viernes, 24 de mayo de 2013

BGP Local Preference



R2#sh run | sec bgp
router bgp 65000
 bgp log-neighbor-changes
 network 2.2.2.0 mask 255.255.255.0
 neighbor 1.1.1.1 remote-as 65000
 neighbor 1.1.1.1 update-source Loopback0
 neighbor 1.1.1.1 next-hop-self
 neighbor 3.3.3.3 remote-as 65000
 neighbor 3.3.3.3 update-source Loopback0
 neighbor 3.3.3.3 next-hop-self
 neighbor 6.6.6.6 remote-as 65001
 neighbor 6.6.6.6 ebgp-multihop 2
 neighbor 6.6.6.6 update-source Loopback0
 neighbor 6.6.6.6 route-map local3 in


R3#sh ip bgp
BGP table version is 61, local router ID is 3.3.3.3
Status codes: s suppressed, d damped, h history, * valid, > best, i - internal,
              r RIB-failure, S Stale, m multipath, b backup-path, f RT-Filter,
              x best-external, a additional-path, c RIB-compressed,
Origin codes: i - IGP, e - EGP, ? - incomplete
RPKI validation codes: V valid, I invalid, N Not found
     Network          Next Hop                Metric LocPrf Weight Path
 *>i 1.1.1.0/24       1.1.1.1                      0          100      0 i
 *>i 2.2.2.0/24       2.2.2.2                      0          100      0 i
 *>  3.3.3.0/24       0.0.0.0                      0         32768 i
 *>i 4.4.4.0/24       2.2.2.2            2809856        201      0 65001 i
 * i 5.5.5.0/24        2.2.2.2             2297856       100      0 65001 i
 *>i                        1.1.1.1             2297856       100      0 65001 i
 *>i 6.6.6.0/24       2.2.2.2                  0              100      0 65001 i
 *>  10.10.10.0/30    0.0.0.0                  0         32768 i
 *>  10.10.10.4/30    0.0.0.0                  0         32768 i
 *>  10.10.10.8/30    10.10.10.1             128         32768 i
 *>i 40.40.40.0/30    1.1.1.1                  0    100      0 65001 i
 *>i 40.40.40.4/30    2.2.2.2                  0    100      0 65001 i
R3#

miércoles, 15 de mayo de 2013

SNMP






R1(config)#access-list 21 permit 192.168.100.0 0.0.0.255
R1(config)#snmp-server community lectura ro 21
R1(config)#snmp-server location Block1
R1(config)#snmp-server contact cesarinj@hotmail.com
R1(config)#snmp-server chassis-id 3725block1
R1(config)#snmp-server enable traps snmp
R1(config)#snmp-server enable traps hsrp
R1(config)#snmp-server enable traps config
R1(config)#snmp-server enable traps entity
R1(config)#snmp-server enable traps os
R1(config)#snmp-server enable traps bgp
R1(config)#snmp-server enable traps fra
R1(config)#snmp-server enable traps frame-relay
R1(config)#snmp-server enable traps rtr
R1(config)#snmp-server h
R1(config)#snmp-server host 192.168.100.100 lectura

miércoles, 17 de abril de 2013

CCIE LAB

A las personas que desean tener este BUNDLE , escribir al correo  cesarinj@hotmail.com  para darles los password e ip paraque puedan acceder  totalmente gratis

 
 
1) En el AS 100 usar Eigrp y en el AS 200 usar OSPF

2) R14,R15 y R16 son FRSwITCH. Sobre FR debe implementar MPLS para asegurar el reenvío basado en etiquetas en  la red FR

3) El trafico del AS 254 y 54 debe ir por  R10 ,R5,R4,R6 en caso de que se caiga debe ir por R10,R5,R3 (red redundante),  este trafico debe de pasar por la vrf 10024 en todo el trayecto indicado , (las redes destinos son las mismas R13 y R11,(debe publicar 8 redes privadas IPv4 sumarizables en R11 y R13 iguales en cada router, agregadas en una sola). El enlace Ethernet VLAN 45(100.1.45.0) solo debe usarse ante la caída de la red FR del router R4, en otros casos no presentará tráfico

4)El tráfico desde el AS 254 (Red Privada A) llegará a Internet por el AS 200 al R8 (usar una loopback con IP pública), la segunda opción sería por el AS 100 al  R9 (usar la misma IP pública en otra loopback) en caso de caída del R8. Para este controlar este tráfico debemos hacer túneles GRE con que permitirán la redundancia usando EIGRP.

5. El tráfico desde el AS 54 llegará a Internet en forma primaria por el AS 100, la segunda opción sería por el AS 200 en caso de caída del R9. Esto permitirá el acceso a los servidores de los AS 54 los cuales tendrán IPv6 e IPv4. Para ambos casos se debe hacer NAT para IPv6 (IPv4 público a IPv6 del servidor) así como para IPv4 (IPv4 público a IPv4 privado del servidor) desde Internet. Los AS 54 deben poder conectarse solamente por IPv6, mas no por IPv4 ya que sus direcciones IPv4 se repiten.

