ENARSI SA Troubleshooting - ILM
ENARSI SA Troubleshooting - ILM
ENARSI SA Troubleshooting - ILM
Instructor Note: Red f ont color or gray highlights indicate text that appears in the instructor copy only.
Topology
Addressing Table
Device Interface IPv4 Address/Mask IPv6 Address/Prefix Length Link-Local Address
R1
G0/0/1 10.165.249.1/24 2001:db8:249::1/64 f e80::1:2
R1
Loopback 0 10.0.0.1/24 2001:db8:10::1/64 f e80::1:3
R1
Loopback 1 10.165.248.1/24 2001:db8:248::1/64 f e80::1:4
R2
G0/0/1 209.165.201.2/24 2001:db8:201::2/64 f e80::2:2
R2
Loopback 0 172.16.0.1/24 2001:db8:172::1/64 f e80::2:3
R2
Loopback 1 209.165.224.1/24 2001:db8:224::1/64 f e80::2:4
© 2020 - 2020 Cisco and/or its affiliates. All rights reserved. Cisco Public Page 1 of 21 www.netacad.com
ENARSI Skills Assessment - Troubleshooting
R3
G0/0/1 192.168.241.1/24 2001:db8:241::1/64 f e80::3:2
R3
Loopback 0 192.168.0.1/24 2001:db8:192::1/64 f e80::3:3
R3
Loopback 1 192.168.240.1/24 2001:db8:240::1/64 f e80::3:4
D1
VLAN 250 10.165.250.1/24 2001:db8:24a::1/64 f e80::d1:2
D1
VLAN 251 10.165.251.1/24 2001:db8:24b::1/64 f e80::d1:3
D2
VLAN 242 192.168.242.1/24 2001:db8:242::1/64 f e80::d2:2
D2
VLAN 243 192.168.243.1/24 2001:db8:243::1/64 f e80::d2:3
A1 VLAN 250 10.165.250.2/24 2001:db8:24a::2/64 f e80::a1:1
Objectives
Troubleshoot network issues related to the conf iguration and operation of routing protocols.
Background / Scenario
This is the same topology that you built in Part 1 of the ENARSI SA. In this topology, R1 and D1 are EIGRP
neighbors and R3 and D2 are OSPF neighbors. R1, R2, and R3 are all speaking BGP f or their respective
ASNs. Switch A1 is supporting host access f or a AAA server. You will be loading conf igurations with
intentional errors onto the network. Your tasks are to FIND the error(s), document your f indings and the
command(s) or method(s) used to f ix them, FIX the issue(s) presented here and then test the network to
ensure both of the f ollowing conditions are met:
1) the complaint received in the ticket is resolved
2) f ull reachability is restored
Note: The routers used with CCNP hands-on labs are Cisco 4221 with Cisco IOS XE Release 16.9.4
(universalk9 image). The switches used in the labs are Cisco Catalyst 3650 with Cisco IOS XE Release
16.9.4 (universalk9 image) and Cisco Catalyst 2960 with Cisco IOS Release 15.2(2) (lanbasek9 image).
Other routers, switches, and Cisco IOS versions can be used. Depending on the model and Cisco IOS
version, the commands available and the output produced might vary f rom what is shown in the labs. Ref er to
the Router Interf ace Summary Table at the end of the lab f or the correct interf ace identif iers.
Note: Make sure that the devices have been erased and have no startup conf igurations. If you are unsure,
contact your instructor.
Note: The def ault Switch Database Manager (SDM) template on a Catalyst 2960 does not support IPv6. You
must change the def ault SDM template to the dual-ipv4-and-ipv6 def ault template using the sdm prefer dual-
ipv4-and-ipv6 default global conf iguration command. Changing the template will require a reboot.
© 2020 - 2020 Cisco and/or its affiliates. All rights reserved. Cisco Public Page 2 of 21 www.netacad.com
ENARSI Skills Assessment - Troubleshooting
Instructor Note: Ref er to the Instructor Lab Manual f or the procedures to initialize and reload devices.
