Академический Документы
Профессиональный Документы
Культура Документы
Page 1
Page 2
Page 3
Configure the ACME Headquarters network (AS 12345) & New York Office (34567) as per the
following requirements.
1.
2.
3.
4.
5.
Page 4
Page 5
On SW2
On SW3
Page 6
On SW4
Page 7
Configure All Switch Ports as per the following requirements :1. Complete the configuration of all vlans so that all routers that are located in ACME's headquarters
(AS12345) and New York office (AS 34567) can ping their directly connected neighbors.
2. All four switches (SW1-SW4) must have four dot1q trunks that do not rely on negotiation
DO NOT configure any ether channel
3. Ensure that the following unused ports on all four switches are shutdown and configured as access
ports in vlan 999
E3/0 - E3/3 are unused on SW1 and SW2
E1/0 - E1/3 are unused on SW3 and SW4
E3/0 - E3/3 are unused on SW3 and SW4
Page 8
Page 9
SW2
------ Configuration
Page 10
Page 11
SW3
------ Configuration
SW3(config)#vlan 34
SW3(config-vlan)#exit
SW3(config)#vlan 38
SW3(config-vlan)#exit
SW3(config)#vlan 49
SW3(config-vlan)#exit
SW3(config)#vlan 89
SW3(config-vlan)#exit
SW3(config)#vlan 111
SW3(config-vlan)#exit
SW3(config)#vlan 310
SW3(config-vlan)#exit
SW3(config)#vlan 411
SW3(config-vlan)#exit
SW3(config)#vlan 999
SW3(config-vlan)#exit
SW3(config)#
SW3(config)#interface range ethernet 2/0 3
SW3(config-if-range)#switchport trunk encapsulation dot1q
SW3(config-if-range)#switchport mode trunk
SW3(config-if-range)#switchport nonegotiate
SW3(config-if-range)#exit
SW3(config)#
SW3(config)# interface range ethernet 1/0 - 3 , ethernet 3/0 3
SW3(config-if-range)#switchport mode access
SW3(config-if-range)#switchport access vlan 999
SW3(config-if-range)#shutdown
SW3(config-if-range)#exit
SW3(config)#
SW3(config)#interface ethernet 0/0
SW3(config-if)#switchport mode access
SW3(config-if)#switchport access vlan 38
SW3(config-if)#no shutdown
SW3(config-if)#exit
SW3(config)#
SW3(config)#interface ethernet 0/1
SW3(config-if)#switchport mode access
SW3(config-if)#switchport access vlan 89
SW3(config-if)#no shutdown
SW3(config-if)#exit
SW3(config)#
Copyright@www.passccieexam.com All Right Reserved
Page 12
SW4
------ Configuration
SW4(config)#vlan 34
SW4(config-vlan)#exit
SW4(config)#vlan 38
SW4(config-vlan)#exit
SW4(config)#vlan 49
SW4(config-vlan)#exit
SW4(config)#vlan 89
SW4(config-vlan)#exit
SW4(config)#vlan 111
SW4(config-vlan)#exit
SW4(config)#vlan 310
SW4(config-vlan)#exit
SW4(config)#vlan 411
SW4(config-vlan)#exit
SW4(config)#vlan 999
SW4(config-vlan)#exit
SW4(config)#exit
SW4(config)#interface range ethernet 2/0 3
SW4(config-if-range)#switchport trunk encapsulation dot1q
SW4(config-if-range)#switchport mode trunk
SW4(config-if-range)#switchport nonegotiate
SW4(config-if-range)#exit
SW4(config)#
SW4(config)# interface range ethernet 1/0 - 3 , ethernet 3/0 3
SW4(config-if-range)#switchport mode access
SW4(config-if-range)#switchport access vlan 999
SW4(config-if-range)#shutdown
SW4(config-if-range)#exit
SW4(config)#
Copyright@www.passccieexam.com All Right Reserved
Page 13
Page 14
Page 15
On SW2
Page 16
On SW3
Page 17
Page 18
On SW4
Page 19
Page 20
SW1 must be the root switch for all odd vlans and must be the backup for all even vlans
SW2 must be the root switch for all even vlans and must be the backup for all odd vlans
SW3 must be the root switch for all odd vlans and must be the backup for all even vlans
SW4 must be the root switch for all even vlans and must be the backup for all odd vlans
Explicitly configure the root and backup roles, assuming that other switches with default configuration
may eventually be added in the network in the future
Solution :SW1
------ Configuration
SW2
------ Configuration
Page 21
SW3
------ Configuration
SW4
------ Configuration
Page 22
On SW2
On SW3
On SW4
Page 23
NOTE :- 1) When SW1 goes down , SW2 will become root switch for all odd vlans.
