This topic details the lab activity for Challenge 11: Summary Challenge Lab 4. (Objective: Implement and troubleshoot « medium sized network. ‘¥ou work for DENTIC Networking. Your colleaeue Andy did some maintenance on the network over the ‘weekend. On Monday moming, he is seeing certain issues in the network and needs your help in troubleshooting it He gives you the following information about the network: + Routers R1, R2, R3, and Ré are enabled for EIGRP routing with AS number 1023, +R has been configured to get the IP address dynamically from the ISP. R4 also has NAT configured. “+ Please refer to the topology for the VLAN information. Ris the DHCP server for VLANIO (PC!) and ‘VLAN 20 PCD). ‘The following are the issues you need to resolve: + PCI cannot access the Intemet. To test Intemet connectivity, use IP address 209.165.201.225. + Ré should be load balancing the networks advertised by R1. The routing table for the following networks should look like: Réfshow ip route eigrp ‘output omitted> D__192.168.1.0/24 [90382800] via 172.16.2.5, 00:00:24, Ethemet02 [90/332800] via 172.16.1.5, 00:00:24, Ethemet0/1 D_ 192.168.10.0/24 [90/332800] via 172.16.2.5, 00:00:24, Ethemet0/2 [90/332800] vie 172.16.1.5, 00:00:34, Fthemet0/1 D_ 192.168.20.0/24 [90/332800] via 172.16.2.5, 00:00:24, Ethemet0i2 [90/332800] via 172.16.1.5, 00:00:24, Fthemet0/1 D_ 192.168.30.0/24 [907337920] via 172.16:2.5, 00:00:24, Ethemet0/2 [90/337920} via 172.16.1.5, 00:00:24, Fthemet0/1 + Server SRV cannot reach PC3 (192.168.11.11). + R2 isnot forming IPv6 EIGRP nejghbor with R1. Also, the neighborship with R4 on interface Ethemet0/l on R2 is continuously flapping. 20 Sytem, ne. Course Administration Guise Topology| Topology © 2017 Cisco Systems ne Discovery 43: Configure and Verify Single-Area OSPF This topic details the lab activity for Discovery 43: Configure and Verify Single-Area OSPF. Objective: Configure and verify the OSPF configuration This discovery will guide you through the configuration and verification of OSPF for [Pr om a Cisco 10S router. The virtual lab is prepared with the devices that are represented im the topology diagram and the comnectivty table. All devices have their basic configurations in place, including hostnames and IP addresses. R2 and R3 are also configured with OSPF. You will configure OSPF on RI and verify the results, Topology Topology Ethoro (©2017 Cisco Systems, ne Course Adrinistation Gace 107 Discovery 44: Configure and Verify Multiarea OSPF| This topic details the lab activity for Discovery 44: Configure and Verify Multiares OSPF. Objective: Describe how to configure multiarea OSPF This discovery will guide you through the configuration of an ABR in a multiarea OSPF environment. The virtual lab is prepared with the devices that are represented in the topology diagram and the comnectivity table. All devices have their basic configurations in place, including hostnames and IP adresses. Rl is configured as an internal router in Area O, while R3 is configured as an intemal router in Area 1. Area 0 spans subnets of 10.0.0.0/16, while Area 1 spans subnets of 10.1.0,0/16. Your job in this diseovery isto configure R2 as an ABR between Area 0-and Area 1. After R2 is configured, you will verify the results Topology a Topology 08 Inteconnactng isco Networking Davies: Accslerated (CCNA) (© 2017 Cisco Systems ne covery 45: Configure and Verify OSPFv3| This topic details the lab activity for Discovery 45: Configure and Verify OSPF v3 Objective: Describe how to configure OSPF'3 for IPv6 This discovery will guide you through the configuration and verification of OSPFv3 ona Cisco IOS router. ‘The virtual lab is prepared with the devices that are represented in the topology diagram and the connectivity table. All devices have ther basic configurations in place, including the hostnames and IP addresses. RD and R3 are also configured with OSPFv3. In this discovery, you will configure OSPF13 on Rl and verify the results. Topology Topology ©2017 Cisco Systems, ne tion Gade Discovery 46: Troubleshoot Multiarea OSPF| This topic details the lb activity for Discovery 46: Troubleshoot Multiarea OSPF. Objective: Describe how to troubleshoot multiarea OSPF ‘This discovery will guide you through the troubleshooting of various OSPF configuration istues. The virtual lkb is prepared with the devices that are represented in the topology diagram and the connectivity table. All devices have their basic configurations in place, including their hostnames and IP addresses. OSPF has been cor cn all seven routers, but there are problems with the router configurations. Each router has 2 loopback interface with the TP adress 192.168 R 1/24 (where R indicates the router number). The routing table on RI is missing routes to the loopback interface