You are on page 1of 43
Taken on 4th Sep 10.1.1.0/24 interface E 0/3 ip address 192.168.2.1 255.255.255.0 vrf forwarding Science no shut vrf definition Science ! interface E ip address 132.168.1.1 255.255.255.0 no shut 1 interface E 0/3 ip address 192.168.2.1 255.255.255.0 no shut vrf definition Science address-family ipv4 ! interface E 0/2 ip address 182.168.1.1 255.255.255.0 no shut ! interface E 0/3 ip address. 192.168.2.1)266.265.255.0 no shut Taken on 4th Sep ST Rs aE NON eae [Ps aacan tnimim Once yaar O60 Cuceamas Odd Once paar Jono panaiansn it Sworn SW tp ce nm rt eny FEF FFT, ce [srs'szezs 22 onc swoorW. SW tne seep sat Vt [sn 2931 sco ONCPSwooP Nn st Hn Seng wu asp Mas [sn 2031 500 OMchswaorin stn Stn t moa eon Was ed [sn 2831209 BNcrSNORin snp) Satin rata Papa Ye dan is203 sir onc shoot eet EHCP aa oe npn Po cham ‘Sato buaeon ONC enon uae een inte) ben Hh Gane manson Pa ac “ [Ereipasrenngtomston pen lp ep ty oman porta? “instep eepngat -nthenncnng sarge cogs ean forgone trl aes bs set uitiprotocal 8G atthe customer ste for aggregation & U2 How does an MPL on? customer sites inerConnect trough a service provider network using customer edge to provider edge connectiviy tes | over the intemet fr security Inteccomect trough servce provide network to create secure tunnels between custemer edge devices Taken on 4th Sep HQ_R1 gino 172.16.35 0130 HO_R3 10.10.20.0124 iy 192.168.100.024 ' BRANCH (config) # ip sla 1 BRANCH (config-ip-sla)# ignp-echo 172 2 BRANCH (config-ip-sla)# timeout 200 BRANCH (conf'ig-ip~ -requel 1 BRANCH ( p 5 je 1 life forever start-time now \fig)# track 1 ip sla 1 reachability gio Ao Wt re gh ab ay el ony en Pe Ope own on Taken on 4th Sep RI interface Loopback Sp aaarene 172.16.1.1 255.25 sntartace Fastrenernet/0 ‘fp asdeess 192-168-12-1 288.288. 258.0 12.1 vastuenerneto/0 Referto the exhibit Rt and R2.cannet establish a EIGRP ac ishes EIGRP adjacency? (© Ai the passiveinterface commando the Rt 20 thatit matches the R2 coniguraon {B)Remove the passiveinterface command trom tha? S01RSt& matches the Rt confouraton © Remove the cuent autonomous system nuber on one and change oa diferent vale » Adi the ne auto-summary command to So that matches the Rt configuration , ro 1045. re sn garo enna ae pad ar onsen ea Bars WR RP eh rae ecas » LAN Segments. LAN Segments 192.168.3.0/24 192.168.1.0/24 192.168:4.0/24 Static Routing (Aq q\ (4) EIGRP (21/45) / ae“ eo Yeon corn pe 10.1.1.0124 ; 10.1.2.0124 Chicago NewYork Chicago Router ip route 192.168.1.0 255.255.255.0 ip route 192.168.2.0 255.255.255.0 ' router eigrp 100 b redistribute static LA Router ip route,0.0.0.0,0.0.0.0 10.1.1.1 ‘Rae ue mae 1010103050 age Une nat Taken on 4th Sep Refer othe exhibit Which acton resolves the failed authenticati [Configure aaa authorization console global command. © Configure aaa autherization login command onl vty 0 © Configure aaa authorization console command or Hine vty (© Configure aaa authorization login command Biine cons ee rumen "PeoaSoboneneara0 pean Taken on 4th Sep Taken on 4th Sep LO: 1.1.1.1/24 200.1.3.0/24 LO: 3.3.3.3/24 (cfg-crypto-trans)# mode transport R2{contigy# crypto ipsec profile TST R2{ipsec-profley# set transform-set TSET R2(config)# interface tunnel 123, R2{config-i# tunnel