2) When SW2 goes down , SW1 will become root switch for all even vlans.
3) When SW3 goes down , SW4 will become root switch for all odd vlans.
4) When SW4 goes down , SW3 will become root switch for all even vlans.
Page 24
Solution :R18
------ Configuration
R19
------ Configuration
Page 25
Page 26
On R19
Page 27
Page 28
R2 ------ Configuration
R2(config)#router ospf 12345
R2(config-router)#router-id 123.2.2.2
R2(config-router)#network 123.10.1.9 0.0.0.0 area 0
R2(config-router)#network 123.10.1.17 0.0.0.0 area 0
R2(config-router)#network 123.2.2.2 0.0.0.0 area 0
R2(config-router)#exit
R2(config)#
R3 ------ Configuration
R3(config)#router ospf 12345
R3(config-router)#router-id 123.3.3.3
R3(config-router)#network 123.10.1.10 0.0.0.0 area 0
R3(config-router)#network 123.10.1.13 0.0.0.0 area 0
R3(config-router)#network 123.3.3.3 0.0.0.0 area 0
R3(config-router)#exit
R3(config)#
R4 ------ Configuration
R4(config)#router ospf 12345
R4(config-router)#router-id 123.4.4.4
R4(config-router)#network 123.10.1.2 0.0.0.0 area 0
R4(config-router)#network 123.10.1.21 0.0.0.0 area 0
R4(config-router)#network 123.10.1.18 0.0.0.0 area 0
R4(config-router)#network 123.4.4.4 0.0.0.0 area 0
R4(config-router)#exit
R4(config)#
Page 29
R5 ------ Configuration
R5(config)#router ospf 12345
R5(config-router)#router-id 123.5.5.5
R5(config-router)#network 123.10.1.6 0.0.0.0 area 0
R5(config-router)#network 123.10.1.14 0.0.0.0 area 0
R5(config-router)#network 123.10.1.29 0.0.0.0 area 0
R5(config-router)#network 123.5.5.5 0.0.0.0 area 0
R5(config-router)#exit
R5(config)#
R6 ------ Configuration
R6(config)#router ospf 12345
R6(config-router)#router-id 123.6.6.6
R6(config-router)#network 123.10.1.22 0.0.0.0 area 0
R6(config-router)#network 123.10.1.25 0.0.0.0 area 0
R6(config-router)#network 123.6.6.6 0.0.0.0 area 0
R6(config-router)#exit
R6(config)#
R7 ------ Configuration
R7(config)#router ospf 12345
R7(config-router)#router-id 123.7.7.7
R7(config-router)#network 123.10.1.30 0.0.0.0 area 0
R7(config-router)#network 123.10.1.26 0.0.0.0 area 0
R7(config-router)#network 123.7.7.7 0.0.0.0 area 0
R7(config-router)#exit
R7(config)#
Page 30
Verification :On R1
On R2
Page 31
On R3
On R4
On R5
On R6
On R7
Page 32
Configure EIGRP for ipv4 in the New York office (AS34567) according to the following requirements
1. The EIGRP Autonomous System is 34567
2. The interface loopback 0 on each router must be seen as an internal EIGRP prefix by all other routers
3. Ensure the EIGRP is not running on any interface that is facing another AS. Use any method to
accomplish this requirement
4. Using a single command on one switch only ensure that R8 installs two equal-cost route for the
following three path
Vlan 411
Interface loopback0 at SW4
Interface loopback0 at R11
5. Using a single command on one switch only ensure that R9 installs two equal cost route for the
following three path
Vlan 310
Interface loopback0 at SW3
Interface loopback0 at R10
Page 33
R9 ------ Configuration
R9(config)#router eigrp 34567
R9(config-router)#network 123.10.2.2 0.0.0.0
R9(config-router)#network 123.10.2.9 0.0.0.0
R9(config-router)#network 123.9.9.9 0.0.0.0
R9(config-router)#no auto-summary
R9(config-router)#exit
R9(config)#
Page 34
Verification :On R8
Page 35
On R9
Page 36
On R10
On R11
On SW3
On SW4
Page 37
Page 38
----------------> Pre-configured
----------------> Pre-configured
----------------> Pre-configured
----------------> Pre-configured
Page 39
Page 40
On R16
Page 41
On R17
Page 42
On SW5
Page 43
On SW6
Page 44
On R18
Interface tunnel 0
no ip redirects
Ip address 123.20.1.26 255.255.255.248
tunnel source Serial1/0
tunnel mode gre multipoint
On R19
Interface tunnel 0
no ip redirects
Ip address 123.20.1.27 255.255.255.248
tunnel source Serial1/0
tunnel mode gre multipoint
Copyright@www.passccieexam.com All Right Reserved
Page 45
Page 46
Page 47
On R18
Page 48
On R19
Note : You will get the above result only after completing Section 3.3
(DMVPN task).
