<?xml version="1.0" encoding="UTF-8"?>
<?xml-stylesheet type="text/xsl" media="screen" href="/~d/styles/rss2full.xsl"?><?xml-stylesheet type="text/css" media="screen" href="http://feeds.feedburner.com/~d/styles/itemcontent.css"?><rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:wfw="http://wellformedweb.org/CommentAPI/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:atom="http://www.w3.org/2005/Atom" xmlns:sy="http://purl.org/rss/1.0/modules/syndication/" xmlns:slash="http://purl.org/rss/1.0/modules/slash/" xmlns:feedburner="http://rssnamespace.org/feedburner/ext/1.0" version="2.0">

<channel>
	<title>Pass any IT exam for sure</title>
	
	<link>http://www.realexam.net</link>
	<description>IT Certification Study Guide share &amp;amp; Training Preparation Ebooks free download</description>
	<lastBuildDate>Fri, 30 Jul 2010 09:11:24 +0000</lastBuildDate>
	<language>en</language>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
	<generator>http://wordpress.org/?v=3.0</generator>
<image><link>http://www.realexam.net</link><url>http://www.realexam.net/wp-content/logo.gif</url><title>Pass any it exam for sure!</title></image>		<feedburner:info uri="certting" /><feedburner:info uri="certting" /><atom10:link xmlns:atom10="http://www.w3.org/2005/Atom" rel="self" type="application/rss+xml" href="http://feeds.feedburner.com/certting" /><feedburner:info uri="certting" /><atom10:link xmlns:atom10="http://www.w3.org/2005/Atom" rel="hub" href="http://pubsubhubbub.appspot.com/" /><item>
		<title>Cisco 642-432:Cisco voice certification (Q36-Q75)</title>
		<link>http://feedproxy.google.com/~r/certting/~3/UWBb6ip4Kfc/4717.html</link>
		<comments>http://www.realexam.net/cisco-642-432cisco-voice-certification-q36-q75/4717.html#comments</comments>
		<pubDate>Sat, 24 Jul 2010 15:33:19 +0000</pubDate>
		<dc:creator>Johnny</dc:creator>
				<category><![CDATA[CCVP Training]]></category>
		<category><![CDATA[642-432]]></category>
		<category><![CDATA[ccvp]]></category>
		<category><![CDATA[cisco certification]]></category>
		<category><![CDATA[cvoice]]></category>

		<guid isPermaLink="false">http://www.realexam.net/?p=4717</guid>
		<description><![CDATA[QUESTION NO: 36 With regard to MGCP, what is a call? A. It is the path between two telephones. B. It is the RTP sessions between the endpoints. C. It is a connection between an endpoint and the call agent. D. It is two or more endpoints sharing the same ... ]]></description>
			<content:encoded><![CDATA[<p><strong>QUESTION NO: 36 With regard to MGCP, what is a call? </strong></p>
<p>A. It is the path between two telephones.</p>
<p>B. It is the RTP sessions between the endpoints.</p>
<p>C. It is a connection between an endpoint and the call agent.</p>
<p>D. It is two or more endpoints sharing the same Call ID and the same media stream.</p>
<p><strong>Answer: D </strong></p>
<p><strong>QUESTION NO: 37 Which of the following are CS-ACELP coding schemes? (Choose two) </strong></p>
<p>A. G.711</p>
<p>B. G.728</p>
<p>C. G.729</p>
<p>D. Q.931</p>
<p>E. G-729A</p>
<p><strong>Answer: C, E </strong></p>
<p><strong>QUESTION NO: 38 To which layer of the OSI model does Q.921 signaling equates to in ISDN? </strong></p>
<p>A. Session</p>
<p>B. Network</p>
<p>C. Transport</p>
<p>D. Data-Link</p>
<p>E. Application</p>
<p><strong>Answer: D </strong></p>
<p><strong>QUESTION NO: 39 You are the network engineer at TestKing. The TestKing ISDN network has two PBX systems from different manufactures. </strong></p>
<p><strong>Which protocol allows functionality between these two PBX systems? </strong></p>
<p>A. QSIG</p>
<p>B. Q.921</p>
<p>C. Q.931</p>
<p>D. T-CCS</p>
<p><strong>Answer: A </strong></p>
<p><strong>QUESTION NO: 40 You are the network technician at TestKing. Your newly appointed TestKing trainee wants to know which application conveys fax using T.37 fax relay.What will your reply be? </strong></p>
<p>A. IVR</p>
<p>B. TCL</p>
<p>C. TIFF</p>
<p>D. SNMP</p>
<p>E. SMTP</p>
<p><strong>Answer: E </strong></p>
<p><strong>QUESTION NO: 41 What type of multiplexing is packet switching an example of? </strong></p>
<p>A. Statistical</p>
<p>B. Time division</p>
<p>C. Phase division</p>
<p>D. Frequency division</p>
<p><strong>Answer: A </strong></p>
<p><strong>QUESTION NO: 42 You are the network technician at TestKing. Your newly appointed TestKing trainee wants to know which signal types are used by E&amp;M. </strong></p>
<p><strong>What will your reply be? </strong></p>
<p>A. wink start, delay start, and loop start</p>
<p>B. wink start, loop start, and immediate start</p>
<p>C. wink start, delay start, and immediate start</p>
<p>D. delay start, and loop start, and immediate start</p>
<p><strong>Answer: C </strong></p>
<p><strong>QUESTION NO: 43 Which application allows you to communicate to multiple remote offices simultaneously? </strong></p>
