Sunday, September 30, 2012

PFR REVIEW QUESTIONS

PFR
What is the difference between load balancing and load sharing?
What is the job of the mc in pfr?
What is the job if border routers?
what are the requirements for pft as regards internal and external interface?
Is this requirement per device?
what happens if pfr is not specfied on interface?
what is the requirement for routing in pfr?
how would you define a border router connecting to master of 2.2.2.2?
How could you define a md5 authentication for this?
what do we need to define on mc for border router r1 1.1.1.1 and border router 3.3.3.3
how can you check on the master if the connections have been successifully established?
what would you use to define max difference of 20 percent in utilization?
What is different between passive and active mode + which existing ios features do the use?
What is the default monitoring in pfr??
How could we say to only monitor utilization?
what is the default mode control for pfr?
How can we change this to be active in routing?
What is the backoff value in pfr?
how would set pfr to automatic learning based on throughput
how would set so it continiously monitors does not stop and take breaks
What is the default high utilization?
What tag does pfr assign the static routes?
what can we use this tag for ??
how could we tell under the auto learn so that evaluates bgp table rather then the cef fib?
What is the parent route issue in pfr??
What types of routes can parent routes be?
how could we tell pfr to only auto learn www?
How could we in auto learn tell pfr to only looking icmp traffic destined to 5.5.5.5?
how do you turn on logging for pfr?
how can we disable auto learn
how could we tell pfr to aggregate /24
what is a learn list + how do we define it
How can we use pbr mode?
how do we match traffic in pbr mode?
what is important about the acl in pbr mode?
what must we set?
how do you view the pbr route map on the border routers?
what are the requirement when we have multiple border routers?
what do we need to define on the oer master for this interface?
how could we change pfr only to account for delay not throught put?
what is the difference betweeen the relative delay threshold vs the abosultes?
what is the mode fast?
what is a link group + how do we define links groups?
what is flexible netflow?
what 4 steps to we need to take to apply a flexible netflow?
What are the difference between a match and collect statment?
how can we define flexible netflow to integrate with pfr

Wednesday, September 26, 2012

Security Review

Security Review
How would we set authentication to the console to use the local configured username + password??
How could we configure authentication by telnet to only need a password?
How could we configure user trying to go into enable mode to be autheticated by tacacs and fall back to local?
How could we configure a failed login to generate Sorry Authentication failed?
How do we define tacacs server with a password of cisco which use source int lo0?
how could we authorize the console connections by tacacs then fall back to local?
how could we authorize locally all ip options on interface to user with privelege level 6
How can we use rbac to give a specfic access to a user named EOghan to allow him run all debug commands??
How do you combine rbac access??
how can we do lock out after 3 attempts??
What is quietmode and how can we configure away around it?
how could we get a failure logon every 3 attempts
how could we delay each login attempt by 4 tries to prevent dictionary attacks?
Limit a user named Eoghan so he can only telnet from a router to 1.1.1.1 port 80?
Limit telent sessions inbound to router only from 2.2.2.2?
how would you match even 2 octet out of these 5 address 112.1.0.0 112.2.0.0 112.3.0.0 112.4.0.0 112.4.0.0 112.4.0.0 112.5.0.0?
What are the traceroute udp ports?
What is used path mtu discovery process what message is generated?
What error/return message are generated by icmp?
How can you chance the logging of an access list to log every 4th hit?
How can you stop icmp from sending back unreachable info?
How could you drop traffic if entered a specfic interface and leaving on another sepcfic interface so limit traffic to say enters s0/0 and leaves fa0/0 only?
How can we allow return traffic using reflexive accesslist say icmp?
When denying traffic inbound what must we take into account?
why do we not need to take this into account outbound?
If i ping from a router which has a reflect access list how can i account for this with reflect acl?
I want to give access to http server 1.1.1.1 but only if user authenticated to a router 2.2.2.2 how would i configure?
I want to set so the connection timeout every 15 min?
i want to limit access to the web server 1.1.1.1 from a user in 3.3.3.3 subnet to weekdays 6pm to 9am?
If i have 4 (1 to 4) switches connected in full mesh i want to implement vlan access map to filter where should i implement this??
how could create a vlan access map to allow tcp but deny everything else and apply to vlan 20??
In port security what do we need to watch out for with sub interfaces in different vlans?
How do you set an time out on port security enteries??
How do you set port security mode whether it shutdown port etc?
Which action logs and which action does not log when port-security rejects?
How can we configure auto recover for port security shutdown ports?
Where do you enable dhcp snooping trust?
How can we protect dhcp database again reboot??
How could i limit request on a non trusted port?
What does dhcp snooping do with giaddr?
what issues does it cause and how can we resolve?
How do we put a static entry for 150.1.1.1 to mac 000d.2fee.bcef.0000 in arp inspection and when would we do this?
how do we enable arp inspection and include the static entry?
What is ip source guard for?
How do we create a static entry for 150.2.2.2 in ip source guard?
how do we enable ip source guard?
On layer 2 port appy a filter to int gi1/0/1 only allow ethertype 0x806 and icmp?
what is the command to put a port under 802.1x control at interface mode and at global config mode?
how would set 802.1x to send request to radius server?
how could we limit icmp to 100 pps in CPP?
what the differences between cpp and cppr?
What are the 3 interfaces CPR?
How could we match all closed ports with CPPR?
What is notable about routing protocols and ports?
How could we apply que limit to http of 50?
is there a way of globally not allowing ip options?
How could we interface level disallow ip source routing?