Page 49
Configure EBGP between ACME's San Francisco and San Jose sites according to the following requirements
6. R20 is the CE router and uses EBGP to connect to the managed services that are provided by the PE
routers R2 and R3
7. R20 must establish separate EBGP peering with both R2 and R3 for every VRF
8. R20 must advertise the following prefix to all of its BGP peers
123.0.0.0/8 summary-only
10.0.0.0/8 summary-only
9. R20 must advertise a default route to all of its BGP peer except to 10.120.99.1 and 10.120.99.5
Page 50
R1(config-router)#address-family ipv4
R1(config-router-af)#neighbor IBGP route-reflector-client
R1(config-router-af)#neighbor 123.2.2.2 activate
R1(config-router-af)#neighbor 123.3.3.3 activate
R1(config-router-af)#neighbor 123.6.6.6 activate
R1(config-router-af)#neighbor 123.7.7.7 activate
R1(config-router-af)#exit-address-family
R1(config-router)#exit
R1(config)#
R2 ------ Configuration
R2(config)#router bgp 12345
R2(config-router)#bgp router-id 123.2.2.2
R2(config-router)#no bgp default ipv4-unicast
R2(config-router)#neighbor 123.1.1.1 remote-as 12345
R2(config-router)#neighbor 123.1.1.1 update-source loopback 0
R2(config-router)#address-family ipv4
R2(config-router-af)#neighbor 123.1.1.1 activate
R2(config-router-af)#exit-address-family
R2(config-router)#exit
R2(config)#
R3 ------ Configuration
R3(config)#router bgp 12345
R3(config-router)#bgp router-id 123.3.3.3
R3(config-router)#no bgp default ipv4-unicast
R3(config-router)#neighbor 123.1.1.1 remote-as 12345
R3(config-router)#neighbor 123.1.1.1 update-source loopback 0
R3(config-router)#address-family ipv4
R3(config-router-af)#neighbor 123.1.1.1 activate
R3(config-router-af)#exit-address-family
R3(config-router)#exit
R3(config)#
Page 51
R6 ------ Configuration
R6(config)#router bgp 12345
R6(config-router)#bgp router-id 123.6.6.6
R6(config-router)#no bgp default ipv4-unicast
R6(config-router)#neighbor 123.1.1.1 remote-as 12345
R6(config-router)#neighbor 123.1.1.1 update-source loopback 0
R6(config-router)#address-family ipv4
R6(config-router-af)#neighbor 123.1.1.1 activate
R6(config-router-af)#exit-address-family
R6(config-router)#exit
R6(config)#
R7 ------ Configuration
R7(config)#router bgp 12345
R7(config-router)#bgp router-id 123.7.7.7
R7(config-router)#no bgp default ipv4-unicast
R7(config-router)#neighbor 123.1.1.1 remote-as 12345
R7(config-router)#neighbor 123.1.1.1 update-source loopback 0
R7(config-router)#address-family ipv4
R7(config-router-af)#neighbor 123.1.1.1 activate
R7(config-router-af)#exit-address-family
R7(config-router)#exit
R7(config)#
For EBGP
R2 ------ Configuration
R2(config)#router bgp 12345
R2(config-router)#address-family ipv4 vrf BLUE
R2(config-router-af)#neighbor 10.120.13.2 remote-as 65112
R2(config-router-af)#neighbor 10.120.13.2 activate
R2(config-router-af)#exit-address-family
R2(config-router)#
R2(config-router)#address-family ipv4 vrf GREEN
R2(config-router-af)#neighbor 10.120.12.2 remote-as 65112
R2(config-router-af)#neighbor 10.120.12.2 activate
R2(config-router-af)#exit-address-family
R2(config-router)#
Page 52
On R3 ------ Configuration
R3(config)#router bgp 12345
R3(config-router)#address-family ipv4 vrf BLUE
R3(config-router-af)#neighbor 10.120.13.6 remote-as 65112
R3(config-router-af)#neighbor 10.120.13.6 activate
R3(config-router-af)#exit-address-family
R3(config-router)#
R3(config-router)#address-family ipv4 vrf GREEN
R3(config-router-af)#neighbor 10.120.12.6 remote-as 65112
R3(config-router-af)#neighbor 10.120.12.6 activate
R3(config-router-af)#exit-address-family
R3(config-router)#
R3(config-router)#address-family ipv4 vrf INET
R3(config-router-af)#neighbor 10.120.99.6 remote-as 65112
R3(config-router-af)#neighbor 10.120.99.6 activate