protection ipsec profile TST to 9. Which coniguratin allows spokeo-spoke communication using loopback as a tunnel source? re eryptoisahmp ky lscoaderess 000 heh Contigue erp Isak key cisco adress 2001.0 288 288.00 on the ub. Configure erp isakmp hey cese adress 2001.00 255,258.00 on the sakes Configure crypto isshmp key csco address 0..0.0on the spokes Taken on 4th Sep What are two functions of MPLS Layer 3 VPNs? (Choose two.) [g/Customer traffic is encapsulated in a VPN label when it is forwarded in MPLS . Se) [tis used for transparent point-to-multipoint connectivity between Ethernet lin (LDP and BGP can be used for Pseudowire signaling. @ BGP is used for signaling customer VPNv4 routes between PE (DA packet with node segment ID is forwarded along with destin: Taken on 4th Sep Taken on 4th Sep sear orton: rato setae rrgenn so adheeaon as ecg WP CES Bm eae Ped UNSER —— GO? How are MPLS Layer 3 VPN services deployed? {giThe label switch path must be available between the local ro © The RD and RT values must match under the VRF. © The import and export RT values under a VRF must always same © The RD and RT values under a VRF the PE router. open conse ots sag cing ita systems capt ct supper, wat ste minimum re spacing requires for BFD can acketo rece once cons packets aed? x a Tent Taken on 4th Sep R1#show run | begin line line con 0 exec-timeout 0 0 privilege level 15 logging synchronous transport preferred telnet transport output none transport referred telnet transport input none transport output tel Rig 6812.2 permitted from this terminal ietartnecnaed ay 172.20.7.0124) 172.20.8.0124) 192.168.100.0/24 192.168.200.024 Ast 2 a ASz0 ise (3%) (4) wea (a) (2) 192.168.10.0124 ‘192.168.20.0124 AS tt EOO\ a a\/E On (ay ES (119) Customer-Edge Customer-Edae ip prefix-list PLIST1 permit 172.20.5.0/24 ! route-map SETLP pérmit 10 match ip"address prefix-list PLIST1 set local-preference 90 ! router bgp 111 neighbor 192.168.10.1 remote-as 100 n@ighbor/192.168.10.1 route-map SETLP in ope 192.168.20.2 remote-as 200 024 AS 00a eta, Are igs S10 er amy cr te We Taken on 4th Sep soerane mat angus Cc rent ese crear emt sce Scene toi ces ree tach (cra cena nae (econ anguish onmand ene conse (ong aTHCACS* aed tien Taken on 4th Sep OSPF - Area 100 wrass02 seomoes (2) Gateway of last resort is not set 172.1.0.0/16 is variably subnetted, 5 172.1.11.0/24 is directly com 172.1.11.1132 is directly con 172.1.12.0/24 is directly cont 3 Taken on 4th noe © 192.168.3.0/24 [110/11] via 172.1. O 192.168.4.0/24 [110/11] via 172.1. O 192.168.5.0/24 [110/11] via 24 Gateway of last resort is not set 172.1.0.0/16 is variably subnetted, 5 subnets, 2 mask: 172.1, A are4 (AO viata 13,2, 00:04:44, Ethernet [110/11] via 172.1.12.1, 00:04: 172.1.12.0/24 is directly Sraed, Ether 172.1,12.3/32 is directly connected, Et 172.1.13.0/24 is directly connected, 172.1.13.3/32 is directly connected, 192.168.5.0/24 is 192.168.5.0/24°8 dire 192.168.5.1/32 is dire Taken on 4th Sep Cagrerote mp maeas SSD Covet coannee a0? coo tin FR > cores eee om ma cman. 05 ar ‘onfigure Configure set commands. Configure PBR on the interface. Configure fast switching for PBR. Taken on 4th Sep Which protocol does MPLS use to support traffic