<p>A. IP Phone</p>
<p>B. IP Centrex</p>
<p>C. Toll Bypass</p>
<p>D. Multi-tenant</p>
<p>E. Hoot and Holler</p>
<p><strong>Answer: E </strong></p>
<p><strong>QUESTION NO: 44 You are the network technician at TestKing. Your newly appointed TestKing trainee wants to know what the attributes of a scalable dialing plan are. </strong></p>
<p><strong>What will your reply be? (Choose four) </strong></p>
<p>A. Logic distribution</p>
<p>B. Hierarchical design</p>
<p>C. Simplicity in provisioning</p>
<p>D. Reduction in pre-dial delay</p>
<p>E. reduction in post-dial delay</p>
<p><strong>Answer: A, B, C, E </strong></p>
<p><strong>QUESTION NO: 45 What happens if no incoming dial peer matches a router or gateway? </strong></p>
<p>A. The incoming call leg takes an alternate path.</p>
<p>B. The incoming call leg matches the default dial peer.</p>
<p>C. The incoming call leg sends a busy to the originator.</p>
<p>D. The incoming call leg is denied and the call is dropped.</p>
<p><strong>Answer: B </strong></p>
<p><strong>QUESTION NO: 46 What is the recommended configuration for the transmit interface in switchwide queuing? </strong></p>
<p>A. CoS</p>
<p>B. PFC</p>
<p>C. FIFO</p>
<p>D. TIFF</p>
<p>E. 2Q1T</p>
<p><strong>Answer: E </strong></p>
<p><strong>QUESTION NO: 47 Which of the following QoS measures affect the outbound queue when implemented? </strong></p>
<p><strong>(Choose three.) </strong></p>
<p>A. LLQ</p>
<p>B. RSQ</p>
<p>C. WFQ</p>
<p>D. FIFO</p>
<p>E. FRF.12</p>
<p>F. CBWFQ</p>
<p><strong>Answer: A, C, F </strong></p>
<p><strong>QUESTION NO: 48 On what is traffic engineering for voice based? </strong></p>
<p>A. Peak of service.</p>
<p>B. Class of service.</p>
<p>C. Grade of service.</p>
<p>D. Speed of service.</p>
<p>E. Quality of service.</p>
<p><strong>Answer: C </strong></p>
<p><strong>QUESTION NO: 49 You are the Voice technician at TestKing. The TestKing network uses VoIP. Your newly appointed TestKing trainee wants to know what the modes of the playout delay buffer are. </strong></p>
<p><strong>What will your reply be? </strong></p>
<p>A. Percent and Unit.</p>
<p>B. Nominal and Full.</p>
<p>C. Dynamic and Static.</p>
<p>D. Smooth and Serrated.</p>
<p>E. Minimum and Maximum.</p>
<p><strong>Answer: C QUESTION NO: 50 You are the network engineer at TestKing. TestKing has its headquarters in New York and a branch office in Delaware. In the branch office, one VoIP dial-peer has been configured to point to headquarters over a low speed serial link. You want to limit the maximum number of concurrent calls to 3. </strong></p>
<p><strong>Which command would you use? </strong></p>
<p>A.      interface serial 3/3 ip rsvp bandwidth 3</p>
<p>B.      interface serial 3/3  max-con 3</p>
<p>C.      dial-peer voice 1000 voipmax-conn 3</p>
<p>D.      dial-peer voice 1000 voip max-concurrent 3</p>
<p>E.      dial-peer voice 1000 voipip rsvp neighbor 3</p>
<p><strong>Answer: C </strong></p>
<p><strong>QUESTION NO: 51 In a campus network, which of the following are categories for QoS? </strong></p>
<p>A. Separation of queues, queue scheduling, and pruning of queues</p>
<p>B. Pruning of queues, and marking control and management traffic</p>
<p>C. Queue scheduling, pruning of queues and marking control and management traffic</p>
<p>D. Separation of queues, queue scheduling, and marking control and management traffic</p>
<p><strong>Answer: D </strong></p>
<p><strong>QUESTION NO: 52 You are the network technician at TestKing. Your newly appointed TestKing trainee wants to know when glare occurs. </strong></p>
<p><strong>What will your reply be? </strong></p>
<p>A. When echo cancellers fail to synchronize.</p>
<p>B. When two phones go off-hook at the same time.</p>
<p>C. When two optical wavelengths collide in the same fiber.</p>
<p>D. When both ends of a telephone line or trunk experience echo.</p>
<p>E. When both ends of a telephone line or trunk are seized by different users.</p>
<p><strong>Answer: E </strong></p>
<p><strong>QUESTION NO: 53 What will happen when a network link is oversubscribed? </strong></p>
<p>A. The link goes down.</p>
<p>B. All voice calls suffer.</p>
<p>C. Voice packets are fragmented.</p>
<p>D. Excess voice calls are dropped.</p>
<p>E. Data packets are given priority.</p>
<p><strong>Answer: B </strong></p>
<p><strong>QUESTION NO: 54 Your newly appointed TestKing trainee wants to know what CAC applies to. </strong></p>
<p><strong>What will your reply be? </strong></p>
<p>A. Latency</p>
<p>B. Data traffic</p>
<p>C. Voice traffic</p>
<p>D. TCP networks</p>
<p>E. Voice and data traffic</p>
<p><strong>Answer: C </strong></p>
<p><strong>QUESTION NO: 55 You are the network engineer at TestKing. Your newly appointed TestKing trainee wants to know under which standard the fragmentation for VoIP over Frame Relay is defined. What will your reply be? </strong></p>