R3(config-router-af)#exit-address-family
R3(config-router)#
R3(config-router)#address-family ipv4 vrf RED
R3(config-router-af)#neighbor 10.120.14.6 remote-as 65112
R3(config-router-af)#neighbor 10.120.14.6 activate
R3(config-router-af)#exit-address-family
R3(config-router)#
Page 53
Page 54
On R2
On R3
On R6
Page 55
On R7
For EBGP
On R2
Page 56
Page 57
On R3
Page 58
On R20
Page 59
Page 60
SW3 and SW4 must not establish any BGP session at any time
All four BGP routers must use their interface loopback0 as their bgp router-id
Disable the default ipv4 unicast address family for peering session establishment in all BGP routers
Configure full mesh IBGP peering between all four routers use any configuration method
R9 must be selected as the preferred exit point for traffic destined to remote AS's
R11 must be selected as the next preferred exit point in case R9 fails
No BGP speaker in AS 34567 must use network statement under the BGP router configuration.
Ensure that all the BGP next-hop is never marked as unreachable as long as interface loopback0 of
the remote peer is known via IGP
Page 61
R8(config-router)#address-family ipv4
R8(config-router-af)#neighbor 123.9.9.9 activate
R8(config-router-af)#neighbor 123.9.9.9 next-hop-self
R8(config-router-af)#neighbor 123.10.10.10 activate
R8(config-router-af)#neighbor 123.10.10.10 next-hop-self
R8(config-router-af)#neighbor 123.11.11.11 activate
R8(config-router-af)#neighbor 123.11.11.11 next-hop-self
R8(config-router-af)#exit-address-family
R8(config-router)#exit
R8(config)#
R9 ------ Configuration
R9(config)#router bgp 34567
R9(config-router)#bgp router-id 123.9.9.9
R9(config-router)#no bgp default ipv4-unicast
R9(config-router)#neighbor 123.8.8.8 remote-as 34567
R9(config-router)#neighbor 123.8.8.8 update-source loopback 0
R9(config-router)#neighbor 123.10.10.10 remote-as 34567
R9(config-router)#neighbor 123.10.10.10 update-source loopback 0
R9(config-router)#neighbor 123.11.11.11 remote-as 34567
R9(config-router)#neighbor 123.11.11.11 update-source loopback 0
R9(config-router)#bgp default local-preference 102
R9(config-router)#address-family ipv4
R9(config-router-af)#neighbor 123.8.8.8 activate
R9(config-router-af)#neighbor 123.8.8.8 next-hop-self
R9(config-router-af)#neighbor 123.10.10.10 activate
R9(config-router-af)#neighbor 123.10.10.10 next-hop-self
R9(config-router-af)#neighbor 123.11.11.11 activate
R9(config-router-af)#neighbor 123.11.11.11 next-hop-self
R9(config-router-af)#exit-address-family
R9(config-router)#exit
R9(config)#
Page 62
R10(config-router)#address-family ipv4
R10(config-router-af)#neighbor 123.8.8.8 activate
R10(config-router-af)#neighbor 123.8.8.8 next-hop-self
R10(config-router-af)#neighbor 123.9.9.9 activate
R10(config-router-af)#neighbor 123.9.9.9 next-hop-self
R10(config-router-af)#neighbor 123.11.11.11 activate
R10(config-router-af)#neighbor 123.11.11.11 next-hop-self
R10(config-router-af)#exit-address-family
R10(config-router)#exit
R10(config)#
Page 63
For EBGP
R8 ------ Configuration
R8(config)#router bgp 34567
R8(config-router)#neighbor 101.1.34.1 remote-as 10001
R8(config-router)#address-family ipv4
R8(config-router-af)#neighbor 101.1.34.1 activate
R8(config-router-af)#redistribute eigrp 34567
R8(config-router-af)#exit-address-family
R8(config-router)#exit
R8(config)#
R9 ------ Configuration
R9(config)#router bgp 34567
R9(config-router)#neighbor 102.2.34.1 remote-as 10002
R9(config-router)#neighbor 33.34.4.1 remote-as 30000
R9(config-router)#address-family ipv4
R9(config-router-af)#neighbor 102.2.34.1 activate
R9(config-router-af)#neighbor 33.34.4.1 activate
R9(config-router-af)#redistribute eigrp 34567
R9(config-router-af)#neighbor 33.34.4.1 route-map DEFAULT in