networks for each of its peers. In this discovery, you ‘will troubleshoot and fix the problem that is associated with the routing of each of these networks. ‘You will start with the R2 loopback network, and then proceed one ata time, finishing with RT, which is also configured for OSPFv3. In each case, you will fist determine the root cause and then you Will fix the {soue and verify thatthe route is properly defined in the routing table of Ri. Topology i Topology Leos 10 _nterconnectng Cisco Neter jevoas:Accaloratad (CCNA (© 2017 Cisco Systems ne Challenge 12: Troubleshoot O SPF This topic details the lab activity for Challenge 12: Troubleshoot OSPE. Objective: Troubleshoot common OSPF-related issues ‘Susan, network engineer at GCE, completed an OSPF implementation for a new customer, All routers ran OSPF, as shown in the topology diagram. The network connectivity verification has encountered some issues. Youneed to isolate and correct all issues before leaving the site Here are the issues thet youneed to resolve + PCI cannot ping PC? (192.168.20.2) + PC2 cannot ping the IP address 192.168.33.1 (R1 E02). There will be a DNS server added to the network subnet 192.168.33.0/24. You need to make sure that PC? can reach this network. + In future, GCE will enable OSPF\3 routing for IPv6. For testing, GCE enabled OSPF(3 for IPv6 on RI ‘and R3. You need to fix the OSPF 3 neighbor issue between RI and R3. Topology [ Topology (©2017 Cisco Systems, ne (Course Adriisvation Gude 111 Discovery 47: Configure Serial Interface and PPP This topic details the ab activity for Discovery 47: Configure Serial Interface and PPP. Objective: Configure serial interfaces with PPP encapsulation and authentication] ‘This discovery will guide you through the configuration of the clock rate on the DCE side of a serial link and the configuration of PPP encapsulation on Goth sides of a serial lik between two Cisco IOS routers. ‘The virtual lab is prepared with two routers as depicted inthe topology diagram and the comectivity table. Ri has the DCE side of the serial link, while R2 has the DTE side. Both routers have their basic configurations in place, including hostnames, IP addresses, and EIGRP asthe routing protocol. First you will configure and verify a serial interface to use PPP encapsulation, and then you will configure PAP and CHAP authentication for PPP. Topology Topology Loo Loo Lot Lot 12 vices: Accelerated (CONA) Inteconnecing Gisoo Netra Discovery 48: Configure and Verify MLP This topic details the lab activity for Discovery 48: Configure and Verify MLP. Objective: Configure and verify MLP This discovery will guide you through the configuration of the Multilink PPP, also inown as MLP. MLP | provides a method for spreading traffic across multiple distinct PPP connections. You can use it, for ‘example, either to connect a home computer to an ISP by using two traditional modems or to comect a company through two leased lines ‘You will configure an MLP bundle on Ri and R2, which are connected by two serial interfaces. Topology Topology sein seis ———— _ 2017 Cisco Systems, ne Course Adrnistraton Gude Discovery 49: Configure and Verify a PPPoE Client This topic details the lb activity for Discovery 49: Configure and Verify a PPPoE Client Objective: Configure and verify PPPoE ‘This discovery will guide you through the configuration of a PPPOE client, PPoE provides an emulated (and optionally authenticated) point-to-point link across a shared medium, typically @ broadband azzregation network such a5 the ones that you can find in DSL service providers. A very common scenario is to rm a| PPPoE client on the customer side, which comects to and obtains its configuration from the PPPOE server (headend router) a the ISP side ‘You will configure RI as a PPPOE client, while R2 is preconfigured as the PPPOE server. Topology Topology <=._—____—~ 500 Netwo — ©2017 Ci Discovery 50: Configure and Verify a GRE Tunnel This topic details the lab activity for Discovery 50: Configure and Verify a GRE Tunnel Objective: Configure and verify « GRE tunnel This discovery will guide you through the configuration, verification, and usage of a GRE tum to connect IP networks by using a completely different IP network 2s a transit link. The live virtual lab is prepared with the devices that are represented in the topology diagram and the conectivity table. All devices have their basic configurations in place, including hostnames and IP addresses on the Ethernet and loopback interfaces. EIGRP is configured on R2 and R3 for the 10.0.0.0/8 network. R2 and R3 are-not aware of any| of the 172.16.0.0/16 networks that exist on Rl and R4. The tunnel interfaces have not been configured yet Configuring them is one of your tasks during this discovery. Once the tue! interfaces