<p>A. FRF.5</p>
<p>B. FRF.6</p>
<p>C. FRF.9</p>
<p>D. FRF.11</p>
<p>E. FRF.12</p>
<p><strong>Answer: E </strong></p>
<p><strong>QUESTION NO: 56 You are the network engineer at TestKing. TestKing is using LLQ on the serial interface 3/3 on the TestKing router. You want to verify the status if LLQ on the interface. </strong></p>
<p><strong>Which command would you use? </strong></p>
<p>A. show class 11q</p>
<p>B. show interface serial 3/3</p>
<p>C. show queue interface serial 3/3</p>
<p>D. show interface serial 3/3 class 11q</p>
<p>E. show policy-map interface serial 3/3</p>
<p><strong>Answer: E </strong></p>
<p><strong>QUESTION NO: 57 You are the network engineer at TestKing. You are implementing Frame Relay traffic shaping on the TestKing network. Your newly appointed TestKing trainee wants to know why Frame Relay traffic shaping is important. </strong></p>
<p><strong>What will your reply be? </strong></p>
<p>A. It ensures that excess traffic above the CIR on the link is dropped.</p>
<p>B. It ensures that voice packets are not trapped behind large data packets.</p>
<p>C. It ensures that the priority of the voice packet is higher than the data packets.</p>
<p>D. It ensures that the RTP headed is reduced in size to reduce the overall size of the voice packet.</p>
<p>E. It ensures that excess traffic above the CIR on the link is not dropped, but is buffered and sent when there is capacity on the link.</p>
<p><strong>Answer: E </strong></p>
<p><strong>QUESTION NO: 58 You are the network engineer at TestKing. TestKing has its headquarters in New York and a branch office in Delaware. The branch office is using a 128 kbps Frame Relay link to connect to headquarters. You want to ensure good voice quality on this link. </strong></p>
<p><strong>Which two QoS mechanisms should you implement on the Frame Relay interface? (Choose two.) </strong></p>
<p>A. CIR</p>
<p>B. LLQ</p>
<p>C. WFQ</p>
<p>D. WRED</p>
<p>E. Fragmentation</p>
<p><strong>Answer: B, E </strong></p>
<p><strong>QUESTION NO: 59 What component can be used to compensate for jitter? </strong></p>
<p>A. FIFO queuing</p>
<p>B. Ethernet hubs</p>
<p>C. DSP algorithms</p>
<p>D. Playout delay buffer</p>
<p>E. Transmission medium</p>
<p><strong>Answer: D </strong></p>
<p><strong>QUESTION NO: 60 In accordance with the G.114 standard, which of the following delay ranges is acceptable? </strong></p>
<p>A. 0 – 150 ms</p>
<p>B. 0 – 250 ms</p>
<p>C. 0 – 300 ms</p>
<p>D. 0 – 400 ms</p>
<p>E. 0 – 500 ms</p>
<p><strong>Answer: A </strong></p>
<p><strong>QUESTION NO: 61 You are the network technician at TestKing. Your newly appointed TestKing trainee wants to know what factors affects audio quality. </strong></p>
<p><strong>What will your reply be? </strong></p>
<p>A. Echo and delay variation</p>
<p>B. Infidelity and delay variation</p>
<p>C. Echo and playout delay buffer</p>
<p>D. Infidelity and transmission medium</p>
<p><strong>Answer: A </strong></p>
<p><strong>QUESTION NO: 62 What could happen if the playout delay buffer size is configured too large? </strong></p>
<p>A. The overall echo on the connection may rise to unacceptable levels.</p>
<p>B. The overall delay on the connection may rise to unacceptable levels.</p>
<p>C. The overall stress on the connection may rise to unacceptable levels.</p>
<p>D. The overall volume on the connection may rise to unacceptable levels.</p>
<p><strong>Answer: B </strong></p>
<p><strong>QUESTION NO: 63 You are the network technician at TestKing. Your newly appointed TestKing trainee wants to know what TCP</strong><br />
<strong>’</strong><br />
<strong>s reliable deliver service provides. </strong></p>
<p><strong>What will your reply be? </strong></p>
<p>A. Connectionless service, flow control, sequenced delivery, and automatic error recovery</p>
<p>B. Flow control, sequenced delivery, automatic error recovery, and transmission window management</p>
<p>C. Unregulated send rate, automatic error recovery, and transmission window management</p>
<p>D. Connectionless service, unregulated send rate, automatic error recovery, and transmission window management</p>
<p><strong>Answer: B </strong></p>
<p><strong>QUESTION NO: 64 You are the Voice technician at TestKing, Inc. You want to deploy an IP telephony solution for the company. The TestKing network is currently a traditional LAN/WAN based on Frame Relay. </strong></p>
<p><strong>Your CEO has read about the issues of converging both data and voice traffic onto a single network. She is concerned about the quality of their calls that need to cross the WAN in particularly. </strong></p>
<p><strong>What would you need to implement to ensure QoS for VoIP over Frame Relay? </strong></p>
