mardi 24 août 2010

IPExpert V2 Lab17

1.1 Vty timeout

Bonehead error, timeout for vty is exec-timeout and not session-timeout used for physical

2.5 Fallback bridging

Not available on dynamips but permits to bridge between 2 vlan for non IP protocols :

bridge 1 proto vlan-bridge
int vlan X
bridge-group 1
int vlan Y
bridge-group 1

4.0 Cisco RIP timer

Task was about disabling the Cisco defined RIP timer, which is holdown :
timers basic 30 180 0 180

4.3 Forbidden RIP to accept routes from future gateway

I used a distribute-list or offset-list, other solution was a distance default of 255 except for the current neighbor.

6.3 OSPF

DR/BDR election timeout : configured by the dead-intervall timer !
Make an ospf neighbor prefered without using cost or bandwidth : AD of course :

distance 109 gateway acl

6.4 OSPF Misc

LSA expiration in DB : configured by pacing on lsa-group

No Null0 with summarization : no discard-route

7.0 BGP

An AS with 2 routers peered with iBGP, each as one eBGP peer, sync and IGP redistribution is forbidden.
Due to sync rule, an iBGP learnt route will not be installed if it's not learnt by an IGP. So eBGP learnt root from one routers will no be learnt by the other thrue iBGP. The solution is using confederation, as sub-as peering become eBGP like peering.


7.5 BGP Community override

The task was to prevent prefix to be sent out of AS (no-export community) except for one router. Only way to do that is re-write the prefix on inbound for this router (internet community)

Aucun commentaire:

Enregistrer un commentaire