Documenti di Didattica
Documenti di Professioni
Documenti di Cultura
Friends... Dont be panic about ip address alignment; keep on practicing it will be easy for you to manage
Setion1 layer 2
1.1 initial Faults 1.2 Implement Access Switch Ports of Switched Network
Configure all of the appropriate non-trunking switch ports on SW1-SW4 according to the following requirements: VTP domain should e !CC"#$ and password !cisco$ VTP%& should e configured with SW1 as ser%er' SW&( SW)( SW4 V*+, data ase should e updated - SW1 Configure the V*+, ". and ,ame according to the ta le elow /case sensiti%e0 Configure the access ports for each V*+, as per the diagram +ll 4 switches must run in transparent mode after s-nchroni1ation +ll unused ports including 2iga ports ha%e to e on access V*+, 333 and shutdown
V AN I! NA"#
14 16 &6 )4 47 46 43 63 188 &88 )88 788 333 51toSW1 51toSW) 5&toSW) 5)toSW1 54to57 SW1toSW) SW1toSW4 SW)toSW4 991 99& 99) Client :nused
#nsure that these fi%e ports are allowed to communicate with their *a-er ) gatewa- /the V*+, 788 SV" on SW)0 and are prohi ited from directl- sending frames to each other' #nsure that none of these fi%e ports forwards flooded traffic due to an unknown unicast or unknown multicast' .o not use pri%ate %lans'
Frame-relay configuration
:se the following requirements to configure 51 and 57( 51 and 54( 5& and 54 for <rame-5ela-' #na le PPP etween 5) and 57' Configure 9ack to 9ack frame-rela- etween 51 and 57' :se su -interface etween 51 and 57 shown in diagram' Configure 9ack to 9ack frame-rela- etween 51 and 54 using .*C" &88 Configure 9ack to 9ack frame-rela- etween 5& and 54 using .*C" &@@ 57 and 54 ha%e to e .C# t-pe' .o not disa le keepali%e' .o not use in%erse +5P to resol%e "P addresses'
Section 2 - Layer 3
.o not use an- "P address not listed in A.iagram 1: "2P 5outing$ unless e;plicitl- required' .o not ena le >SP< on an- interfaces other than the ones shown in A.iagram 1: "2P 5outing$ unless e;plicitl- required'
Configure !mpls ldp e;plicit-null$ on oth P#s' SW& must maintain two separate routing ta les for each site as descri ed in the A.iagram )$ The onl- prefi; that SW& ma- see in its glo al routing ta le is its preconfigured "oop ack8 interface' @our configuration must full- recon%erge after a reload of an- P# router at the end of the e;am'
IP%&
1 &
Configure -our network as per A.iagram 4: "P%4 5outingA and according to the following requirements: Configure all routers #"25P%4 +S @@' :se the *oop ack 8 "P%4 address as the #"25P%4 router ".'
) 4 7 4 G 6
Configure the area 8 of >SP<%4 / etween the SW1 and SW) as shown the A.iagram of "P%4 5outingA0' The >SP<%4 process ". must e 188' *oop acks of SW1 and SW) in >SP<%) area8' *oop acks of 57( 5&( 54( and 51 in #"25P%4 +S @@' 5edistri ute >SP<%4 into #"25P%4 and on SW)' #nsure that there is full reacha ilit- among all "P%4 speakers'
(.2 2 Securit+
Consider that three ser%ers /S?TP( W#9( .,S0 connected to V*+, 788 on SW) must e reacha le from an- host an-where in the network' ?an- users are connected to V*+, 788 on SW) as well( and are allowed to connect to these local ser%ers' These users must also e allowed to connect to other S?TP( W#9 and .,S ser%ers located outside of V*+, 788' + num er of these users are a using the link with unnecessar- traffic' Configure -our network as per the following requirements: Create a filter on SW) to allow onl- legitimate traffic /S?TP-TCP port &7( W#9-TCP port 68( .,S:.P port 7)( "C?P all t-pes0 on V*+, 788 going from and to an- hosts /.o not specif- an- "P address in the filter0' +ll non-legitimate traffic must e dropped' :ser a single named access-list to accomplish this requirement of this task' .o not include an- denstatement in the access-list
'
(.* P52
Configure -our network as per the following requirements: Create interface *oop ack146 in SW) with the "P address 146'8'8'6=)& and add it into #"2 5P @@ an- means a%aila le' Create interface *oop ack146 in 54 with the "P address 146'8'8'4=)& and add it into #"25P @@ - anmeans a%aila le' Traffic sourced from *oop ack146 of SW) and destined to *oop ack146 of 54 /and onl- this traffic0 must alwa-s lea%e SW) %ia interface V*+,16 no other interface ma- e%er transmit these packets' SW) must load- alance / etween 51 and 5&0 an- other traffic destined to *8146 of 54' "n case interface V*+, 16 of SW) is not operational packets etween *8146 of SW) and *ol46 of 54 must e dropped on SW)' :se a single num ered and e;tended access-list with a single entr- in order to accomplish this requirement' .o not modif- an- #"25P parameter an-where to accomplish this requirement' :se the following tests to %alidate -our solution
Protocol JipK: Target "P address: 146'8'8'4 Source address: 146'8'8'6 ,umeric displa- JnK: Timeout in seconds J)K: Pro e count J)K: ?inimum Time to *i%e J1K: ?a;imum Time to *i%e J)8K: Port ,um er J))4)4K: *oose( Strict( 5ecord( Timestamp( Ver oseJnoneK: T-pe escape sequence to a ort' Tracing the route to 146'8'8'4 1 18'18'16'1 4 msec 4 msec 4 msec & 18'18'14'4 8 msec L 4 msec 5ack18SW)Itrace 146'8'8'4 T-pe escape sequence to a ort' Tracing the route to 146'8'8'4 1 18'18'16'1 4 msec 18'18'&6'& 4 msec 18'18'16'1 4 msec & 18'18'&4'4 4 msec 18'18'14'4 4 msec L
9' Configure a named access-list called containing e;actl- two entries in order to classif- the a o%e BTT and BTTPS traffics' C' Configure another named access-list called A+**F"C?PA containing the single statement Apermit icmp an- an-A' .' The class-map A9*>CNE must drop the traffic matched - these two access-list /ABTTPA and A+**F"C?PA0' Configure another class-map called A"C?PF*"?"TA according to the following requirements: +' "C?P echo and echo-repl- to or from an-where must e policed to 188p=s( allowing 18 packets in urst' 9' Configure a named access-list called A"C?PF#CB>A in order to classif- the a o%e "C?P echo and echo-repl- traffic' .o not use an- Amatch notA statement in an- class-map' #nsure that an- de%ice / ut SW&0 can still ping the interfaces of 57' +ll class-map and access-list names are case sensiti%e and must not include an- quotes'
(.. N'P
Configure -our network as per the following requirements: 51 is the ,TP master /stratum 10' 5) and 57 must s-nchroni1e their clock to the clock of 51' #nsure that all three de%ices retain the clock etween re oots' +ll ,TP peer must use their *oop ack8 interface as the ,TP source'