6. Solamente el tráfico generado en el AS 100 irá hacia el AS 200 por el enlace FR, mientras que el tráfico de retorno, es decir el generado en el AS 200 irá al AS 100 solamente por los routers R10-R5. El tráfico entre el AS 254 (Red Privada B) y una nueva Red Privada C del R9 (interface loopback con IPv6 pública) debe ser incluido en BGP. Este tráfico solo tomará el camino R10, R5 y R3.

miércoles, 27 de marzo de 2013

Nuevo CCNA 200-120


Operation of IP Data Networks
  • Recognize the purpose and functions of various network devices such as Routers, Switches, Bridges and Hubs.
  • Select the components required to meet a given network specification.
  • Identify common applications and their impact on the network
  • Describe the purpose and basic operation of the protocols in the OSI and TCP/IP models.
  • Predict the data flow between two hosts across a network.
  • Identify the appropriate media, cables, ports, and connectors to connect Cisco network devices to other network devices and hosts in a LAN
LAN Switching Technologies
  • Determine the technology and media access control method for Ethernet networks
  • Identify basic switching concepts and the operation of Cisco switches. 
    • Collision Domains
    • Broadcast Domains
    • Types of switching
    • CAM Table
  • Configure and verify initial switch configuration including remote access management. 
    • Cisco IOS commands to perform basic switch setup
  • Verify network status and switch operation using basic utilities such as ping, telnet and ssh.
  • Describe how VLANs create logically separate networks and the need for routing between them. 
    • Explain network segmentation and basic traffic management concepts
  • Configure and verify VLANs
  • Configure and verify trunking on Cisco switches
  • DTP
  • Auto negotiation
IP addressing (IPv4 / IPv6)
  • Describe the operation and necessity of using private and public IP addresses for IPv4 addressing
  • Identify the appropriate IPv6 addressing scheme to satisfy addressing requirements in a LAN/WAN environment.
  • Identify the appropriate IPv4 addressing scheme using VLSM and summarization to satisfy addressing requirements in a LAN/WAN environment.
  • Describe the technological requirements for running IPv6 in conjunction with IPv4 such as dual stack
  • Describe IPv6 addresses 
    • Global unicast
    • Multicast
    • Link local
    • Unique local
    • eui 64
    • autoconfiguration
IP Routing Technologies
  • Describe basic routing concepts  
    • CEF
    • Packet forwarding
    • Router lookup process
  • Configure and verify utilizing the CLI to set basic Router configuration  
    • Cisco IOS commands to perform basic router setup
  • Configure and verify operation status of an ethernet interface
  • Verify router configuration and network connectivity  
    • Cisco IOS commands to review basic router information and network connectivity
  • Configure and verify routing configuration for a static or default route given specific routing requirements
  • Differentiate methods of routing and routing protocols 
    • Static vs. Dynamic
    • Link state vs. Distance Vector
    • next hop
    • ip routing table
    • Passive interfaces
  • Configure and verify OSPF (single area)  
    • Benefit of single area
    • Configure OSPF v2
    • Configure OSPF v3
    • Router ID
    • Passive interface
  • Configure and verify interVLAN routing (Router on a stick) 
    • sub interfaces
    • upstream routing
    • encapsulation
  • Configure SVI interfaces
IP Services
  • Configure and verify DHCP (IOS Router) 
    • configuring router interfaces to use DHCP
    • DHCP options
    • excluded addresses
    • lease time
  • Describe the types, features, and applications of ACLs
  • Standard
  • Sequence numbers
  • Editing
  • Extended
  • Named
  • Numbered
  • Log option
  • Configure and verify ACLs in a network environment
  • Named
  • Numbered
  • Log option
  • Identify the basic operation of NAT
  • Purpose
  • Pool
  • Static
  • 1 to 1
  • Overloading
  • Source addressing
  • One way NAT
  • Configure and verify NAT for given network requirements
  • Configure and verify NTP as a client
Network Device Security
  • Configure and verify network device security features such as:
  • Device password security
  • Enable secret vs enable
  • Transport
  • Disable telnet
  • SSH
  • VTYs
  • Physical security
  • Service password
  • Describe external authentication methods
  • Configure and verify Switch Port Security features such as
  • Sticky MAC
  • MAC address limitation
  • Static / dynamic
  • Violation modes
  • Err disable
  • Shutdown
  • Protect restrict
  • Shutdown unused ports
  • Err disable recovery
  • Assign unused ports to an unused VLAN
  • Setting native VLAN to other than VLAN 1
  • Configure and verify ACLs to filter network traffic
  • Configure and verify an ACLs to limit telnet and SSH access to the router
Troubleshooting
  • Troubleshoot and correct common problems associated with IP addressing and host configurations.
  • Troubleshoot and Resolve VLAN problems
  • identify that VLANs are configured
  • port membership correct
  • IP address configured
  • Troubleshoot and Resolve trunking problems on Cisco switches
  • correct trunk states
  • correct encapsulation configured
  • correct vlans allowed
  • Troubleshoot and Resolve ACL issues
  • Statistics
  • Permitted networks
  • Direction
  • Interface
  • Troubleshoot and Resolve Layer 1 problems
  • Framing
  • CRC
  • Runts
  • Giants
  • Dropped packets
  • Late collision
  • Input / Output errors
LAN Switching Technologies
  • Identify enhanced switching technologies
  • RSTP
  • PVSTP
  • Etherchannels
  • Configure and verify PVSTP operation
  • describe root bridge election
  • spanning tree mode
IP Routing Technologies
  • Describe the boot process of Cisco IOS routers
  • POST
  • Router bootup process
  • Configure and verify operation status of a Serial interface
  • Manage Cisco IOS Files
  • Boot preferences
  • Cisco IOS image(s)
  • Licensing
  • Show license
  • Change license
  • Differentiate methods of routing and routing protocols
  • Administrative distance
  • split horizon
  • metric
  • next hop
  • Configure and verify OSPF (single area)
  • neighbor adjacencies
  • OSPF states
  • Discuss Multi area
  • Configure OSPF v2
  • Configure OSPF v3
  • Router ID
  • LSA types
  • Configure and verify EIGRP (single AS)
  • Feasible Distance / Feasible Successors /Administrative distance
  • Feasibility condition
  • Metric composition
  • Router ID
  • Auto summary
  • Path selection
  • Load balancing
  • Equal
  • Unequal
  • Passive interface
IP Services
  • Recognize High availability (FHRP)
  • VRRP
  • HSRP
  • GLBP
  • Configure and verify Syslog
  • Utilize Syslog Output
  • Describe SNMP v2 & v3
Troubleshooting
  • Identify and correct common network problems
  • Utilize netflow data
  • Troubleshoot and Resolve Spanning Tree operation issues
  • root switch
  • priority
  • mode is correct
  • port states
  • Troubleshoot and Resolve routing issues
  • routing is enabled
  • routing table is correct
  • correct path selection
  • Troubleshoot and Resolve OSPF problems
  • Neighbor Adjacencies
  • Hello and Dead timers
  • OSPF area
  • Interface MTU
  • Network types
  • Neighbor states
  • OSPF topology database
  • Troubleshoot and Resolve EIGRP problems
  • neighbor adjancies
  • AS number
  • Load balancing
  • Split horizon
  • Troubleshoot and Resolve interVLAN routing problems  
    • Connectivity
    • Encapsulation
    • Subnet
    • Native VLAN
    • Port mode trunk status
  • Troubleshoot and Resolve WAN implementation issues 
    • Serial interfaces
    • PPP
    • Frame relay
  • Monitor NetFlow statistics
  • Troubleshoot etherchannel problems
WAN Technologies
  • Identify different WAN Technologies 
    • Metro Ethernet
    • VSAT
    • Cellular 3G / 4G
    • MPLS
    • T1 / E1
    • ISDN
    • DSL
    • Frame relay
    • Cable
    • VPN
  • Configure and verify a basic WAN serial connection
  • Configure and verify a PPP connection between Cisco routers
  • Configure and verify Frame Relay on Cisco routers
  • Implement and troubleshoot  PPPoE