engineering? @BGP B OLDP © : 1 @TDP Y SSMS ASAT RT eee mene soca er What are two MPLS: :? (Choose two.) (9 The lal labels on the received packets. packets after the Layer 3 header. for reliable delivery of information. label is a short identifier that identifies a forwarding equivalence class. mum of two labels can be imposed on an MPLS packet. Ta x ken on 4th Sep remy eet ose cose tmuwcact Stunts) Layer 2 loop symptoms interface GigabitEthernet1/0/13 switchport trunk allowed vlan 30-33 switchport mode trunk ! interface GigabitEthernet1/0/23 switchport trunk allowed vlan 30-33 switchport mode trunk ‘An engendered a Layer 2 oop sng DNAC. Vic conmand este pobem nthe F-00300. uth? spanningtree backbonetast no spanningtree ulna, ‘Fspanningsee pontast bpduguard spanning-teeloopgurd default Taken on 4th Sep ‘Drag and drop the LOP features from the left onto the descriptions on the right. roves ways of improving loa balancing the okt ited wort ee terbt seat ore ‘xpi nul abel sR reeves an MPLS he entre el icit null label inbound label binding filtering a an i ag eng care i cums a Epics Taken on 4th Sep loa ck [sa Pr m2 0 Jetonerea| entra cnmanas, npr no End wan CATE Jono er aman ys conn. contpeestom saab ene sein nag tn crs cnnans ten sen nag tn el scans ete aenan imine amin ypemanin 8 ¢ ont acsaqunnce 2 pep host 018. DBH'A:2host 20180B1-AGt eg net ‘Satay Aovereany-pr-sasequter§ pomp ho 218 0B:A8:2 host 216 0BI:AC: a wine » Gatenay Rovere agers Oatauk Bocas b ‘SAStoy Roden pes dipemt ep hon HHO OBUAB:2 ost 218041 ene Gateway toon awe at eu Aas "Sy Adc tedeaquune 6 ptt hort 2408'AB-2hox 2HEOBLAC ag tnt Taken on 4th Sep einbiteSeany Seay sy ac Ye a os he cng Sat ets se case wie egies oe ages | Colne elogmgrtenat nat cmt | Cage nig eee tga nr ay | Colne elongates ocalgze eta min csnmasy \Whichconfguration feature shoud be used te Heck rogue router atversemenss instead of using he 2 (© PVLAN wi comemunty ports asscite to route advertisements and slated pat for noses (© 1PV4 ACL blocking owe advisement om nonauthorzed hosts {© VACL blocking broadcast rames from nonauthrzed hosts [BEPVLANs with promiscuous pos associate o route advertisements and iscate pots fr stepsatgergcomreeracrgona npc ton nts meen rary posctat prg ents Wren Peco Stenson ant an cca oy os crc Peay na cae cn 1 iste cotton ocean ety re gy eines rey nee ec Ste nt acon aoa ee ae Crs Fare Pyne cen Stee ce sn aentan 7 vente ph Cart Pe icy ne nt en Jo sotnta coun toma Psa bane parse sane ctgtin Wat mcg hte policy-map COPP-7600 class COPP-CRITICAL-7600 police cir 2000000 bc 62500 conform-action transmit exceed-action transmit ! class class-default police cir 200000 bc 6250 conform-action transmit exceed-action drop ! class-map match-all COPP-CRITICAL-7600 match access-group name COPP-CRITICAL-7600 ! ip access-list extended) COPP-CRITICAL-7600 permit ip any any eq http permit ip any any eq https Reter lg the exhibit 8G? i flapping after the CoPP policy is applied. Wha ae the two solutions to fixthe issue? (Choose two) ‘Concur a tree.cil!potcer instead of two-color poier under Class COPP-CRITICAL-7600. Contgie a higher valve for CIR under the Class COPP-CRITICAL.7600, 2 Contigue a higher value for CIR under the default lass to allow more packets