ccnp switch interview questions and answers
-
- 1016 Reviews
For specific supported equipment, see the official CISCO documentation.
Default seed metric
Catos port switch ID in the default priority 32 (priority . 6 th 'bit ) , the IOS switch default 128 (priority field . 8 bits)
BGP table version is 3, local router ID is 4.4.4.4
?
Wherein SW1 is as follows:
After SW3 receives this message, it knows that SW2 no longer has vlan10 users, and no longer needs vlan10 traffic, so it will trim vlan10 on its own FA0/22 port :
TCAM table
10 FastEthernet0/1
Port
Cc01.043c.0000 (10.1.1.252)
Write multiple commums in the same line, such as ip community-list 1 permit no-export 12:1111 does not take effect, can not delete these two values
*>i100.0.2.0/24
RIP and OSPF
Switch(config)# vlan 10
Reposted FAQ 49
Network
If there is an EBGP connection between R2 , then a routing loop occurs, and R1 and R2 will receive the summary route and accept the routing update. This is because this summary route does not carry any information about AS100 and AS200 .
Set ip address prefix-list
--------------
Remarks
Neighbor xxx password xxx
For 802.1D , when a port is elected as the designated interface, which from blocking to forwarding at least 30S of time. However, in RSTP , the proposal/Agreement mechanism enables the interface to complete a fast,ccnp switch interview questions and answers, reliable transition in seconds.
VTP configuration
Origin IGP, metric 0, localpref 100, valid, internal
Y
Gateway of last resort is not set 9.0.0.0/24 is subnetted, 2 subnets
If R1 turns off auto-summary and network 1.1.1.0 mask 255.255.255.0 , then R2 can learn BGP route 1.1.1.0/24
Neighbor IBGP_peers update-source loopback0 neighbor IBGP_peers password cisco
?
Switched network management
Match ip address 2 set metric 3
[123].[7-9]
Ip address 10.1.45.4 255.255.255.0
Hostname R1 interface s0/0
abbreviation
SW1(config-if)# switchport trunk allowed vlan ?
FastEthernet FastEthernet IEEE 802.3
COMMUNITY attribute is set . 4 th 8 value bit group, RFC1997 predetermined front 2B represents AS number, after 2B represents the basis for management purposes set identifier, the format of AA : NN , and CISCO default display format is NN : AA , may be used The global configuration command ip bgpcommunity new-format changes the CISCO default format to RFC format.
Acl-match matchlog —Logs packets based on the DAI ACL configuration. If you specify the
1-9, 11-4094
Route reflection clusters include reflectors and their clients
Router bgp 100
2
Origin file flash:CCIE.txt
Incomplete ? Learned from other sources (confirm that the source of the route is incomplete), the re-routed origin is the tag
1.1.1.1 (metric 129) from 4.4.4.4 (4.4.4.4)
Access-list 1 permit 172.16.1.0 route-map unsupp permit 10 match ip address 11
If the route is learned from other neighbors, the default value (locally the route) is 0.
Network
A VLAN divided into several separate VLAN , the VLAN use the same IP network segment.
Both SW1 and SW2 can learn, and three-year-olds can do it.
Device ID
Preferably EBGP route
As you can see, the route carries the atomic-aggregate attribute, which is used to inform the downstream neighbor that this is the route attribute that summarizes the route and loses the detail. At the same time, the aggregator attribute identifies the summary location ( the RouterID of the AS and the summary router ).
The greater the weight , the more priority
DAI configuration example
9.
The configuration of R3 is as follows:
Generally, it is 60-240 seconds longer than the invalid timer . If this time also expires, the routing entry is completely deleted. Cisco default 60s (note than invalidtimer multi- 60s ), RFC default 120s
3.3.3.3
10.1.25.2
Network
Ip as-path access-list 1 permit .* router bgp 300
2 : RIP-2 .
FastEthernet1/0
AD value and back door
To 100 end of the AS_PATH , which is the route originated in 100AS route
During the migration, the router running DUAL AS can establish EBGP with the external AS using both the primary AS and the secondary AS.
Paths: (2 available, best # 2, table Default-IP-Routing-Table) Flag: 0x820
Display all BGP routes advertised to a specific neighbor
10.1.12.2
Static route associated with the outbound interface
The access layer switch uses a dual link to connect to two aggregation devices to form a Layer 2 environment with physical link redundancy, which solves the problem of single link failure.