Required Resources
• 3 Routers (Cisco 4221 with Cisco IOS XE Release 16.9.4 universal image or comparable)
• 2 Switches (Cisco 3650 with Cisco IOS XE Release 16.9.4 universal image or comparable)
• 1 Switch (Cisco 2960 with Cisco IOS Release 15.2(2) lanbasek9 image or comparable)
• 3 PCs (Choice of operating system with terminal emulation program installed)
• 1 PC (Choice of operating system with a server running conf igured RADIUS (Optional))
• Console cables to conf igure the Cisco IOS devices via the console ports
• Ethernet and serial cables as shown in the topology
Scenario
You had the network working to specif ications and took a week of f . While you were gone, a junior
administrator and a security engineer were tasked to improve the network. The opposite occurred. Now you
are tasked with f ixing the network.
The instructions the junior administrator and security engineer were given were as f ollows:
1. Reduce the number of TCP sessions between R1 and R3.
2. Apply IPv4 and IPv6 f ilters to the outward -f acing interf aces on R1 and R3 to ensure that inbound
traf f ic sourced f rom their local networks is dropped.
3. Reduce the size of the EIGRP routing table on R1.
4. Reduce the number of route entries R1 is sending to R2.
5. Incorporate AAA using the AAA server at 209.165.251.5 to secure remote access to all devices in the
AS 10 and AS 192 networks.
They did not document things as they were supposed to, so all you have been told is things are not working
as they should be. You need to f ix all of this as soon as possible!
Use the commands listed below to load the conf iguration f iles f or this skills assessment:
Instructor Note: Commands f or uploading the conf iguration are provided at the end of this document.
Device Command
• Console Passwords on all devices are cisco12345. If a username is required, use admin.
• Remote access should be available using the username raduser and password upass123.
Instructor Note: If you are using a RADIUS server, update the RADIUS username and password as necessary.
© 2020 - 2020 Cisco and/or its affiliates. All rights reserved. Cisco Public Page 3 of 21 www.netacad.com
ENARSI Skills Assessment - Troubleshooting
• PC2 must be conf igured with static addresses as shown in the topology diagram/addressing table.
PC1, PC3, and PC4 will dynamically acquire IPv4 and IPv6 addresses.
• When you have f ixed the ticket, change the MOTD on EACH DEVICE using the f ollowing command:
banner motd # This is $(hostname) FIXED Skills Assessment #
• Save the conf iguration by issuing the wri command (on each device).
• Inf orm your instructor that you are f inished.
• Af ter the instructor approves your solution, issue the reset.now privileged EXEC command. This
script will clear your conf igurations and reload the devices.
Instructor Notes:
This skills assessment contains several intentional errors. The list below is mapped to the tasks given the junior
administrator and security engineer:
1. Reduce the number of TCP sessions between R1 and R3.
The junior administrator did not complete the conf iguration - at both R1 and R3, the ebgp-multihop
command was excluded. The commands to f ix this error are:
Router R1
conf t
router bgp 10
neighbor 192.168.0.1 ebgp-multihop 3
neighbor 2001:db8:192::1 ebgp-multihop 3
exit
end
Router R3
config t
router bgp 192
neighbor 10.0.0.1 ebgp-multihop 3
neighbor 2001:db8:10::1 ebgp-multihop 3
exit
end
2. Apply IPv4 and IPv6 f ilters to the outward -f acing interf aces on R1 and R3 to ensure that inbound traf f ic
sourced f rom their local networks is dropped .
R3 has the default-information originate command, but it does not seem to be working. D2 does not
see the def ault route. R2 is sending it, as R1 has it. The issue is that the MY-X-NETWORKS f ilter at the
G0/0/0 ingress is denying 0.0.0.0. The filters configured on R1 are correct. The commands to f ix this on
R3 are as f ollows:
config t
ip access-list standard MY-4-NETWORKS
no 30
exit
ipv6 access-list MY-6-NETWORKS
no permit ipv6 any any
exit
end
© 2020 - 2020 Cisco and/or its affiliates. All rights reserved. Cisco Public Page 4 of 21 www.netacad.com
ENARSI Skills Assessment - Troubleshooting
© 2020 - 2020 Cisco and/or its affiliates. All rights reserved. Cisco Public Page 5 of 21 www.netacad.com
ENARSI Skills Assessment - Troubleshooting
Router Model Ethernet Interface #1 Ethernet Interface #2 Serial Interface #1 Serial Interface #2
Note: To f ind out how the router is conf igured, look at the interf aces to identif y the type of router and how many
interf aces the router has. There is no way to ef f ectively list all the combinations of conf igurations f or each router
class. This table includes identif iers f or the possible combinations of Ethernet and Serial interf aces in the device.
