Professional Documents
Culture Documents
Description
Author: CCIE Lab Center (CLC)
Focus: Practice
Level: Expert (CCIE)
Stream: CCIE Enterprise Infrastructure
Content: Diagrams (Topology) & Questions.
Format: PDF
Protection: None
Price: Free
Links to Download:
Lab Simulator (Eve-ng):
https://mega.nz/file/P7xjGYRC#f9271lat541J72_9YReQMGVH9Jc3K81co8CNTTg-NY8
HD Topology (PNG):
https://mega.nz/file/O25nEQqb#xZsTxSLXB8bG5JGpO1JilnyUQciI7r8KPlvtUgTDxN0
QUESTION
Refer Diagram#2
Configure the network in New York AS64510 site as per the following requirements:
QUESTION
Refer Diagram#2
Configure the network in New York AS64510 site as per the following requirements:
QUESTION
Refer Diagram#2
Configure the network in New York AS64510 site as per the following requirements:
QUESTION
Refer Diagram#2
Configure the network in New York AS64510 site as per the following requirements:
1. Configure layer 2 ether channels between SW1 & SW2 as per the diagram.
2. SW1 must initiate ether channel negotiation using LACP and SW2 must never initiate ether
channel negotiation.
3. Your ether channel configuration must not impact the trunks.
4. Ensure that all ports included in ether channel are effectively in use and bundled in the
expected channel.
QUESTION
Refer Diagram#3
Configure the network in Brazil AS64540 site as per the following requirements:
1. You must use the EIGRP Autonomous System as per the topology
2. The interface loopback0 on each L3 device must be seen as an internal EIGRP prefix by all other
devices.
3. Ensure the EIGRP is not running on any interface that is facing another AS. Use any method to
accomplish this requirement.
4. At the end VPC-2 must be able to ping both the gateway routers Loopback0.
QUESTION
Refer Diagram#3
Configure the network in Australia AS64550 & Singapore AS64520 site as per the following
requirements:
1. You must use the EIGRP Autonomous System as per the topology
2. The interface loopback0 on each L3 device must be seen as an internal EIGRP prefix by all other
devices.
3. Ensure the EIGRP is not running on any interface that is facing another AS. Use any method to
accomplish this requirement.
4. At the end make sure that the reachability is successful.
QUESTION
Refer Diagram#4
Configure the network in New York AS64510 site as per the following requirements:
QUESTION
Refer Diagram#4
Configure the network in San Jose AS64580, W DC AS64530, New Zealand AS64560 & London
AS64570 site as per the following requirements:
QUESTION
Refer Diagram#5
Configure the network in Singapore AS64520 & Brazil AS64540 site as per the following
requirements:
QUESTION
Refer Diagram#6
Configure the network MPLS Core site as per the following requirements:
There are pre-confguration in MPLS Core AS500.
The admisnistrator has already configured OSPF in AS500
Configure all the CSR (ISP & P Routers) as per below requirements :
1. All BGP routers must use their interface loopback0 as their BGP router-id.
2. Disable the default ipv4 unicast address family for peering session establishment in all
BGP routers.
3. Interface loopback on each router must be seen as a internal BGP route
4. P1 must be the ipv4 route-reflector for BGP AS500.
5. P1 must use the peer-gorup named “CLC” for all internal peerings (ISP Routers).
6. At the end all IGP routes must be reachable to each other and must have a successful
ping test.
QUESTION
Refer Diagram#6
Configure the network of MPLS & WAN sites
Configure all PE & CE sites as per the following requirements:
1. All BGP devices must use their interface loopback0 as their BGP router-id
2. Disable the default ipv4 unicast address family for peering session establishment in all
BGP routers.
3. All PE devices must establish EBGP peerings with CE & Vice Versa.
4. On CE devices redistribute IGP into BGP and vice versa to receive the required routes and
reachability.
5. Make sure that the routes received from PE must not enter the IGP through CE devices and
must receive only summary routes from ISP’s.
6. Make sure your configuration does not disallows you the end-to-end rechability.
QUESTION
Refer Diagram#7
Configure the network in Singapore AS64520 & Brazil AS64540 sites as per the following
requirements:
QUESTION
Refer Diagram#8
Configure the network in New York AS64510 & Brazil AS64540 as per the following
requirements
QUESTION
Refer Diagram#10
Configure the network in San Jose AS64510 as per the following requirements
QUESTION
Refer Diagram#10
Configure the network in London AS64570, New Zealand AS64560 & WDC AS64530 as per the
following requirements
QUESTION
Refer Diagram#10
Configure the network SD-WAN Technology as per the following requirements
QUESTION
Refer Diagram#10
Configure the network SD-WAN Technology as per the following requirements
QUESTION
Refer Diagram#9
The administrator has decided to use VPN Technology for securing the MPLS network.