using nbar match any http request which end .pfd or .txt and drop?
What is the difference between URPF strict and loose mode?
Why would we use loose?
what the command to configure each?
What modes are in tcp intercept + how do they difffer?
how could you configure a passive mode to limit icomplete connections to 100 if they drop below 80 reallow?
Also set connection timeout?
how could allow return traffic for ftp using cbac what is special about ftp that reflexive would not work?
How can we set a global setting for CBAC for dns timeout 10 seconds compared to interface specfic??
How would account for custom ports in cbac say 8008 for internet ?
How do we apply a cbac to an interface?
how do you define secuirty zone and inside zone?
how could we allow return traffic zbfw?
how do we assign an interface to a zone?
can inside speak to outside by default?
can outside speak to inside by default ?
how would we allow outside transit traffic into inside?
How do apply a parameter map + what is it?
why would we need a key for cisco ips defentions?
what if the key was on another router how could we copy it accoss?

how could we limit ips to check traffic to host 5.5.5.5

how could we tell ips to syslog violations
how could we disable all signatures + why would we do this?
how can we enable individual signature
how do we apply to interface ips
how do you copy a .pkg into your ips database?
how can we make event action in ips?
if all host are in vlan 20 which is isolated can they communicate to each other?
if all host are in vlan 30 which is communtity can they speak to each other + can they speak to communtiy vlan 40?
how would assign primary vlan?
how can you configure the above vlan 10 the primary port?
what is limit with protected ports?
when unkown traffic comes in will it floood out on protect port + could another protected recieve how do we get around this
problem?
how do you cofigure storm control to lime unicast to 80 percent of the bw ??