martes, 26 de marzo de 2013

IOU-GC HSRP IP-SLA

Se esta usanando el IOU-GC para esta topologia
PC1, PC2, PC3 maquinas virtuales VMnet1,Vmnet2,VMnet3


R2  ISP
S11,S12: HSRP
pc1: vlan 10:192.168.10.10/24
pc2: vlan 20:192.168.20.10/24
pc3:200.10.10.10/24

martes, 19 de marzo de 2013

Multicast IPV6



R1(config)#int f1/0
R1(config-if)#ipv6 address 2001:2:1::1/64
R1(config-if)#no shut
R1(config-if)#int f0/1
R1(config-if)#ipv6 address 2001:1:3::1/64
R1(config-if)#no shut
R1(config-if)#int f0/0
R1(config-if)#ipv6 address 2001:1:1::1/64
R1(config-if)#no shut
R1(config)#ipv6 unicast-routing
R1(config)#ipv6 router ospf 1
R1(config-rtr)#router-id 1.1.1.1
R1(config-rtr)#int f1/0
R1(config-if)#ipv6 ospf 1 area 0
R1(config-if)#int f0/1
R1(config-if)#ipv6 ospf 1 area 0
R1(config-if)#int f0/1
R1(config-if)#ipv6 ospf 1 area 0
R1(config)#ipv6 multicast-routing
R1(config)#ipv6 cef
R1(config)#int f0/0
R1(config-if)#ipv6 mld join-group ff08::10
R1(config)#ipv6 pim rp-address 2001:5:2::1
R1(config)#int f0/1
R1(config-if)#ipv6 mld join-group ff08::10
R1# show ipv6 mld groups
MLD Connected Group Membership
Group Address                           Interface          Uptime    Expires
FF08::10                                FastEthernet0/0    00:13:59  never
FF08::10                                FastEthernet0/1    00:10:29  never

