Documenti di Didattica
Documenti di Professioni
Documenti di Cultura
Assessment Objectives
Part 1: Initialize Devices (8 points, 5 minutes)
Part 2: Configure Device Basic Settings (28 points, 30 minutes)
Part 3: Configure Switch Security, VLANs, and Inter-VLAN Routing (14 points, 15 minutes)
Part 4: Configure OSPFv2 Dynamic Routing Protocol (24 points, 25 minutes)
Part 5: Implement DHCP and NAT (13 points, 25 minutes)
Part 6: Configure and Verify Access Control Lists (ACLs) (13 points, 25 minutes)
2013 Cisco and/or its affiliates. All rights reserved. This document is Cisco Public.
Page 1 of 20
SA Exam
Scenario
In this Skills Assessment (SA) you will configure a small network. You will configure routers, switches, and
PCs to support IPv4 connectivity, switch security, and inter VLAN routing. You will then configure the devices
with OSPFv2, DHCP, and dynamic and static NAT. Access control lists (ACLs) will be applied for added
security. You will test and document the network using common CLI commands throughout the assessment.
Required Resources
3 Routers (Cisco 1941 with Cisco IOS Release 15.2(4)M3 universal image or comparable)
2 Switches (Cisco 2960 with Cisco IOS Release 15.0(2) lanbasek9 image or comparable)
3 PCs (Windows 7, Vista, or XP with terminal emulation program, such as Tera Term)
Console cable to configure the Cisco IOS devices via the console ports
IOS Command
Points
R1#erase startup-config
R2#erase startup-config
R3#erase startup-config
1 points
( point
per
router)
R1#reload
R2#reload
R3#reload
1 points
( point
per
router)
S1#erase startup-config
S1#delete vlan.dat
S3#erase startup-config
S3#delete vlan.dat
2 points
(1 point
per
switch)
S1#reload
S3#reload
2 points
(1 point
per
switch)
S1#show flash
S3#show flash
1 point
( point
per
switch)
2013 Cisco and/or its affiliates. All rights reserved. This document is Cisco Public.
Page 2 of 20
SA Exam
Points: __________ of 8
Specification
Points
IP Address
209.165.200.226
(1/2 point)
Subnet Mask
255.255.255.248
(1/2 point)
Default Gateway
209.165.200.225
Note: It may be necessary to disable the PC firewall for pings to be successful later in this lab.
Specification
Points
No ip domain lookup
(1/2 point)
Router name
R1
(1/2 point)
class
(1/2 point)
cisco
(1/2 point)
cisco
(1/2 point)
Service password-encryption
(1/2 point)
MOTD banner
(1/2 point)
Interface S0/0/0
(1/2 point)
Default route
(1/2 point)
2013 Cisco and/or its affiliates. All rights reserved. This document is Cisco Public.
Page 3 of 20
SA Exam
Specification
Points
(1/2 point)
Router name
R2
(1/2 point)
class
(1/2 point)
cisco
(1/2 point)
cisco
(1/2 point)
(1/2 point)
(1/2 point)
MOTD banner
(1/2 point)
Interface S0/0/0
(1 point)
Interface S0/0/1
(1 point)
(1 point)
(1/2 point)
Default route
(1/2 point)
2013 Cisco and/or its affiliates. All rights reserved. This document is Cisco Public.
Page 4 of 20
SA Exam
Specification
Points
(1/2 point)
Router name
R3
(1/2 point)
class
(1/2 point)
cisco
(1/2 point)
cisco
(1/2 point)
(1/2 point)
MOTD banner
(1/2 point)
Interface S0/0/1
(1/2 point)
Interface Loopback 4
(1/2 point)
Interface Loopback 5
(1/2 point)
Interface Loopback 6
(1/2 point)
Default route
(1/2 point)
Specification
Points
(1/2 point)
Switch name
S1
(1/2 point)
class
(1/2 point)
cisco
(1/2 point)
cisco
(1/2 point)
(1/2 point)
Unauthorized Access is Prohibited!