<p>A. Traffic shaping, priority queuing, Call Admission Control, and Class Based Weighted Fair Queuing</p>
<p>B. Traffic shaping, priority queuing, Call Admission Control, and Weighted Random Early Detection</p>
<p>C. Fragmentation, traffic shaping, priority queuing, Low Latency Queuing, and link efficiency with cRTP.</p>
<p>D. Fragmentation, traffic shaping, priority queuing, Call Admission Control, and Weighted Random Early Detection</p>
<p><strong>Answer: C </strong></p>
<p><strong>QUESTION NO: 65 You are the network engineer at TestKing. TestKing has its headquarters in New York and branch offices in Delaware, Detroit and Denver. You have deployed VoIP over the TestKing WAN. TestKing user at headquarters complain that early in the day, the quality of calls between headquarters and the branch offices is very good, but as the day progresses and more calls are placed to the branch offices, the quality degrades. </strong></p>
<p><strong>The TestKing network is using RSVP. The WAN bandwidth to the branch offices allows 4 calls to the Delaware office, 6 calls to the Detroit office, and 8 calls to the Denver office. You want to verify the configuration of Call Admission Control on the headquarters router. </strong></p>
<p><strong>What command should you use? </strong></p>
<p>A. show call cac conf</p>
<p>B. show call rsvp-sync logs</p>
<p>C. show call rsvp-sync conf</p>
<p>D. show call rsvp-sync stats</p>
<p>E. show call rsvp-sync events</p>
<p><strong>Answer: C </strong></p>
<p><strong>QUESTION NO: 66 Which of the following is the worst-case compression delay for CD-ACELP? </strong></p>
<p>A. 2.5 ms</p>
<p>B. 5 ms</p>
<p>C. 7.5ms</p>
<p>D. 10 ms</p>
<p>E. 20 ms</p>
<p><strong>Answer: E </strong></p>
<p><strong>QUESTION NO: 67 What type of connection is considered a call leg? </strong></p>
<p>A. A digital connection</p>
<p>B. A virtual connection</p>
<p>C. A logical connection</p>
<p>D. A physical connection</p>
<p>E. A hardwired connection</p>
<p><strong>Answer: C </strong></p>
<p><strong>QUESTION NO: 68 You are the network engineer at TestKing. TestKing has its headquarters in New York and a branch office in Delaware.  Users at headquarters must be able to call users at the branch office and users at the branch office must be able to call headquarters. </strong></p>
<p><strong>How many dial peers must you configure to meet these requirements? </strong></p>
<p>A. 1</p>
<p>B. 2</p>
<p>C. 3</p>
<p>D. 4</p>
<p>E. none</p>
<p><strong>Answer: D </strong></p>
<p><strong>QUESTION NO: 69 You are the network engineer at TestKing. TestKing has an IP network. Your newly appointed TestKing trainee wants to know which issues would adversely affect voice quality on the TestKing network. </strong></p>
<p><strong>What will your reply be? </strong></p>
<p>A. Jitter, delay, and packet loss</p>
<p>B. Jitter, prioritization, and acknowledgment</p>
<p>C. Prioritization, delay, and delivery guarantee</p>
<p>D. Packet loss, acknowledgment, and delivery guarantee</p>
<p><strong>Answer: A QUESTION NO: 70 What is the biggest issue affecting voice transport when you implement IPSec VPNs in a converged network? </strong></p>
<p>A. Hop count.</p>
<p>B. Using G.729 as the codec.</p>
<p>C. Throughput considerations.</p>
<p>D. Ensuring only software encryption is running.</p>
<p><strong>Answer: C </strong></p>
<p><strong>QUESTION NO: 71 What factors must be considered in the overall design when implementing an IPSec VPN for transport of voice? </strong></p>
<p>A. Port numbers and added delay.</p>
<p>B. Added delay and added overhead.</p>
<p>C. Port numbers and longer dial plan.</p>
<p>D. Port numbers and added overhead.</p>
<p>E. Added overhead and longer dial plan.</p>
<p><strong>Answer: D </strong></p>
<p><strong>QUESTION NO: 72 You are the network technician at TestKing. VoIP is implemented on the TestKing network. Your newly appointed TestKing trainee wants to know what this implementation uses to carry the payload across the network. </strong></p>
<p><strong>What will your reply be? </strong></p>
<p>A. Only RTP</p>
<p>B. Only UDP</p>
<p>C. UDP inside RTP</p>
<p>D. RTP inside UDP</p>
<p><strong>Answer: D </strong></p>
<p><strong>QUESTION NO: 73 What does the PBX use to determine the destination of a call? </strong></p>
<p>A. An ISDN ANI packet</p>
<p>B. A blocked/permitted call list</p>
<p>C. An analysis of the dialled digits</p>
<p>D. Historic requests from the specific phone extension</p>
<p><strong>Answer: C </strong></p>
<p><strong>QUESTION NO: 74 You are the network technician at TestKing. VoIP is implemented on the TestKing network. Your newly appointed TestKing trainee wants to know what is used to carry VoIP voice packets on this network. </strong></p>
<p><strong>What will your reply be? </strong></p>
<p>A. ICMP/IP</p>
<p>B. RTP/TCP</p>
<p>C. RTP/UDP</p>