Configure MPLS Core AS500 as per below requirements:
1. Ensure that all ISP(PE) Routers must make VPNv4 neighborship with P1
2. P1 must reflect VPNv4 prefixes to all its PE’s
3. Configure all ISP(PE) routers as per below VRF’s
ISP1 CSR1: SAN-JOSE
ISP1 vEdge1: LONDON
ISP1 vEdge2: NEW-ZEALAND
ISP2 CSR2: SAN-JOSE
ISP2 R11: HOME
ISP2 R1: NEW-YORK
ISP2 R2: SINGAPORE
ISP2 vEdge3: WDC
ISP3 vEdge1: LONDON
ISP3 vEdge2: NEW-ZEALAND
ISP3 R6: AUSTRALIA
ISP3 R3: BRAZIL
ISP4 R1: NEW-YORK
ISP4 R2: SINGAPORE
ISP4 vEdge4: WDC
ISP4 R4: Brazil
4. You must configure in such a way to receive all prefixes from CE routers.
5. The Mpls core network AS 500 has been already configured with OSPF by the Service Provider
Administrator.
6. At the end of the exam your configuration must not impact the services running at
customer end.
QUESTION
Refer Diagram#9
The administrator has decided to use VPN Technology for securing the network.
Configure MPLS Core AS 6500 as per below requirements:
1. San Jose AS64580 & New York AS64510 must be able to connect with every device in the CLC
Network.
2. Singapore AS64520 & Brazil AS64540 must be able to connect with each other in CLC Network.
3. Ensure that non other than the above mentioned are reachable to each others network.
4. The Mpls core network AS500 has been already configured with OSPF by the Service Provider
Administrator.
5. In MPLS Core, all P & PE routers must use LDP protocol & must use their interface loopback0 as
their LDP Router ID.
6. In MPLS Core all PE routers must allow maximum 500 prefixes from CE and must generate a log
when the prefixes reaches 80% of the total prefixes allowed.
7. You are not supposed to modify any changes on CE Routers to accomplish this task.
QUESTION
Refer Diagram#11
The administrator has decided to use Dual-Hub VPN Technology for securing the network but
facing certain issues in getting spoke to spoke reachability.
1. The admin has already configured the dmvpn configuration with a dual hub technology.
Interface tunnel0 & tunnel1 on all four routers R1, R2, R3 & R4 are used.
R3 is the DMVPN-Hub1 router for both spokes R1 & R2 and R4 is the DMVPN-
Hub2 router for both spokes R1 & R2.
2. You must be able to get the OSPF adjacency up through the tunnels between both the
Hubs and Spokes routers.
3. You need to check and troubleshoot the issue/reason due to which the spoke-to-spoke
connections are down.
4. When you make a tarceroute, Spoke-to-Spoke traffic does not transit via the Hub router.
QUESTION
Refer Diagram#12
The administrator has decided to use Flex VPN Technology for securing the network in
Australia AS64550 site as per the following requirements.
1. The administrator has already configured the Flex-VPN Technology in Australia AS64550.
2. R6 is the Hub and R7 & R8 are the Spokes.
3. You are suppose to identify the cause and get the services back to live again.
4. At the end you must the test your solution with below commands:
a. Show ip interface brief ----> you must see the virtual-access interfaces as up & up
b. Show crypto ipsec sa ----> you must see the hits on encrypt and decrypt packets
c. Show crypto ikev sa detailed ----> you must see the other spoke ip address (as remote)
with ready status.
QUESTION
The administrator has decided to use Network Time Protocol Service(NTP).
Configure NTP in New York AS64510 as per the below requirements.
QUESTION
Configure R1 in the New York AS64510 site as per the following requirements
QUESTION
Configure the network in New York AS64510 as per the following requirements:
1. R1 must assign hosts (VPC-1) in VLAN 10 on SW3 with a valid IP address from the prefix
172.10.253.254/24
2. Ensure that addresses that were statically configured will never be assigned to any hosts.
3. Ensure that the distribution switches SW1 and SW3 forward DHCP discover broadcast messages
received from VLAN 100 to VPC-1 (in VLAN 10) as unicast message.
4. Ensure that the VPC-1 effectively receives an IP address as well as its default gateway
information.
QUESTION
1. R11 router must allow all the incoming & outgoing traffic from required sources.
2. R11 router must use its interface loopback0 ip address for swapping any destination
traffic.
3. You are allowed to use a single standard list to complete this task
4. R11 router must enable all private corporate traffic that is originated from any host with
source ip address 172.0.0.0/8 to connect to any public destination.
5. R11 must swap the source ip address in these packets with the ip address of its interface
loopback0
6. R11 must allow multiple concurrent connections.
QUESTION
Configure the network in San Jose AS64580 as per the following requirements
1. Configure API calls for real-time monitoring of application-aware routing: SLA Class as
per the below informations
QUESTION
Configure the network in San Jose AS64580 as per the following requirements
Display statistics about data traffic characteristics for all operational data plane tunnel.
CLI Equivalent: show app-route stats
URL: https://172.80.200.11/dataservice/device/app-route/statistics?deviceId=deviceId
Method: GET
Request Parameters
QUESTION
Configure the network in San Jose AS64580 as per the following requirements
1. Use Python to establish a session to the vManage server, with the username and
password indicated on the command line
Class with REST Api GET and POST libraries
python rest_api_lib.py vmanage_hostname username password
PARAMETERS:
vmanage_hostname : Ip address of the vmanage or the dns name of the vmanage
username : Username to login the vmanage
password : Password to login the vmanage