R1# show ipv6 pim neighbor
PIM Neighbor Table
Mode: B - Bidir Capable, G - GenID Capable
Neighbor Address           Interface          Uptime    Expires  Mode DR pri
FE80::C801:2AFF:FE5C:8     FastEthernet0/0    00:21:07  00:01:24 B G  DR 1
FE80::C802:6FF:FE74:8      FastEthernet0/1    00:20:53  00:01:35 B G  DR 1


R1#show ipv6 mroute
Multicast Routing Table
Flags: D - Dense, S - Sparse, B - Bidir Group, s - SSM Group,
       C - Connected, L - Local, I - Received Source Specific Host Report,
       P - Pruned, R - RP-bit set, F - Register flag, T - SPT-bit set,
       J - Join SPT
Timers: Uptime/Expires
Interface state: Interface, State
(*, FF08::10), 00:14:50/never, RP 2001:5:2::1, flags: SPCL
  Incoming interface: FastEthernet0/0
  RPF nbr: FE80::C801:2AFF:FE5C:8
  Immediate Outgoing interface list:
    FastEthernet0/1, Null, 00:11:20/never

R1#ping ipv6 ff08::10
Output Interface: Fastethernet0/1
Type escape sequence to abort.
Sending 5, 100-byte ICMP Echos to FF08::10, timeout is 2 seconds:
Packet sent with a source address of 2001:1:3::1
Reply to request 0 received from 2001:1:2::3, 428 ms
Reply to request 1 received from 2001:1:3::3, 104 ms
Reply to request 1 received from 2001:1:2::3, 104 ms
Reply to request 2 received from 2001:1:3::3, 64 ms
Reply to request 2 received from 2001:1:2::3, 64 ms
Reply to request 3 received from 2001:1:3::3, 80 ms
Reply to request 3 received from 2001:1:2::3, 80 ms
Reply to request 4 received from 2001:1:3::3, 80 ms
Reply to request 4 received from 2001:1:2::3, 80 ms
Success rate is 100 percent (5/5), round-trip min/avg/max = 64/120/428 ms
9 multicast replies and 0 errors.
R1#

Set Next-hop


Set ip default next hop
    Si la ip destino existe la politica no se aplica y el paquete es enviado segun la tabla de enrutamiento
    Si la ip detinono existe , el comando policy es aplicado

Set ip next hop
    Si la ip destino existe en la tabla de enrutamiento la politicano se aplica
    Si la ip detino no esite en la tabla de enrutamiento , el comando policy no es   aplicada




R1(config)
access-list 101 permit ip host 100.100.100.3 host 200.200.200.4

route-map pbr permit 10

match ip address 101

set default interface Serial1/0

R1#sh ip route 200.200.200.4
Routing entry for 200.200.200.0/24

Known via "ospf 1", distance 110, metric 65, type intra area

Last update from 20.20.20.2 on Serial1/1, 00:13:23 ago

Routing Descriptor Blocks:

* 20.20.20.2, from 200.200.200.2, 00:13:23 ago, via Serial1/1

Route metric is 65, traf
 

 
VPCS[1]> ping 200.200.200.4
200.200.200.4 icmp_seq=1 ttl=62 time=326.542 ms
200.200.200.4 icmp_seq=2 ttl=62 time=261.533 ms
200.200.200.4 icmp_seq=3 ttl=62 time=90.512 ms
200.200.200.4 icmp_seq=4 ttl=62 time=59.508 ms
200.200.200.4 icmp_seq=5 ttl=62 time=195.024 ms
 
 
R1#debug ip policy
*Mar 19 00:39:48.707: IP: s=100.100.100.3 (FastEthernet0/0), d=200.200.200.4, len 92, FIB policy match
*Mar 19 00:39:48.707: IP: s=100.100.100.3 (FastEthernet0/0), d=200.200.200.4, len 92, PBR Counted
*Mar 19 00:39:48.707: IP: s=100.100.100.3 (FastEthernet0/0), d=200.200.200.4, len 92, FIB policy rejected(explicit route) - normal forwarding
R1#

R1#trace 200.200.200.4

1 20.20.20.2 212 msec 116 msec 72 msec
2 200.200.200.4 36 msec 104 msec 48 msec