<p>D. STP/UDP</p>
<p>E. RTP/RCMP</p>
<p><strong>Answer: C </strong></p>
<p><strong>QUESTION NO: 75 Which lower layer protocol does the Real-Time Protocol (RTP) use? </strong></p>
<p>A. TCP</p>
<p>B. UDP</p>
<p>C. WDP</p>
<p>D. HTTP</p>
<p>E. RTCP</p>
<p><strong>Answer: B</strong></p>
<div style='clear:both'></div><img src="http://www.realexam.net/?ak_action=api_record_view&id=4717&type=feed" alt="" /><img src="http://feeds.feedburner.com/~r/certting/~4/h5RF-TmtmfI" height="1" width="1"/><img src="http://feeds.feedburner.com/~r/certting/~4/Uyr8bGa8yPI" height="1" width="1"/><img src="http://feeds.feedburner.com/~r/certting/~4/UWBb6ip4Kfc" height="1" width="1"/>]]></content:encoded>
			<wfw:commentRss>http://www.realexam.net/cisco-642-432cisco-voice-certification-q36-q75/4717.html/feed</wfw:commentRss>
		<slash:comments>0</slash:comments>
		<feedburner:origLink>http://www.realexam.net/cisco-642-432cisco-voice-certification-q36-q75/4717.html</feedburner:origLink><feedburner:origLink>http://feedproxy.google.com/~r/certting/~3/h5RF-TmtmfI/4717.html</feedburner:origLink><feedburner:origLink>http://feedproxy.google.com/~r/certting/~3/Uyr8bGa8yPI/4717.html</feedburner:origLink></item>
		<item>
		<title>Cisco 642-432:Cisco voice certification (Q1-Q35)</title>
		<link>http://feedproxy.google.com/~r/certting/~3/lMx8lNNJGiQ/4715.html</link>
		<comments>http://www.realexam.net/cisco-642-432cisco-voice-certification-q1-q35/4715.html#comments</comments>
		<pubDate>Sat, 24 Jul 2010 15:27:18 +0000</pubDate>
		<dc:creator>Johnny</dc:creator>
				<category><![CDATA[CCVP Training]]></category>
		<category><![CDATA[642-432]]></category>
		<category><![CDATA[ccvp]]></category>
		<category><![CDATA[cisco certification]]></category>
		<category><![CDATA[cvoice]]></category>

		<guid isPermaLink="false">http://www.realexam.net/?p=4715</guid>
		<description><![CDATA[Section A QUESTION NO: 1 You are the voice technician at TestKing. TestKing has its offices in Great Britain. You need to install a Cisco router to support IP Telephony services with direct-connected analog phones. You need to emulate the local PSTN prov... ]]></description>
			<content:encoded><![CDATA[<p><strong>Section A </strong></p>
<p><strong>QUESTION NO: 1 You are the voice technician at TestKing. TestKing has its offices in Great Britain. You need to install a Cisco router to support IP Telephony services with direct-connected analog phones. You need to emulate the local PSTN provider. </strong></p>
<p><strong>What FXS port parameter do you need to change? </strong></p>
<p>A. Pulse</p>
<p>B. Signal</p>
<p>C. Cptone</p>
<p>D. Busyout</p>
<p>E. Description</p>
<p><strong>Answer: C </strong></p>
<p><strong>QUESTION NO: 2 TestKing distributes computer components and has warehouses in New York and Chicago. Headquarters is located in Washington, DC. To keep costs low, all inside sales associates are located at headquarters. </strong></p>
<p><strong>Your want to provide a direct analog telephone connection to the inside sales teams from the pick-up counters at the warehouses. This connection should not require the inside sales teams to dial any digits. </strong></p>
<p><strong>One of the warehouses is having a problem with their sales phone. </strong></p>
<p><strong>You receive the following output: </strong></p>
<p>altwhse#show voice port 1/0:1</p>
<p>Foreign Exchange Office</p>
<p>Type of VoicePort is E&amp;M</p>
<p>Operation State is DORMANT</p>
<p>Administrative State is UP</p>
<p>The Last Interface Down Failure Cause is Administrative Shutdown</p>
<p>Description is not set</p>
<p>Noise Regeneration is enabled</p>
<p>Non Linear Processing is enabled</p>
<p>Music On Hold Threshold is Set to –38 dBm In Gain is Set to 0 dB Out Attenuation is Set to 0 dB Echo Cancellation is enabled Echo Cancel Coverage is set to 8 ms Connection Mode is plar Connection Number is 2000 Initial Time Out is set to 10 s Interdigit Time Out is set to 10 s Call-Disconnect Time Out is set to 60 s Ringing Time Out is set to 180 s Region Tone is set for US</p>
<p><strong>What is the cause of the problem? </strong></p>
<p>A. VoicePort type is incorrect.</p>
<p>B. Echo cancellation is enabled.</p>
<p>C. Connection Number is not required.</p>
<p>D. Interdigit Time Out is set to 10 seconds.</p>
<p><strong>Answer: A </strong></p>
<p><strong>QUESTION NO: 3 You are the Voice technician at TestKing. Your newly appointed TestKing trainee wants to know what types of trunks Cisco support with the connection trunk command. </strong></p>
<p><strong>What will your reply be? (Choose three) </strong></p>
<p>A. FXS to FXS trunks, FXS to FXO trunks, and FXS to E&amp;M trunks</p>
<p>B. FXS to FXS trunks, FXS to FXO trunks, and E&amp;M to E&amp;M trunks</p>
<p>C. FXS to FXS trunks, FXO to FXO trunks, and E&amp;M to E&amp;M trunks</p>