are up and operational, you will verify connectivity between the 172.16.0.0/16 networks through the GRE tunel. Topology Topology (©2017 Cisco Systems, ne (Cours Adminstration Gude 108 Discovery 51: Configure and Ver Single-Homed EBGP This topic details the lab activity for Discovery 51: Configure and Verify Single Homed EBGP. Objective: Configure and verify EBGP In this discovery, you will leam how to configure extemal BGP between the service provider and customer. ‘The service provider (ISP1) has two different customers (R1 and R2). It has to establish a separate EBGP session with each ofthe customers. All devices have their basic configurations in place, including hostnames and TP addresses. R1 and R2 are also preconfigured with BGP. Topology! Topology Le Challenge 13: Implement igle-Homed EBGP This topic detail the lab activity for Challenge 13: Implement Single-Homed EBGP. Objective: Configure and verify single-homed EBGP ABC Networks is adding a new remote site, Site C. to its network. The company has all these sites, connected via an MPLS provider and itrims EBGP with the ISP. The intemal network is setup for Site C. ‘The network is running BIGRP interelly. You have been contracted to complete the BGP configuration. Here are the requirements for Site C: + Establish EBGP with the MPLS provider on CE3. The neighbor IP address is 209.165.202.205, + On CES, advertise the networks that are leamed from EIGRP into BGP on CE3 by using metwork commands in BGP. You should see these networks in the routing table on CE and CES. + You should see the following networks in the CE3 routing table once the BGP session is established, If not, You can troubleshoot the issue by logeing into CE1 and CE2: © 2047 Cisco Systems, ne — 192.168.1.0.24 (from Site A) — 192.168.2.0.24 (from Site B) — 192.168.11.026 (from Site A) — 192.168.22.028 (from Site B) Topology Topology cristo Guide ©2017 Cisco Systems, ne Discovery 52: Configure Syslog ‘This topic details the eb activity for Discovery 52: Configure Syslog, Objective: Describe Syslog Configuration The objective ofthis discovery lab isto provide you with some experience with the syntax of basic syslog configuration to facilitate the management of Cisco 10S devices. This lb is prepared with the router and server that are represented in the topology diagram and the connectivity table. The devices have their basic configurations in place, including hostnames and IP addresses. Inthe discovery lab, you will configure the syslog server address ofthe router and set the severity threshold for messages tat are forwarded to the server. You will also use show commands to verify the syslog configuration and examine the syslog messages in the local logging buffer of the router. Topology Topology EtOH (conan Discovery 53: Configure SNMP This topic details the lab activity for Discovery 53: Configure SNMP. Objective: Configure and verify SNMP This discovery will provide you with some experience with the syntax of a basic SNMP configuration that facilitates the management of Cisco IOS devices. The live virtual lab is prepared with the roufer and server that are represented in the topology diagram and the connectivity table. The devices have their basic configurations in place, including hostnames and IP addresses. Inthe discovery, you will configure the router SNMP system contact and location variables. You will also define a read-only and a read-write community string and an SNMP server as the destination for SNMP traps. Topology Topology Challenge 14: Summary Challenge Lab 5 ‘This tonic details the lah acticin foe Challance Li Challenge Lah S This topic details the lab activity for Challenge 14: Summary Challenge Lab 5 Objective: Implement and troubleshoot a scalable multiarea network ‘You work for RMZ Networking. Your colleague Peter improved the network over the weekend. On. Monday moming, he is seeing certain issues inthe network and needs your help in troubleshooting it He gives you the following information about the network: + Site A and site B are comnected via serial links that are bundled into a muitilin interface + Site A has OSPF routing while site B has EIGRP on the devices. + CEI should establish a PPPOE session with the ISP, and the dialer interface should be configured to allow 2 dynamic IP address to be assigned. + The edge routers, CEL and CE2, are injecting default routes into OSPF and EIGRP, respectively (©2017 Cisco Systems, ne Course Adrinistaton Gace 119 + The serial links between CE1-R1 and CE1-R2 have PPP enabled. They authenticate by using CHAP. ‘The CHAP password is "clee0.” + Re and RS mm HSRP with the standby group number 10. Here are the issues that you need to resolve + OnR4 and RS, the following error message is seen: Rue Dac 9 06:09:00,695: %

You might also like