R9(config-router-af)#exit-address-family
R9(config-router)#exit
R9(config)#
R9(config)#ip prefix-list DEFAULT permit 0.0.0.0/0
R9(config)#route-map DEFAULT
R9(config-route-map)#match ip address prefix-list DEFAULT
R9(config-route-map)#exit
R9(config)#
R9(config)#router eigrp 34567
R9(config-router)#redistribute bgp 34567 route-map DEFAULT metric 100000 10 255 1 1500
R9(config-router)#exit
R9(config)#
Page 64
Page 65
On R9
On R10
On R11
Page 66
For EBGP
On R8
Page 67
On R9
Page 68
Page 69
On R10
Page 70
On R11
Page 71
Page 72
On R8
Page 73
Configure EBGP in ACME's APAC region (AS45678 and AS 65222) according to the following
requirements.
Refer Diagram 3 : BGP routing
1.
2.
3.
4.
5.
6.
7.
8.
9.
10.
SW5 and SW6 must not establish any BGP session at any time.
All BGP routers must use their interface loopback0 as the BGP router-id.
No IBGP peering session are allowed in AS 45678.
R15 must establish an EBGP peering with AS 10003 and must receive a default route as well as other
prefix.
R15 must redistribute BGP into EIGRP vice versa.
R15 must also advertise an aggregate prefix for 123.20.1.0/24 to AS 10003 and must suppress all
components prefixes.
R16 , R17 , R18 , R19 must establish an EBGP peering with AS 20003 and must receive a default route as
well as other prefix.
R16 , R17 , R18 , R19 must not advertise any prefix to AS 20003.
As long as R15 operational , R16 , R17 , R18 , R19 must prefer the EIGRP default route over the EBGP
default route.
Do not create any VRF in anywhere in order to accomplish the above requirements.
Page 74
Page 75
Page 76
On R16
Page 77
On R17
Page 78
On R18
Page 79
On R19
Page 80
Page 81
R3 ------ Configuration
R3(config)#Ip prefix-list FILTER permit 123.0.0.0/8 le 32
R3(config)#Router bgp 12345
R3(config-router)#Address-family ipv4 vrf INET
R3(config-router-af)#Neighbor 102.2.123.1 remote-as 10002
R3(config-router-af)#Neighbor 102.2.123.1 activate
R3(config-router-af)#Neighbor 102.2.123.1 prefix-list FILTER out
R3(config-router-af)#exit-address-family
R3(config-router)#exit
R3(config)#
R6 ------ Configuration
R6(config)#Ip prefix-list FILTER permit 123.0.0.0/8 le 32
R6(config)#Router bgp 12345
R6(config-router)#Address-family ipv4 vrf INET
R6(config-router-af)#Neighbor 201.1.123.1 remote-as 20001
R6(config-router-af)#Neighbor 201.1.123.1 activate
R6(config-router-af)#Neighbor 201.1.123.1 prefix-list FILTER out
R6(config-router-af)#exit-address-family
R6(config-router)#exit
R6(config)#
R7 ------ Configuration
R7(config)#Ip prefix-list FILTER permit 123.0.0.0/8 le 32
R7(config)#Router bgp 12345
R7(config-router)#Address-family ipv4 vrf INET
R7(config-router-af)#Neighbor 202.2.123.1 remote-as 20002
R7(config-router-af)#Neighbor 202.2.123.1 activate
R7(config-router-af)#Neighbor 202.2.123.1 prefix-list FILTER out
R7(config-router-af)#exit-address-family
R7(config-router)#exit
R7(config)#
Page 82
R8 ------ Configuration
R8(config)#ip prefix-list FILTER permit 123.0.0.0/8 le 32
R8(config)#Router bgp 34567
R8(config-router)#Address-family ipv4
R8(config-router-af)#Neighbor 101.1.34.1 prefix-list FILTER out
R8(config-router-af)#exit-address-family
R8(config-router)#exit
R8(config)#
R9 ------ Configuration
R9(config)#Ip prefix-list FILTER permit 123.0.0.0/8 le 32
R9(config)#router bgp 34567
R9(config-router)#address-family ipv4
R9(config-router-af)#neighbor 102.2.34.1 prefix-list FILTER out
R9(config-router-af)#exit-address-family
R9(config-router)#exit
R9(config)#
Page 83
Page 84
On R13
Page 85
On R14
Note : You will get the above result only after completing Section 3.1 & 3.2
(MPLS VPN PART 1 & PART 2)
Page 86
Configure OSPFv3 in the ACME New York office as per the following requirements.