<p>D. FXO to FXS trunks, FXO to FXO trunks, and E&amp;M to E&amp;M trunks</p>
<p>E. FXS to FXS trunks, FXS to E&amp;M trunks, and E&amp;M to E&amp;M trunks</p>
<p><strong>Answer: B </strong></p>
<p><strong>QUESTION NO: 4 What happens if no incoming dial peer matches a router or gateway? </strong></p>
<p>A. The incoming call leg takes an alternate path.</p>
<p>B. The incoming call leg matches the default dial peer.</p>
<p>C. The incoming call leg sends a busy to the originator.</p>
<p>D. The incoming call leg is denied and the call is dropped.</p>
<p><strong>Answer: B </strong></p>
<p><strong>QUESTION NO: 5 You are the network engineer at TestKing. TestKing has its headquarters in New York and a branch office in New Hamshire. You want to configure a permanent connection between the PBX at headquarters and the PBX at the branch office. </strong></p>
<p><strong>The following configuration is used at the New York site: </strong></p>
<p>dial-peer voice 20 pots  destination-pattern 20  port 1.0:1</p>
<p>dial-peer voice 41 voip  destination-pattern 41 session target ipv4:10.2.0.20</p>
<p><strong>The following configuration is used at the New Hamshire site: </strong></p>
<p>dial-peer voice 40 pots  destination-pattern 41  port 1.0:1</p>
<p>dial-peer voice 20 voip  destination-pattern 20 session target ipv4:10.4.1.41</p>
<p><strong>What must be added to the voice port configuration at the New York site? </strong></p>
<p>A. connection trunk 20</p>
<p>B. connection trunk 41</p>
<p>C. connection tie-line 20</p>
<p>D. connection tie-line 41</p>
<p><strong>Answer: B Explanation: </strong>You must specify the same number in the <strong>connection trunk</strong> voice port command as in the appropriate dial peer destination-pattern command in order to create a permanent trunk.</p>
<p><strong>QUESTION NO: 6 TestKing sells managed IP Phone service to businesses in multi-tenant units. TestKing has POPs in many cities, so all of their dial peer patterns are based on 10 digit numbers. Users dial 9 for local calls, followed by the 7 digital local number. </strong></p>
<p><strong>The following dial peer has been configured in a New York POP: </strong></p>
<p>dial-peer voice 595 pots  destination-pattern 595  port 1/0:24</p>
<p><strong>A user dials a local number, 9-638-4422. What command must be configured in the gateway to allow the call to complete? </strong></p>
<p>A. prefix 595</p>
<p>B. forward-digits 7</p>
<p>C. rule 1 9&#8230;&#8230;.595&#8230;&#8230;.</p>
<p>D. forward 9&#8230;&#8230;.595&#8230;&#8230;.</p>
<p>E. num-exp 9&#8230;&#8230;.595&#8230;&#8230;.</p>
<p><strong>Answer: E </strong></p>
<p><strong>QUESTION NO: 7 You are the Voice technician at TestKing. Your newly appointed TestKing trainee wants to know what configuration would define a destination pattern for all of the 1000 and 2000 range of extensions starting with the numbers 555. </strong></p>
<p><strong>What will your reply be? </strong></p>
<p>A. 5551…</p>
<p>B. 5552…</p>
<p>C. 555[1-2]…</p>
<p>D. 555[100-200]…</p>
<p>E. 555[1000-2000]…</p>
<p><strong>Answer: C </strong></p>
<p><strong>QUESTION NO: 8 You are the Voice technician at TestKing. The TestKing network uses RTCP. Your newly appointed TestKing trainee wants to know what RTCP does. </strong></p>
<p><strong>What will your reply be? </strong></p>
<p>A. It provides independent services irrespective of RTP.</p>
<p>B. It provides compression techniques to save bandwidth.</p>
<p>C. It provides in-band control information for an RTP flow.</p>
<p>D. It provides out-of-band control information for an RTP flow.</p>
<p><strong>Answer: D Explanation: </strong>RTCP provides out-of-band control information for an RTP flow.</p>
<p><strong>QUESTION NO: 9 You are the Voice technician at TestKing. The TestKing network uses VoIP. Your newly appointed TestKing trainee wants to know what the disadvantage of using VoIP rather than VoFR or VoATM are. </strong></p>
<p><strong>What will your reply be? </strong></p>
<p>A. Data can arrive out of sequence.</p>
<p>B. Networks are complicated to design.</p>
<p>C. Data units can arrive out of sequence.</p>
<p>D. Network failures are not automatically found.</p>
<p><strong>Answer: C </strong></p>
<p><strong>QUESTION NO: 10 You are the network engineer at TestKing. You have configured real-time call control processing on the TestKing VoIP network. You want to verify this configuration. </strong></p>
<p><strong>What command should you use? </strong></p>
<p>A. debug voip rtcp</p>
<p>B. debug call control</p>
<p>C. debug voip ccapi inout</p>
<p>D. debug voip call control</p>
<p>E. debug voice call control</p>
<p><strong>Answer: C </strong></p>
<p><strong>QUESTION NO: 11 You are the network engineer at TestKing. Your newly appointed TestKing trainee wants to know what a voice gateway is. </strong></p>