dung peak rate iiConfgure BGP in the COPP-CRITICAL-7600 ACL. & Configure IP CEF for CoPP policy and BGP to work config t flow record v4_r1 match ipv4 tos match ipv4 protocol match ipv4 source address match ipv4 destination address match transport'source-port match transport destination-port collect counter. bytes long collect.counter packets long | flow exporter EXPORTER-1 destination 172.16.10.2 transport udp 2055 exit Taken on 4th Sep ! flow monitor v4_r1 B ! « ) ip cef o> | interface Ethernet0/0. Y ip address 172.16 .255.255.0 iP flow monitor Wa ut Mod Kip port under flaw exporter profile to ip transport udp 4738. “5 rm posed to orn fw nor & Taken on 4th Sep Router Configuration: router ospf 0.0.0.0 network 2.0.0.0 0.255.255.255 area 0.0.0.0 ! router bgp 100 redistribute ospf 0.0.0.0 o> ! neighbor 3.3.3.2 remote-as 200 Y ! end Router# show ip route |, Ethernet0/O fed, Serial1/0 0) via 2.2.2.2, 00:16:17, Ethernet0/O 104] via 2.2.2.2, 00:00:41, Ethernet0/O subnetted, 2 subnets [110/74] via 2.2.2.2, 00:16:17, Ethernet0/O 1.0 [110/84] via 2.2.2.2, 00:16:17, Ethernet0/O Routers show ip bop Network NextHop Metre LocPr Weight Path 22200 0000 os2768? 911081004 2222 4 327687 11082028 2222 4 327687 ‘etre on The CSPF eng HE ease Re BSF ge, a sae OSFF anes doe HD BOF Wh anesthe ee? be arouamap canada OSPF onl erat nace at |p ters earner sont Une arava cand rine OSPF ena res ein rei fen on 4th Sep Taken on 4th Sep Taken on 4th Sep ip sla 10 tep connect 10.1.1.1 80 ip sla schedule 10 life 30 start time now Taken on 4th Sep In which two ways does the IPv6 First-Hop Security Binding Table operate? (Choose two.) [Sby IPV6 HSRP to make sure neighbors are authenticated before being used as gateways @ by various IPV6 guard features to validate the data link layer address (by storing hashed keys for IPsec tunnels for the builtin IPsec features [@by IPV6 routing protocols to securely build neighborships without the ion a by the recovery mechanism to recover the binding table in the ‘Anengnee canine acanganysmtioe wea OSPF Hed ce tn te yn. a le core APE ere MPLS ag otcea Sank Bora & (Basarece 02x amaanaautane feteont tate ‘ie festng ah ster confuse ftheL SA, ree Vic evan soe i se? cone ena wt on Peas roe abe cone ena wt on as ola oe Fel os abe cone ena wo 8 soar nt eae A> Ofc ar St Aros ie rot pt wf abe Taken on 4th Sep 192.168.0.1 /24 Physical: 172.17.0.1 Tunnel: 10.0.0.1 HUB / Physical: 172.17.0.2 ” Tunnel: 10.0.0.11 Fa0/0 Fa0/0 SpokeA — Spoki Interface TunnelO description mGRE ip address 10:4.0.1 258: 192.168.1.1 /24 192.168.2.1 /24 =k Pars. se mae ner mi ‘tunnel mode gre multipoint Taken on 4th Sep R1#show policy-map control-plane Control Plane Service-policy output: CoPP © Class-map: SNMP-Out (match-all) 124 packets, 3693 bytes 5 minute offered rate 0000 bps, drop 10 bp: Match: access-group name SNMP police: cir 8000 bps, be 1500 byt conformed 0 packets, 0 transmit exceeded 0 packet drop conformed 01 Class-map: class: ; any ip access-list SNMP Extended IP access list SNMP 10 permit udp any eq snmp any feng SNP and montrg deces reir ory pail norman What acon shade ten orca hs es? eter tgesbe RY bona 2 CoP lyons the cogued exceeded tf SP tesomeap Pp to nreae he congue CR er SNP Moat stn a a secon he