Tuesday, September 18, 2012

QOS REVIEW QUESTIONS




QOS REVIEW QUESTIONS

what is the formula for IOS weight for WFQ??
What is the virtual scheduling time + how is calculated??
What is the queue tail time for new packet in new flow??
What is CDT in wfq??
How do we enable wfq on interface??
Using legacy tools  how would reserve 128kb for ports 16384 to 32766?
what weight does reserve get in fair que??
Where would you see weighting in the cli?
with legacy tools how would priorise 128 kb for ports 16384 to 32766?
DO legacy custom que to allow for 3 protocols rtp (60 byte packets) icmp (100 byte packets) TCP 160 byte packets
Rtp should get 30 percent icmp should get 10 % tcp should 60 percent??
What is assigned to que 0 in custom queing??
How do we assign a priority que to the legacy custom que??
How do we legacy priority queing giving we want udp rip as the top http in middle lowest would be traffic going to 10.229.11.11
How does priority queing work as regards allocation to ques?
Enable legacy wred the weight constant should be 4 it should start dropping at 11 packets and tail drop 12 for prec 6
What is flow based wred and how do we enable?
What goes to the spd extended headroom que?
what goes to spd headroom que??
what happens if either que fills??
How would you set threshold for spd?
What is the difference between spd in normal mode and spd in aggressive mode?
What payload compression uses min cpu but high memory + how do you configure?
what payload compression uses high cpu but little memory + how do you configure
How do you enable payload compression of particular dlici??
How could we get around an issue with small packets + large packet headers for both tcp and rtp??
How do you apply this and how do you limit connections??
How do we configure multilink and interleave to max delay of 10ms for packets
What is the formula for fragment size?
How do you configure legacy traffic shaping first effecting all traffic and secondly affecting subset?
Whats the bc in GTS if you have CIR 128k and TC 10 ms?
WHat is the problem with setting bc 1000 bytes if your average packet is 1500 bytes?? How does IOS get around this
problem?
What is solution to deal with under sending as periods of quietness is the transmission?
Maximum  Burst for BE??
What is BE set to in GTS if it is not specfied?
How can we use legacy rate limiting to limit access to a host 150.1.1.1 to 256000 if the traffic confirms it should
be set to prec 1 if it does not it is set to prec 0
What is the bc in legacy rate limiting for 128kb at 10ms TC??
What is bc when we use the drop option in legacy car??
If we do not specify bc in legacy car what is set to?
What would be usual be value?
how could you with 1 line match ip prec 4 and 6 in car?
What is fecn??
What is becn??
How do we enable router to use fecn??
how do we enable gts on frame relay interface
what is the min rate + how to we enable?
How would we traffic shape a particular dlci using legacy commands?
How could we get the router to use fecn and becn on a singular dlci?
How could we change vc to use fair que using legacy commands?
How could we use pq at per vc level using legacy commands?
How could we use cq at per vc level using legacy commands?
How can we fragment at per vc level using legacy??
how do you work out the size of the fragment using legacy??
How do you apply per vc rtp priority using legacy??
How do Apply tcp header compression to multiple dlci bar one using legacy??
How do you limit the frame relay pseudo bcast que?
what is the legacy way of setting de marking say for all packets gt 64?
How would you match icmp with packet lenght of 1001 using mqc??
What is the policed rate for bandwidth 128 reservation??
What weight do specfic classes get in cbwfq?
How could we make template of bandwidth reservation given we have multiple different speed intefaces?
How would apply priority for traffic class and give all the remaining bw to another class??
How does priority reservation behave during congestion vs when network is not conjested
How do you apply mqc wred?
How would change a class default que to be fifo??
what is ecn and how to we apply it??
Create MQC GTS with CIR 384k and TC 20 MS?
WHat is BE if not specfied in MQC GTS?
If we are using CBWFQ bw reservation etc and we want to shape to 384k cir how would we do it?
Police http to 128000 with 200 ms tc if it keeps to cir set prec 0 if it goes over set prec 0 if it goes over burst drop it?
What type of policer is the above?
How does be behave in this type of policing?

OK we have 3 router on lan segment r1 r2 and r3. R1 wants to limit overall traffic to 128k and it also when to limit r2 64000 and r3 6400
how would we configure?
We have been told by our provider our CIR 64k and PIR is 128k. Our cir burst is 300 mbs while our PIR bust is 400 ms
How are the CIR and PIR buckets filled??
SHape http traffic to a peak rate of 128k?
What is the formula for PIR in shaping?
We want to do a template for MQC policing to apply to different speed interfaces how do we do this?
How do we account for tcp small payloads with large packet headers is there way optimize using mqc?
How do shape a singular dlci using mqc and no legacy commands??
in the above set de on all traffic?
how can we use mqc with legacy frts?
how can we set fragment of 480 on interface?
We have guaranteed rate of 128k and pir rate of 192k on our frame relay circuit. The only delay sensitive traffic we send is voice. But we do not
want to shape to 128k just to keep voice in the cir. We only want to shape to 128k when voice is in the que how can we do
this?
How do you fragment and interleaving with mqc??
How can you ensure gre traffic is not considered just one flow by mqc and recieves proper qos treatment?

How does rsvp router reserve from host x to host y what messages does it use?
reserve 64k of 96k link using rsvp?
what weight does rsvp?
How can we keep track of rsvp on shared ethernet segment?
what weight does rsvp get?
What is AF13 in decimal?
What is AF13 ip precedence value
What is drop preference?
how can we map cos - dscp on ethernet switches? so that cos 2 is changed to dscp26
how can we map ip prec- dscp so that ip prec 5 is dscp 46?
what is the default incoming marking action when mls qos is not enabled?
What is the default incoming marking action when mls qos is enabled?
how could we trust dscp in from a router on the switch?
How could we remark all cos values to 4 coming in an interface?
How could we trust ip prec but remark all cos to 4?
For untagged packets how can we mark cos 1?
How can we reset dscp but pass cos??
how do you read sh mls qos int fa0/16 stats?
how would you at layer 2 Set ipx traffic to dscp ef??
We want to apply a qos policy to all ports in vlan what is the best way to do this and how would you configure?
Apply policing at layer 2 to police to cir 128k
what command do you need to do to allow setting cos in mqc class map??
If traffic exceeds we do not want to drop but remark to CS2 how do we do that?
S1 and S2 are connected and we have set to trust dscp incoming on the port connected to a router on s1 when it
gets to s2 it has default marking what is the problem?
We want to limit all classes in mqc to 128k shaped how do we do that?
How many ingress que are there on 3560 switch interface?
how can we assign cos 5 to que 1 and all other cos values to que 2 on ingress ques?
How can we set a pq?
How does the pq work with bw assigned??
what configurable threshold are there on ingress?
How many ques are there on egress interface on 3560?
what is difference between shaped round robin and shared round robin?
How do you enable shaped round robin?
how do you set a pq on 3560 and what que number is it?
how can we limit egress sending rate?
how can we map dscp/cos values to ques on egress?
What is queue set how do you configure it?
how on input could we change cs 0 to cs 1?
How could we match .txt or text with nbar?