<p><strong>What will your reply be? </strong></p>
<p>A. It is a device that connects two dissimilar networks.</p>
<p>B. It is a device that transports voice and restricts data.</p>
<p>C. It is a device that can support only a distributed call processing model.</p>
<p>D. It is a device that cannot be connected to the traditional PSTN network.</p>
<p><strong>Answer: B </strong></p>
<p><strong>QUESTION NO: 12 </strong></p>
<p><strong>TestKing has its headquarters in New York and branch offices in Delaware, Detroit and Denver. Each office has an analog phone at each location. These phones are connected to an FXS port on the on-site router. The Finance department at the Denver office is unable to make any phone class from these analog phones. </strong></p>
<p><strong>You receive the following output: </strong></p>
<p>2611#s voice port 1/0/0</p>
<p>Foreign Exchange Station 1/0/0 Slot is 1, Sub-unit is 0,</p>
<p>Port is 0</p>
<p>Type of VoicePort is FXS</p>
<p>Operation State is DORMANT</p>
<p>Administrative State is UP</p>
<p>No Interface Down Failure</p>
<p>Description is not set</p>
<p>Noise Regeneration is enabled</p>
<p>Non Linear Processing is enabled</p>
<p>Non Linear Mute is disabled</p>
<p>Non Linear Threshold is –21 dB</p>
<p>Music On Hold Threshold is Set to 38 dBm</p>
<p>In Gain is Set to 0 dB</p>
<p>Out Attention is Set to 3 dB</p>
<p>Echo Cancellation is enabled</p>
<p>Echo Cancellation NLP mute is disabled</p>
<p>Echo Cancellation NLP threshold is –21 dB</p>
<p>Echo Cancel Coverage is set to default</p>
<p>Playout-delay Mode is set to default</p>
<p>Playout-delay Nominal is set to 60 ms</p>
<p>Playout-delay Maximal is set to 200 ms</p>
<p>Playout-delay Minimum mode is set to default, value 40 ms</p>
<p>Playout-delay Fax is set to 300 ms</p>
<p>Connection Mode is normal</p>
<p>Connection Number is not set</p>
<p>Initial Time Out is set to 10 s</p>
<p>Interdigit Time Out is set to 10 s</p>
<p>Call Disconnect Time Out is set to 60 s</p>
<p>Ringing Time Out is set to 180</p>
<p>Wait Release Time Out is set to 30 s</p>
<p>Companding Type is u-law</p>
<p>Region Tone is set for US</p>
<p>Analog Info Follows:</p>
<p>Currently processing none</p>
<p>Maintenance Mode Set to None (not in mtc mode)</p>
<p>Number of signaling protocol errors are 0</p>
<p>Impedance is set to 600r Ohm Station name None, Station number None</p>
<p>Voice card specific Info Follows: Signal Type is groundStart Ring Frequency is 25 Hz Hook Status is On Hook Ring Active Status is inactiveRing Ground Status is inactiveTip Ground Status is inactive Digit Duration Status is inactive Digit Duration Timing is set to 100 ms InterDigit Duration Timing is set to 100 ms No disconnect acknowledge Ring Cadence is defined by CPTone Selection Ring Cadance are [20 40] * 100 msec</p>
<p>2611#</p>
<p><strong>What is the cause of this problem? </strong></p>
<p>A. The cptone is incorrect</p>
<p>B. The dial-type is incorrect</p>
<p>C. The signal type is incorrect</p>
<p>D. The playout-delay is incorrect</p>
<p>E. The disconnect-ack is incorrect</p>
<p><strong>Answer: C </strong></p>
<p><strong>QUESTION NO: 13 You are the network engineer at TestKing. TestKing has been using the following dial peer codec command: </strong></p>
<p>Codec g729r8</p>
<p><strong>You reconfigure the dial peers with the following command: </strong></p>
<p>Codec g729ar8 bytes 10</p>
<p><strong>How will this reconfiguration affect the voice network bandwidth and delay characteristics? (Choose two.) </strong></p>
<p>A. There will be no change.</p>
<p>B. Delay will increase on a per call basis.</p>
<p>C. Delay will decrease on a per call basis.</p>
<p>D. Bandwidth consumption will decrease on a per call basis.</p>
<p>E. Bandwidth consumption will increase on a per call basis.</p>
<p><strong>Answer: C, E </strong></p>
<p><strong>QUESTION NO: 14 You are the network engineer at TestKing. Your newly appointed TestKing trainee wants to know which features render VAD ineffective. </strong></p>
<p><strong>What will your reply be? (Choose two.) </strong></p>
<p>A. Fax</p>
<p>B. CNG</p>
<p>C. Call waiting</p>
<p>D. Music on hold</p>
<p>E. Call forwarding</p>
<p><strong>Answer: A, D </strong></p>
<p><strong>QUESTION NO: 15 You are the VoIP engineer at TestKing. A TestKing user complains that she gets a busy tone instead of a dial tone when she tries to call another user. You want to troubleshoot this problem. </strong></p>
<p><strong>What command should you use? </strong></p>
<p>A. show voice dsp</p>
<p>B. show voice path</p>
<p>C. show voice connection</p>
<p>D. show voice port summary</p>
<p>E. show dial-peer voice summary</p>
<p><strong>Answer: A </strong></p>
<p><strong>QUESTION NO: 16 You are the Voice engineer at TestKing. Your newly appointed TestKing trainee wants to know what compressed RTP does. </strong></p>