atow up ay ny 69 58 Taken on 4th Sep ‘Which two protocols work in the control plane of P routers across the MPLS cloud? (Choose oP juse (MPLS OAM @ECMP Y sinese 2 Chicago interface Tunnel 1 ip address 192.168.1.1 255.255.255.0 tunnel source E0/0 tunnel mode gre multipoint ip nhrp network-id 1 ip nhrp map multicast dynamic no ip next-hop-self eigrp 111 tunnel protection ipsec profile IPSec-PROFILE router eigrp 111 ‘RUE o he clot The Los Arges and New York ues ae reasing ous om Chicago but rat fam eachother. Which confguaton bes tess? Intact Tunnels ‘unnel rotestion psee profile IPSec PROFILE Inertae Tunelt Ipnexthopeei erp 111 cron ear 18 Taken on 4th Sep ‘Spoke# show emvpn ‘Tunnel0, Type:Spoke, NHRP Peers:2, # Ent Peer NMA Addr Peer Tunnel Add State UpDn Tm Att 1172.18.16.2 192.168.1.1 UP 01:08:35 S 1172.18.46.2 192.168.1.4 UP 00:00:25 D ‘Retro te ei An engner has configured DMVPN on a spoke router Whit the WAN IF aoe of ance spoke o wae162 > 192 108 14 2 192 10814 9 EIGRP->OSPF Referee ett carr edsrton onan ASBR to each a WAN networks bt aed Which acon resales theese? > BGR te be 10.0 108.04 rove instead of using he etn tere. ome renting pretaes tom EIGRP oie map rust have the 100106024 ety tent none the bre pret pass map keyed pris eva te pei st ernes. LA router ospf 1 network 192.168.12.0 0.0.0.255 area 0 network 172.16.1.0 0.0.0.255 area 0 NY router ospf 1 network 192.168.12.0 0.0.0.255/area 0 network 172.16.2.0 0.0.0.255/area 0 ! interface E 0/0 ip ospf authentication messagé-digest ip ospf message-digest=key 1 md5 Cisco123 Reler tothe exhibit The neighbor relationship ignaltoming up. Whictfvro configurations bring the adjacency up? (Choose two.) a Fouter ospf t ‘prea 0 authentication message-cigest wy router ospf 1 ‘grea O authentication meszage-digest Ls interface E 0/0 Tpospfmessage-digest-key 1 md8 Cisco123 ny Interface E 010 no Ip ospt messagedigest-key 1 mdS Ciscot23 Tpospf authenticaton-key Clscot23 ey Interface E010 {ip oxpf authentication-key Ciscot23 Taken on 4th Sep Taken on 4th Sep sna eos sn 02.88.19 tn ec + Span Yorn eee bea Taken on 4th Sep Lo0: 4.1.1.1 192.168.23.0/24 inset wit paste om 1821 es 9 0 ‘Sram .19 on Peter nemcaronass ‘Nit nto iz ut.29 000057 a a Fata ‘ey 0 econ mam ona 62500 fib 255 mw ob (ang 8 255 hoe Refeo he ext Ras wo paths foreach 162 68 130724, tt alle sent ny rough RD. Wich acon allows atic louse bah pas? Cong he variance 2 comand unde th EIGRP process on R2 (nicenfiawe te vaane 4 command vnder the EIGRP process on R2 Congr the day 4 comand ur netace Faster on R2 Configure the bandwith 2000 conmand under ntrace Fasten on R2 Taken on 4th Sep 192.168.1.0/24 192.168.3.0/24 192.168.13.0/28 12 168302410) vo 12168 122 9216012026 ears 2 bos, 2 ashe 19216812024 ray emacs, Sot 19216812182 ety enact, Set 11216813024 any owe, 26 2 mas 19216818024 doc comece, Sat 19216812192 recy comece, Ser 2168 25.10724 0728108 vi 12 168.133, 000838, Serio press 02108122 000834 Seats sa s6azte monte va 192168122, 000690, erat x SiepayMeeteere a ctteemanedeae neater are Rate Dat AES. pasate saan eo, Taken on 4th Sep Congsan yur nerves 602 poets ‘Apgar trp summarng ys i be poe Yo a Yu Neg Et Te ren OSS MM PT eo sos as haat um sy agg xn pera onc Yu aD sr

You might also like