The table does not include any other type of interf ace, even though a specif ic router may contain one. An
example of this might be an ISDN BRI interf ace. The string in parenthesis is the legal abbreviation that can be
used in Cisco IOS commands to represent the interf ace.
End of document
© 2020 - 2020 Cisco and/or its affiliates. All rights reserved. Cisco Public Page 6 of 21 www.netacad.com
ENARSI Skills Assessment - Troubleshooting
© 2020 - 2020 Cisco and/or its affiliates. All rights reserved. Cisco Public Page 7 of 21 www.netacad.com
ENARSI Skills Assessment - Troubleshooting
© 2020 - 2020 Cisco and/or its affiliates. All rights reserved. Cisco Public Page 8 of 21 www.netacad.com
ENARSI Skills Assessment - Troubleshooting
© 2020 - 2020 Cisco and/or its affiliates. All rights reserved. Cisco Public Page 9 of 21 www.netacad.com
ENARSI Skills Assessment - Troubleshooting
© 2020 - 2020 Cisco and/or its affiliates. All rights reserved. Cisco Public Page 10 of 21 www.netacad.com
ENARSI Skills Assessment - Troubleshooting
interface loopback 1
ip address 209.165.224.1 255.255.255.0
ipv6 address fe80::2:4 link-local
ipv6 address 2001:db8:224::1/64
no shutdown
exit
ip route 0.0.0.0 0.0.0.0 null0
ipv6 route ::/0 null0
router bgp 172
no bgp default ipv4-unicast
bgp router-id 4.6.172.2
neighbor 209.165.200.1 remote-as 10
neighbor 209.165.201.1 remote-as 192
neighbor 2001:db8:200::1 remote-as 10
neighbor 2001:db8:201::1 remote-as 192
address-family ipv4 unicast
neighbor 209.165.200.1 activate
neighbor 209.165.201.1 activate
network 172.16.0.0 mask 255.255.255.0
network 209.165.224.0
network 0.0.0.0 mask 0.0.0.0
exit
address-family ipv6 unicast
neighbor 2001:db8:200::1 activate
neighbor 2001:db8:201::1 activate
network 2001:db8:172::/64
network 2001:db8:224::/64
network ::/0
exit
exit
line con 0
logging synchronous
exec-timeout 0 0
exit
line vty 0 4
login local
transport input telnet
exec-timeout 5 0
exit
alias exec reset.now tclsh flash:/enarsi/reset.tcl
end
}
tclquit
© 2020 - 2020 Cisco and/or its affiliates. All rights reserved. Cisco Public Page 11 of 21 www.netacad.com
ENARSI Skills Assessment - Troubleshooting
© 2020 - 2020 Cisco and/or its affiliates. All rights reserved. Cisco Public Page 12 of 21 www.netacad.com
ENARSI Skills Assessment - Troubleshooting
© 2020 - 2020 Cisco and/or its affiliates. All rights reserved. Cisco Public Page 13 of 21 www.netacad.com
ENARSI Skills Assessment - Troubleshooting
network 2001:db8:192::/64
exit
exit
router ospfv3 1
router-id 0.0.192.3
address-family ipv4 unicast
passive-interface default
no passive-interface g0/0/1
default-information originate
exit
address-family ipv6 unicast
passive-interface default
no passive-interface g0/0/1
default-information originate
exit
exit
interface g0/0/1
ospfv3 1 ipv4 area 0
ospfv3 1 ipv6 area 0
exit
interface loopback 0
ip ospf network point-to-point
ipv6 ospf network point-to-point
ospfv3 1 ipv4 area 0
ospfv3 1 ipv6 area 0
exit
interface loopback 1
ip ospf network point-to-point
ipv6 ospf network point-to-point
ospfv3 1 ipv4 area 0
ospfv3 1 ipv6 area 0
exit
aaa new-model
radius server MY-RADIUS
address ipv4 10.165.251.5 auth-port 1812 acct-port 1813
key $trongPass
exit
aaa authentication login VTY-CONTROL group radius local
line con 0
logging synchronous
exec-timeout 0 0
exit
line vty 0 4
transport input telnet
exec-timeout 5 0
© 2020 - 2020 Cisco and/or its affiliates. All rights reserved. Cisco Public Page 14 of 21 www.netacad.com