Step 6: Configure S3
Configuration tasks for S3 include the following:
2013 Cisco and/or its affiliates. All rights reserved. This document is Cisco Public.
Page 5 of 20
(1/2 point)
SA Exam
Specification
Points
(1/2 point)
Switch name
S3
(1/2 point)
class
(1/2 point)
cisco
(1/2 point)
cisco
(1/2 point)
(1/2 point)
Unauthorized Access is Prohibited!
(1/2 point)
2013 Cisco and/or its affiliates. All rights reserved. This document is Cisco Public.
Page 6 of 20
From
R1
To
R2, S0/0/0
SA Exam
IP Address
172.16.12.2
Ping Results
Points
R1#
(1/2 point)
R1#ping 172.16.12.2
Type escape
sequence to abort.
Sending 5, 100-byte
ICMP Echos to
172.16.12.2, timeout
is 2 seconds:
!!!!!
Success rate is 100
percent (5/5), roundtrip min/avg/max =
1/6/19 ms
R1#
R2
R3, S0/0/1
172.16.23.2
Internet PC
Default Gateway
209.165.200.225
PC>ping
209.165.200.225
Pinging
209.165.200.225
with 32 bytes of
data:
Reply from
209.165.200.225:
bytes=32 time=0ms
TTL=255
Reply from
2013 Cisco and/or its affiliates. All rights reserved. This document is Cisco Public.
Page 7 of 20
(1/2 point)
SA Exam
209.165.200.225:
bytes=32 time=1ms
TTL=255
Reply from
209.165.200.225:
bytes=32 time=1ms
TTL=255
Reply from
209.165.200.225:
bytes=32 time=0ms
TTL=255
Ping statistics for
209.165.200.225:
Packets: Sent = 4,
Received = 4, Lost =
0 (0% loss),
Approximate round
trip times in milliseconds:
Minimum = 0ms,
Maximum = 1ms,
Average = 0ms
PC>
Note: It may be necessary to disable the PC firewall for pings to be successful.
Instructor Sign-off Part 2: ______________________
Points: _________ of 28
2013 Cisco and/or its affiliates. All rights reserved. This document is Cisco Public.
Page 8 of 20
SA Exam
Specification
Points
(1 point)
(1/2 point)
(1/2 point)
(1/2 point)
(1/2 point)
(1/2 point)
(1/2 point)
(1/2 point)
Specification
Points
(1 point)
(1/2 point)
(1/2 point)
(1/2 point)
(1/2 point)
(1/2 point)
(1/2 point)
2013 Cisco and/or its affiliates. All rights reserved. This document is Cisco Public.
Page 9 of 20
SA Exam
Specification
Points
(1 point)
(1 point)
(1 point)
(1/2 point)
2013 Cisco and/or its affiliates. All rights reserved. This document is Cisco Public.
Page 10 of 20
From
S1
To
R1, VLAN 99 address
SA Exam
IP Address
192.168.99.1
Ping Results
S1#ping
192.168.99.1
Points
(1/2 point)
Type escape
sequence to abort.
Sending 5, 100-byte
ICMP Echos to
192.168.99.1,
timeout is 2 seconds:
!!!!!
Success rate is 100
percent (5/5), roundtrip min/avg/max =
0/0/1 ms
S1#
S3
192.168.99.1
S3#ping
192.168.99.1
(1/2 point)
Type escape
sequence to abort.
Sending 5, 100-byte
ICMP Echos to
192.168.99.1,
timeout is 2 seconds:
!!!!!
Success rate is 100
percent (5/5), roundtrip min/avg/max =
0/0/1 ms
S3#
S1
192.168.31.1
S1#ping
192.168.31.1
Type escape
sequence to abort.
Sending 5, 100-byte
ICMP Echos to
192.168.31.1,
timeout is 2 seconds:
!!!!!
Success rate is 100
2013 Cisco and/or its affiliates. All rights reserved. This document is Cisco Public.
Page 11 of 20
(1/2 point)
SA Exam
S3#ping
192.168.33.1
192.168.33.1
(1/2 point)
Type escape
sequence to abort.
Sending 5, 100-byte
ICMP Echos to
192.168.33.1,
timeout is 2 seconds:
!!!!!