1. Configure the OSPF process id 1 and set the router-id as interface loopback0
2. SW4 must be selected as the designated router on VLAN 34 and must have the best chance.
3. SW3 must be selected as the back-up designated router on VLAN 34 and must take over the
designated router if Switch4 is down.
Page 87
Page 88
On R11
Page 89
On SW3
On SW4
Page 90
Page 91
Page 92
Verification:On R10
Page 93
On R11
On R12
Page 94
Assume that Streaming server is connected in vlan 5 on SW5 and receiver are located at the DMVPN
spoke R18 and R19
Configure the ACME network as per the following requirements
1. Only network segments with active receivers that explicitly require the data must receive the multicast
traffic
2. Interface loopback0 of R15 must be configured as RP
3. Use a standard method of dynamically distributing the RP
4. Both R16 and R17 must participate in the multicast routing
5. For testing purpose ,Configure interface ethernet0/0 of both R18 and R19 to join group 232.1.1.1
Page 95
Page 96
Page 97
On SW6
On R15
Page 98
On R16
On R17
On R18
On R19
Page 99
On SW5
On SW6
Note : You will get the above result only after completing Section 3.3
(DMVPN task).
Page 100
Page 101
R2 ------ Configuration
R2(config)#Mpls ldp router-id loopback 0 force
R2(config)#No mpls ip propagate-ttl
R2(config)#Router ospf 12345
R2(config-router)#Mpls ldp autoconfig
R2(config-router)#exit
R2(config)#
R3 ------ Configuration
R3(config)#Mpls ldp router-id loopback 0 force
R3(config)#No mpls ip propagate-ttl
R3(config)#Router ospf 12345
R3(config-router)#Mpls ldp autoconfig
R3(config-router)#exit
R3(config)#
R4 ------ Configuration
R4(config)#Mpls ldp router-id loopback 0 force
R4(config)#No mpls ip propagate-ttl
R4(config)#Router ospf 12345
R4(config-router)#Mpls ldp autoconfig
R4(config-router)#exit
R4(config)#
Page 102
R5 ------ Configuration
R5(config)#Mpls ldp router-id loopback 0 force
R5(config)#No mpls ip propagate-ttl
R5(config)#Router ospf 12345
R5(config-router)#Mpls ldp autoconfig
R5(config-router)#exit
R5(config)#
R6 ------ Configuration
R6(config)#Mpls ldp router-id loopback 0 force
R6(config)#No mpls ip propagate-ttl
R6(config)#Router ospf 12345
R6(config-router)#Mpls ldp autoconfig
R6(config-router)#exit
R6(config)#
R7 ------ Configuration
R7(config)#Mpls ldp router-id loopback 0 force
R7(config)#No mpls ip propagate-ttl
R7(config)#Router ospf 12345
R7(config-router)#Mpls ldp autoconfig
R7(config-router)#exit
R7(config)#
Page 103
Verifcation :On R1
On R2
Page 104
On R3
On R4
Page 105
On R5
On R6
Page 106
On R7
Page 107
GREEN
BLUE
RED
YELLOW
INET
3. R6 must establish an EBGP peering with the regional SP (AS 20001) for the following VRFs
GREEN
BLUE
INET
4. R7 must establish an EBGP peering with the regional SP (AS 20002) for the following VRFs
BLUE
RED
INET
5. All ip address used for EBGP peering must pass the BGP's directly connected check
6. No BGP speaker is AS 12345 may use the network or redistribute statement under any address-family of
the BGP router configuration
7. At the end of the exam scenario the interface ethernet 0/0 of the gateway router in any remote site
must be able to connect to the interface ethernet 0/0 of any other remote gateway that belongs to AS
65111 or AS 65222
Page 108
R2 ------ Configuration
R2(config)#Router bgp 12345
R2(config-router)#Address-family vpnv4
R2(config-router-af)#Neighbor 123.1.1.1 activate
R2(config-router-af)#Neighbor 123.1.1.1 send-community extended