ENARSI Skills Assessment - Troubleshooting
© 2020 - 2020 Cisco and/or its affiliates. All rights reserved. Cisco Public Page 15 of 21 www.netacad.com
ENARSI Skills Assessment - Troubleshooting
© 2020 - 2020 Cisco and/or its affiliates. All rights reserved. Cisco Public Page 16 of 21 www.netacad.com
ENARSI Skills Assessment - Troubleshooting
aaa new-model
radius server MY-RADIUS
address ipv4 10.165.251.5 auth-port 1812 acct-port 1813
key $trongPass
exit
aaa authentication login VTY-CONTROL group radius local
line con 0
logging synchronous
exec-timeout 0 0
exit
line vty 0 4
transport input telnet
exec-timeout 5 0
login authentication VTY-CONTROL
exit
alias exec reset.now tclsh flash:/enarsi/reset.tcl
end
}
tclquit
© 2020 - 2020 Cisco and/or its affiliates. All rights reserved. Cisco Public Page 17 of 21 www.netacad.com
ENARSI Skills Assessment - Troubleshooting
spanning-tree portfast
switchport access vlan 242
no shutdown
exit
interface g1/0/24
switchport mode access
spanning-tree portfast
switchport access vlan 243
no shutdown
exit
interface vlan 242
ip address 192.168.242.1 255.255.255.0
ipv6 address fe80::d2:2 link-local
ipv6 address 2001:db8:242::1/64
no shutdown
exit
interface vlan 243
ip address 192.168.243.1 255.255.255.0
ipv6 address fe80::d1:3 link-local
ipv6 address 2001:db8:243::1/64
no shutdown
exit
ip dhcp excluded-address 192.168.242.1 192.168.242.5
ip dhcp pool VLAN242DHCP
network 192.168.242.0 255.255.255.0
default-router 192.168.242.1
exit
ip dhcp excluded-address 192.168.243.1 192.168.243.5
ip dhcp pool VLAN243DHCP
network 192.168.243.0 255.255.255.0
default-router 192.168.243.1
exit
router ospfv3 1
router-id 0.0.192.2
address-family ipv4 unicast
passive-interface default
no passive-interface g1/0/11
exit
address-family ipv6 unicast
passive-interface default
no passive-interface g1/0/11
exit
exit
interface g1/0/11
ospfv3 1 ipv4 area 0
© 2020 - 2020 Cisco and/or its affiliates. All rights reserved. Cisco Public Page 18 of 21 www.netacad.com
ENARSI Skills Assessment - Troubleshooting
© 2020 - 2020 Cisco and/or its affiliates. All rights reserved. Cisco Public Page 19 of 21 www.netacad.com
ENARSI Skills Assessment - Troubleshooting
interface f0/23
switchport mode access
switchport access vlan 250
spanning-tree portfast
no shutdown
exit
interface f0/24
switchport mode access
switchport access vlan 251
spanning-tree portfast
no shutdown
exit
interface vlan 250
ip address 10.165.250.2 255.255.255.0
ipv6 address fe80::a1:1 link-local
ipv6 address 2001:db8:24A::2/64
no shutdown
exit
ip default-gateway 10.165.250.1
interface f0/23
shutdown
exit
interface range f0/1-3
switchport mode trunk
channel-group 1 mode active
no shutdown
exit
line con 0
logging synchronous
exec-timeout 0 0
exit
aaa new-model
radius server MY-RADIUS
address ipv4 10.165.251.5 auth-port 1812 acct-port 1813
key $trongPass
exit
aaa authentication login VTY-CONTROL group radius local
line con 0
logging synchronous
exec-timeout 0 0
exit
line vty 0 4
transport input telnet
exec-timeout 5 0
login authentication VTY-CONTROL
© 2020 - 2020 Cisco and/or its affiliates. All rights reserved. Cisco Public Page 20 of 21 www.netacad.com
ENARSI Skills Assessment - Troubleshooting
exit
alias exec reset.now tclsh flash:/enarsi/reset.tcl
end
}
tclquit
© 2020 - 2020 Cisco and/or its affiliates. All rights reserved. Cisco Public Page 21 of 21 www.netacad.com