10.1.12.1 from 10.1.12.1 (1.1.1.1)
Non-default (manually configured non-default) priority and cost unchanged
Ip dhcp relay information trust-all
For example, the following three types of point-to-point transmission services:
Redistribute ospf 3 subnets route-map OSPF3to2
Bytes
Switchport access vlan 100 interface fast0/24
Vlan range and mapping
* i100.0.1.0/24
Rule verification (the AS number in the federation does not participate in the AS_PATH length calculation)
TYPE DHCP-SNOOPING VERSION 1
Protocol Interface
If there is an error, enter the OpenConfirm state.
Bgp deterministic-med
technical background
Remote-ID suboption fields
Neighbor 5.5.5.5 update-source Loopback0 no auto-summary
R1(config-router)# network 192.168.12.1 0.0.0.0 area 0 R1(config-router)# distribute-list 1 out
Two routes, on R2 we introduce these two routes using re-release :
10.1.25.2
If the TCP is successfully established, the BGP process sends an Open message to the neighbor and enters Opensent.
– LoopGuard and RootGuard cannot be enabled at the same time
The direct result of this command is that the metric of 192.168.12.0 in R3's original routing table is 30720 , but now it is 10000 , which becomes 40720 . We see that after the offset command is configured , what actually changes is the DLY that is updated to the neighbor . Because it is true that DLY is the best, the default
Vlans allowed and active in management domain
Create secure addresses through dynamic learning, manual configuration, and stciky
100 i
Port number 520
Topology change process
R2(config-router)# distribute-list 1 in fa0/0
When an RSTP switch receives a BPDU with the TC bit set , it will:
Modify the TAG of all external LSAs generated by the ASBR .
VLAN IDs of the allowed VLANs when this port is in trunking mode add VLANs to the current list
Management VLAN of the Layer 2 switch
Abc*d
Produced when the network topology changes.
R2(config-router)# redistribute os 1 metric 100000 100 255 1 1500
Let's take a look at the role of these well-known values of community :
Let's analyze that SW1 inserts the DHCP request message from the PC into option82 and then sends it to SW2 . Via SW2
If the aggregate-address does not contain any keywords, the details are also passed, and the summary route is also passed.
Distribute-list
A advertises the detailed route to B , B advertises the detailed route to C and D , and C advertises the summary route. At this time, the summary route will be transmitted to B in addition to being notified to D , and this may cause problems. Therefore, you need to filter the summary route on the IP distribution-list x of neighbor B on C. Otherwise, a routing loop will occur.
length
Related points 51
SW1(config-if)# switchport trunk encapsulation dot1q SW1(config-if)# switchport mode trunk
Once the portfast port is connected to the device, the interface can bypass the listening and learning states and enter the forwarding state directly .
Through AS_PATH affect route choice 14
Show run | in route
Next, we SW2 on the vlan10 port removed, directly in fa0 / 2 on the no switchport access vlan
100 i
2 : RIP-2 ;
The spanning tree topology in the network is attached to the timer of the root bridge, and the root passes the timer in the BPDU to all switches on the second layer.
BPDU packet
Configure the switch to verify that the source MAC address in a DHCP packet received on untrusted ports matches the client hardware address in the packet. The default is to verify that the source MAC address matches the client hardware address in the packet.
Router ospf1
Clear the dynamically learned security address entries on the interface.
/ / Is to shield the route from the RIP re-released in addition to 1.1.1.0 , and re-release the local direct connection
Switch(config-if)# no shutdown
R4#sh ip b
Sw(config)#vlan 202
Aggregate-address 172.16.0.0 255.255.0.0 as-set summary-only advertise-map test
Route-map cisco permit 20 match ip address 2 set metric 10
R11#sh ip ro 8.8.8.0
R4#sh ip b
Active
Configure the SVI interface corresponding to the VLAN .
Provides access to physical links.
100
ORIGINATOR_ID and CLUSTER_LIST
Configuration example
inQ number of messages waiting to be processed from this neighbor
To other neighbors
Note inconsistent with err-diasble difference is, ERR-disable will disable off the entire interface, and inconsistentport is for a particular VLAN 's.
Now let 's do the following configuration on R2 :
ipAddress
Note that this modification will take effect on all routes sent by R5 (the weight of all routes will become 100 ), and
LocPrf
As mentioned above, the secure address entry formed by the dynamically learned MAC address of the interface will lose the secure address entries formed by the dynamically learned MAC after the interface is up/down , but all interfaces are used. The switchport port-security mac-address is manually configured and the workload is too large. Therefore, this sticky mac address allows us to turn these dynamically learned MACs into a "sticky state " . It can be simply understood that I will learn dynamically, and after I learn, I will glue you up to form a "static". "(Effectively SecureSticky ) entries.