 

Route Redistribution EEM Multicast Review Questions

Route Redistribution
what routes are redistributed??
When do we need to further investigate route redistribution parameters?
How does OSPF prevent issues inbuilt??
When do we generally have issue with redistribution??
What are the rules for redistribution (4 rules)
How do you verify with TCLSH??

EEMHow do you see what version of EEM you are running?

Write an applet that will not allow in the cli eigrp or ospf when user attempts it should write a message saying
" no eigrp or ospf" it should then send a mail to the admin via the mail server 10.0.0.100 the sendername should
r5@ine.com the email address it is sending to dropboX@ine.com

Write an applet that restores the startup config when a user types help it should also say "have no fear"

Write an applet that hides all i in the running config when user types sh run

Write an applet that when the interface usuage hits 100 percent it applies a prefconfigured control plane policy. Called
ICMP in the inbound direction

Wirte an applet that when user creates a loopback interface it accepts it but puts the loopback into the shutdown state
It should then save the config. Then it should write a message that "lox" loopback command executed" where x is the loopback
number?

Multicast
What is the full mcast address class??
What is the link local range??
what is the source specfic range??
what  is the admin scope??
What protocol number is IGMP?
What are the igmpv1 messages?
What did igmpv2 add to igmpv1??
What did igmpv3 add ??
How does the rpf check work??
What is the difference between the source and the oil interfaces??
What mcast address does pim use??
What are the dense mode messages + how do they work
How do (*,G) and (S,G) work in dense mode??
When does a prune occur in dense mode??
Does (S,g) remain after prune
What is default dense mode flood interval??
How do prune work on multiaccess segmenets where one souce wants traffic and other does not??
What is pim assert + how does the election elect??
What is state refresh??
How can you see briefly how many packets where recieved+ how many were forwarded in mcast??
What mcast address does igmpv3 use??
What is T bit meaning in mcast?
What does a null outgoin interface in dense mode??
Describe the dense mode from igmp join??
What is the difference between source based tree and shared based tree?
What is the RP job in sparse mode?
What will the first hop router do in sparse mode when it hears mcast traffic from a source??
In the above case what will be the state of (S,G) and (*,G) on all the routers
How is the DR elected and what is it function in sparse mode??
What does the last hop router do when it receives an IGMP Join??
What routers will know of the (S,G) and (*,G) when an IGMP Join is recieved and processed (in the case there is no sender??
How does the switchover to the shortest path tree work??
Can we configure not to switchover + how + where to we configure??
Limit this to only the admin scope address to not to switch to shortest path tree?
How do you statically configure RP address??
How do you view the configured RP address for groups??
How can you change the PIM DR priority for an interface??
In the case we have no source but recievers what will the incoming interface and outgoing interface list be on the RP?
How do we specify a potential RP in Autorp??
How do we specify a mapping agent in AutoRP + what is it role??
How could we allow for redudancy not using anyrp??
How do We assign a mapping agent??
What mulitcast address do RP use to communicate to the mapping agent in AUtoRP?
What address does the MA use to speak to all PIM routers??
WHat is the recursive issue in AUtorp??
How do we resolve this issue 2 solutions??
IF MA recieves multiple RP how does it decide which to use??
What is mtrace??
What issue can we face when testing by ping "group" from a router on segment?
Do a config so that we split the group serviced by RP from R4 services 224.0.0.0 - 231.255.255.255
R6 services 232-239.255.255.255? The config should be done on each rp
DO a config on the MA so we will only advertise 224-231-255.255.255 out for R4 RP and 239.255.255.255 out for R6
all other RP attempting to service any groups should denied
What is a BSR router and how do you enable a BSR router?
How do advertise a RP in BSR?
How do you create boundary in BSR
How do you create a Boundary in AutoRP
When you do debug what do you need to do on the interfaces so you can see  mcast traffic transiting the device??