Success rate is 100
percent (5/5), roundtrip min/avg/max =
0/0/1 ms
S3#
Instructor Sign-off Part 2: ______________________
Points: _________ of 14
Specification
Points
OSPF Process ID
(1/2 point)
Router ID
1.1.1.1
(1/2 point)
(1 point)
(1 point)
1000
128 Kb/s
(1 point)
Cost: 7500
(1 point)
2013 Cisco and/or its affiliates. All rights reserved. This document is Cisco Public.
(1 point)
Page 12 of 20
SA Exam
Specification
Points
OSPF Process ID
(1 point)
Router ID
2.2.2.2
(1 point)
(1 point)
(1 point)
1000
128 Kb/s
(1 point)
Cost: 7500
(1 point)
(1 point)
Specification
Points
OSPF Process ID
(1/2 point)
Router ID
3.3.3.3
(1/2 point)
(1 point)
(1 point)
1000
128 Kb/s
(1 point)
(1 point)
2013 Cisco and/or its affiliates. All rights reserved. This document is Cisco Public.
Page 13 of 20
SA Exam
Question
Response
Points
(1 point)
(1 point)
Show ip protocols
(1 point)
(1 point)
(1 point)
(1 point)
Specification
Points
(1 point)
(1 point)
Name: ACCT
DNS-Server: 10.10.10.11
Domain-Name: ccna-sba.com
Set the default gateway.
(1 point)
Name: ENGNR
DNS-Server: 10.10.10.11
Domain-Name: ccna-sba.com
Set the default gateway.
(1 point)
2013 Cisco and/or its affiliates. All rights reserved. This document is Cisco Public.
Page 14 of 20
SA Exam
Specification
Username: webuser
Password: cisco12345
Privilege level: 15
Points
(1 point)
(1/2 point)
(1/2 point)
Inside Global Address: 209.165.200.229
(1 point)
interface Loopback0
ip address 10.10.10.10 255.255.255.255
Assign the inside and outside interface
for the static NAT
ip nat inside
(1 point)
interface GigabitEthernet0/0
ip nat outside
Access List: 1
Allow the Accounting and Engineering networks on
R1 to be translated.
R2(config)#access-list 1 permit 192.168.31.0
0.0.0.255
R2(config)#access-list 1 permit 192.168.33.0
0.0.0.255
(1 point)
2013 Cisco and/or its affiliates. All rights reserved. This document is Cisco Public.
Page 15 of 20
(1 point)
SA Exam
interface Serial0/0/0
ip nat inside
interface Serial0/0/0
ip nat inside
(1 point)
interface GigabitEthernet0/0
ip nat outside
2013 Cisco and/or its affiliates. All rights reserved. This document is Cisco Public.
Page 16 of 20
Test
SA Exam
Results
Points
(1/2 point)
(1/2 point)
PC>ping 192.168.33.21
Pinging 192.168.33.21 with 32 bytes of data:
(1/2 point)
(1/2 point)
Server Reset Connection
2013 Cisco and/or its affiliates. All rights reserved. This document is Cisco Public.
Page 17 of 20
SA Exam
Specification
Points
R2(config)#ip access-list
standard ADMIN-MGT
R2(config-std-nacl)#permit
host 172.16.12.1
(2 points)
line vty 0 4
Apply the named ACL to the VTY lines
access-class ADMIN-MGT
in
(1 point)
R1>telnet 172.16.12.2
Trying 172.16.12.2
...Open Unauthorized
access ia prohibited!
User Access Verification
Password:
R2>ena
Password:
Verify ACL is working as expected,
R2#
2013 Cisco and/or its affiliates. All rights reserved. This document is Cisco Public.
Page 18 of 20
(1 point)
SA Exam
Specification
ACL No.: 101
Points
(2
points)
R2(config)#interface g0/0
R2(config-if)#ip access-group 101
out
interface GigabitEthernet0/0
ip access-group 101 in
(1 point)
From the Internet PC:
2013 Cisco and/or its affiliates. All rights reserved. This document is Cisco Public.
Page 19 of 20
(1 point)
SA Exam
Step 3: Enter the appropriate CLI command needed to display the following:
Command Description
Points
Show access-lists
(1 point)
Sh ip interface
(1 point)
(1 point)
(1 point)
2013 Cisco and/or its affiliates. All rights reserved. This document is Cisco Public.
Page 20 of 20