R2(config-router-af)#exit-address-family
R2(config-router)#exit
R2(config)#
R3 ------ Configuration
R3(config)#Router bgp 12345
R3(config-router)#Address-family vpnv4
R3(config-router-af)#Neighbor 123.1.1.1 activate
R3(config-router-af)#Neighbor 123.1.1.1 send-community extended
R3(config-router-af)#exit-address-family
R3(config-router)#exit
R3(config)#
Page 109
R6 ------ Configuration
R6(config)#Router bgp 12345
R6(config-router)#Address-family vpnv4
R6(config-router-af)#Neighbor 123.1.1.1 activate
R6(config-router-af)#Neighbor 123.1.1.1 send-community extended
R6(config-router-af)#exit-address-family
R6(config-router)#exit
R6(config)#
R7 ------ Configuration
R7(config)#Router bgp 12345
R7(config-router)#Address-family vpnv4
R7(config-router-af)#Neighbor 123.1.1.1 activate
R7(config-router-af)#Neighbor 123.1.1.1 send-community extended
R7(config-router-af)#exit-address-family
R7(config-router)#exit
R7(config)#
R2 ------ Configuration
R2(config)#router bgp 12345
R2(config-router)#Address-family ipv4 vrf BLUE
R2(config-router-af)#Neighbor 101.1.123.1 remote-as 10001
R2(config-router-af)#Neighbor 101.1.123.1 activate
R2(config-router-af)#Exit-address-family
R2(config-router)#
R2(config-router)#Address-family ipv4 vrf GREEN
R2(config-router-af)#Neighbor 101.1.123.1 remote-as 10001
R2(config-router-af)#Neighbor 101.1.123.1 activate
R2(config-router-af)#Exit-address-family
R2(config-router)#
R2(config-router)#Address-family ipv4 vrf INET
R2(config-router-af)#Neighbor 101.1.123.1 remote-as 10001
R2(config-router-af)#Neighbor 101.1.123.1 activate
R2(config-router-af)#Exit-address-family
R2(config-router)#
R2(config-router)#Address-family ipv4 vrf RED
R2(config-router-af)#Neighbor 101.1.123.1 remote-as 10001
R2(config-router-af)#Neighbor 101.1.123.1 activate
R2(config-router-af)#Exit-address-family
R2(config-router)#
Copyright@www.passccieexam.com All Right Reserved
Page 110
R3 ------ Configuration
R3(config-router)#Address-family ipv4 vrf BLUE
R3(config-router-af)#Neighbor 102.2.123.1 remote-as 10002
R3(config-router-af)#Neighbor 102.2.123.1 activate
R3(config-router-af)#Exit-address-family
R3(config-router)#
R3(config-router)#Address-family ipv4 vrf GREEN
R3(config-router-af)#Neighbor 102.2.123.1 remote-as 10002
R3(config-router-af)#Neighbor 102.2.123.1 activate
R3(config-router-af)#Exit-address-family
R3(config-router)#
R3(config-router)#Address-family ipv4 vrf INET
R3(config-router-af)#Neighbor 102.2.123.1 remote-as 10002
R3(config-router-af)#Neighbor 102.2.123.1 activate
R3(config-router-af)#Exit-address-family
R3(config-router)#
R3(config-router)#Address-family ipv4 vrf RED
R3(config-router-af)#Neighbor 102.2.123.1 remote-as 10002
R3(config-router-af)#Neighbor 102.2.123.1 activate
R3(config-router-af)#Exit-address-family
R3(config-router)#
R3(config-router)#Address-family ipv4 vrf YELLOW
R3(config-router-af)#Neighbor 102.2.123.1 remote-as 10002
R3(config-router-af)#Neighbor 102.2.123.1 activate
R3(config-router-af)#Exit-address-family
R3(config-router)#exit
R3(config)#
Page 111
R6 ------ Configuration
R6(config)#router bgp 12345
R6(config-router)#Address-family ipv4 vrf BLUE
R6(config-router-af)#Neighbor 201.1.123.1 remote-as 20001
R6(config-router-af)#Neighbor 201.1.123.1 activate
R6(config-router-af)#Exit-address-family
R6(config-router)#
R6(config-router)#Address-family ipv4 vrf GREEN
R6(config-router-af)#Neighbor 201.1.123.1 remote-as 20001
R6(config-router-af)#Neighbor 201.1.123.1 activate