How do frame-relay main interfaces process multicast/bcast??
WHat happens on nmba partial mesh when a spoke sends a join??
What happens on nbma partial mesh when one spoke prunes in dense mode?
What happens when one spoke is the source of the traffic and the other spoke is listner??
How can you overcome these issues + how does it work + has it limitations??
When would you use bidirectional PIM??
When souce comes online in Bidirectional PIM what are (S,G) (*,G) enteries we will see in the transit path
How does bidirectional pim prevent loops??
What is the df in bidrectional pim + how is it elected??
How do we enable bidirectional pim
What routers do we need to enable it on??
What is SSM??
How does it work what are it requirements??
How do you enable RP in SSM??
What is address range for SSM??
What will be the state of (S,G) (*,G) in the transite path of routers when recievers senders come on line
How do you enable SSM??
How would you enable SSM with different range than default??
How do you test SSM from the source?? 
What is MSDP??
How do you enable msdp??
How do you optimize but potential lose redudancy in MSDP?
What will rp do if it has no reciever and it recieves a SA + how can we see this on the cli?
How does multicast BGP work??
How do you configure MULTICAST BGP??
How can you view mcast bgp routes?
R1 is originating mcast traffic in AS1 and the reciever is in AS3 R3. R3 shortest path to AS1 is direct it also has another
option of going through AS2 how would we influence the mcast traffic to go the longer path via AS1 without interupting any other
normal traffic flow??
How does anycast RP work??
What is requirement for anycast RP to ensure that rp are kept in synch??
What default time it takes is 1 RP goes down that the other RP will service the group??
What address should the mcast routers point at for RP??
How can we get around having non mcast routers in the transit path between 2 multicast routers??
What do we need to configure to enable this??
What is there to watch out for re the RP address and reachability?
When you have rpf failures what is wrong with just doing ip mroute 0.0.0.0 0.0.0.0 pointing at the interface you want to recieve on?
What is the difference between igmp static group and igmp join? When should each be used + what are the commands?
What would you do if you required to recieve mcast on segment but you had a bad connection and low end router?? + How do you
configure?
You have an old udp application that broadcast it needs to be recieved on vlan downstream do this without bridging it should
be recieved on the segmenet as broadcast? UDP port 2222
How can we limit who a router forms pim adjacency with??
how can we limit on non rp what rp address it will use for specfic group??
How can we limit the bw for a feed to 239.0.0.1?
What is the mac address range for mulitcast??
What bits are fixed and what are availible for multicast groups?
How do switches treat multicast traffic?
How does igmp snooping work?? How would we put it on only for a specfic vlan?
How do we statically join a port to a group in igmp snooping??
If reciever moves port at layer 2 how will igmp snooping react??
How can we stop this reaction if neccessary??
Limit via IGMP to permit the range 239.0.0.0??
Limit via IGMP to allow 2 groups max to be joined on interface?? if a new group comes online it should replace an existing group?
Use a technology on switches to allow a specfic vlan to be used for mcast that does not require mcast layer 3 routing to function
Use vlan 30 and the mcast group should be 239.1.1.12??
What is the IPV6 reserved for mcast address range??
What are the flags in ipv6?
What are the scopes ipv6 + are they auto enabled?
What is the all  local node address in ipv6 mcast?
What is the ospf dr address in ipv6?
What is the all routers address??
What is the first two bytes of ipv6 multicast address?
How do you enable ivp6 multicasting??
How do you enable ipv6 pim dense mode??
What is MLD??
What are it equivlant in ipv4?
How do we limit what groups in mld??
How do we change the query-interval in mld?
What is the tunnel in ipv6 mcast on the rp used for??
How do we statically configure an RP address in IPV6 mcast?
How do we configure a potential rp and bsr in IPV6?
What is the ipv6 equivlant to sh ip pim rp-mapping
what is the ipv6 equivant to ip igmp join-group "group address"
How do we assign an embedded RP address if the rp address is
200:1234:5678:ABCD::6/64
Do the config for the rp for embedded rp and also the sender/reciever??
How do we do a mroute in ipv6??