R6(config-router-af)#Exit-address-family
R6(config-router)#
R6(config-router)#Address-family ipv4 vrf INET
R6(config-router-af)#Neighbor 201.1.123.1 remote-as 20001
R6(config-router-af)#Neighbor 201.1.123.1 activate
R6(config-router-af)#Exit-address-family
R6(config-router)#exit
R6(config)#
R7 ------ Configuration
R7(config)#router bgp 12345
R7(config-router)#Address-family ipv4 vrf BLUE
R7(config-router-af)#Neighbor 202.2.123.1 remote-as 20002
R7(config-router-af)#Neighbor 202.2.123.1 activate
R7(config-router-af)#Exit-address-family
R7(config-router)#
R7(config-router)#address-family ipv4 vrf RED
R7(config-router-af)#neighbor 202.2.123.1 remote-as 20002
R7(config-router-af)#neighbor 202.2.123.1 activate
R7(config-router-af)#exit-address-family
R7(config-router)#
R7(config-router)#Address-family ipv4 vrf INET
R7(config-router-af)#Neighbor 202.2.123.1 remote-as 20002
R7(config-router-af)#Neighbor 202.2.123.1 activate
R7(config-router-af)#Exit-address-family
R7(config-router)#exit
R7(config)#
Page 112
On R2
Page 113
On R3
On R6
Page 114
On R7
Page 115
Configure DMVPN phase 3 in the ACME APAC region (AS 45678 and 65222) as per the following
requirements
1.
2.
3.
4.
5.
Use the preconfigured interface tunnel 0 on all the three routers in order to accomplish this task
R17 must be configured as the hub router
R18 and R19 must be the spoke routers and must participate in the NHRP information exchange
Disable send icmp redirect message on all three tunnel 0 interfaces
Configure the following parameters on all the three tunnel 0 interfaces
6.
7.
8.
9.
Page 116
Page 117
On R17
Page 118
On R18
On R19
Page 119
Solution :-
For Phase 1
R17 ------ Configuration
R17(config)#crypto isakmp enable
R17(config)#crypto isakmp policy 10
R17(config-isakmp)#authentication pre-share
R17(config-isakmp)#encryption aes
R17(config-isakmp)#group 2
R17(config-isakmp)#exit
R17(config)#
Copyright@www.passccieexam.com All Right Reserved
Page 120
For Phase 2
R17 ------ Configuration
R17(config)#Crypto ipsec transform-set CCIEXFORM esp-aes 128
R17(cfg-crypto-trans)#mode transport
R17(cfg-crypto-trans)#exit
R17(config)#
R17(config)#crypto ipsec profile DMVPNPROFILE
R17(ipsec-profile)#set transform-set CCIEXFORM
R17(ipsec-profile)#exit
R17(config)#
Page 121
R17(config)#interface tunnel 0
R17(config-if)#tunnel protection ipsec profile DMVPNPROFILE
R17(config-if)#exit
R17(config)#
Page 122
On R18
On R19
Page 123
2. Do not include any extra spaces or any other characters as the ones shown above
R20(config)#
R20(config)#banner login *
WARNING! ACCESS RESTRICTED!*
Page 124
R20(config)#line vty 0 4
R20(config-line)#no motd-banner
R20(config-line)#exit
R20(config)#exit
R20#quit
NOTE : After WARNING! ACCESS RESTRICTED! do not enter or space . You can use * symbol or
return button or type m to come out
Page 125
Page 126
Page 127
Page 128
On R20
Page 129
Page 130
On R20
Note :-
Page 131
1. The output shown below must be seen on R17 during 10 sec after R15 successfully pings interface
loopback 0 of R19
SrcIPaddress
123.20.1.9
DstIf
Tu0*
DestIPaddress
123.19.19.19
Pr SrcP
01 0000
DstP
0800
Bytes
500
Page 132
On R17
Page 133
All NTP traffic must be sourced and destined to interface loopback 0 of the
corresponding devices
SW3(config)#interface loopback 0
SW3(config-if)#ntp disable ip
SW3(config-if)#exit
SW3(config)#
SW3(config)#ntp peer 2001:CC1E:BEF:0:123:10:10:10 version 4
SW3(config)#ntp peer 2001:CC1E:BEF:0:123:12:12:12 version 4
Page 134
Page 135
Page 136