<p><strong>What will your reply be? </strong></p>
<p>A. It significantly reduce packet delay</p>
<p>B. It significantly reduce total bandwidth</p>
<p>C. It significantly reduce Frame Relay overhead</p>
<p>D. It significantly reduce the total number of packets</p>
<p><strong>Answer: B </strong></p>
<p><strong>QUESTION NO: 17 You are the network engineer at TestKing. TestKing has its offices in London. You are installing a voice gateway. </strong></p>
<p><strong>What do you need to verify? (Choose two.) </strong></p>
<p>A. The PSTN standards in England.</p>
<p>B. Encryption capabilities legalities.</p>
<p>C. The service provider installing the gateway.</p>
<p>D. Supplementary service including fax and modem.</p>
<p><strong>Answer: A, B </strong></p>
<p><strong>QUESTION NO: 18 What identifies an MGCP endpoint? </strong></p>
<p>A. A two part identifier that consists of the telephone number and local name of the user.</p>
<p>B. A two part identifier that consists of the telephone number and remote name of the user.</p>
<p>C. A two part identifier that consists of the domain name of the user and the IP address of the gateway.</p>
<p>D. A two part identifier that consists of the local name of the user and the domain name of the gateway.</p>
<p><strong>Answer: D </strong></p>
<p><strong>QUESTION NO: 19 You are the network engineer at TestKing. You to connect a Cisco voice gateway to a PBX or the PSTN via ISDN (PRI, QSIG, BRI). </strong></p>
<p><strong>What are two attributes of the PBX/PSTN switch that must be known to understand which features to configure on the voice gateway to connect successfully to it? (Choose two) </strong></p>
<p>A. Whether Q.921 or Q.931 is supported by the PBX/PSTN switch.</p>
<p>B. Whether Symmetric mode is supported by the PBX/PSTN switch.</p>
<p>C. Which PRI/BRI switch-type is supported by the PBX/PSTN switch.</p>
<p>D. Whether network or user side is supported by the PBX/PSTN switch.</p>
<p>E. Whether wink, delay dial, or immediate dial is supported by the PBX/PSTN switch.</p>
<p><strong>Answer: C, D </strong></p>
<p><strong>QUESTION NO: 20 Your newly appointed TestKing trainee wants to know what protocol negotiates the codec type for H.323 sessions. </strong></p>
<p><strong>What will your reply be? </strong></p>
<p>A. H.225</p>
<p>B. H.245</p>
<p>C. Q.931</p>
<p>D. Q.932</p>
<p>E. H.320</p>
<p><strong>Answer: B </strong></p>
<p><strong>QUESTION NO: 21 You are the Voice technician at TestKing. Your newly appointed TestKing trainee wants to know what request method initiates a SIP call setup. </strong></p>
<p><strong>What will your reply be? </strong></p>
<p>A. ACK</p>
<p>B. INVITE</p>
<p>C. OPTIONS</p>
<p>D. REGISTER</p>
<p>E. DISCOVER</p>
<p><strong>Answer: B </strong></p>
<p><strong>QUESTION NO: 22 You are the network engineer at TestKing. You want to verify the registration of the gateway with the call agent. </strong></p>
<p><strong>Which show command should you use? </strong></p>
<p>A. show mgcp</p>
<p>B. show call agent</p>
<p>C. show gateway mgcp</p>
<p>D. show endpoint mgcp</p>
<p>E. show call active voice</p>
<p><strong>Answer: A </strong></p>
<p><strong>QUESTION NO: 23 You are the Voice technician at TestKing. Your newly appointed TestKing trainee wants to know what makes it possible for gatekeepers to communicate with each other. </strong></p>
<p><strong>What will your reply be? </strong></p>
<p>A. RTP</p>
<p>B. RAS channel</p>
<p>C. call signaling channel</p>
<p>D. H.245 control channel</p>
<p>E. Q.931 control channel</p>
<p><strong>Answer: B </strong></p>
<p><strong>QUESTION NO: 24 What does gateway require to function as a translating gateway? </strong></p>
<p>A. The capacity to translate the audio.</p>
<p>B. The ability to recognize the call control procedures of both connecting endpoints.</p>
<p>C. The ability to establish separate RTP sessions with the originating and terminating endpoints.</p>
<p>D. The ability to recognize the call control procedures for at least one of the connecting endpoints.</p>
<p><strong>Answer: B </strong></p>
<p><strong>QUESTION NO: 25 You are the Voice engineer at TestKing. Numerous TestKing users complain that they are unable to complete calls through the MGCP network. You want to verify the extent of the problem by reviewing a count of the successful and unsuccessful control commands. </strong></p>
<p><strong>Which command should you use? </strong></p>
<p>A. show mgcp</p>
<p>B. show mgcp count</p>
<p>C. show mgcp statistics</p>
<p>D. show call active voice</p>
<p>E. show call history voice</p>
<p><strong>Answer: C </strong></p>
<p><strong>QUESTION NO: 26 Which of the following call control models are based on decentralized call control? (Choose two.) </strong></p>
<p>A. SIP</p>
<p>B. CAS</p>
<p>C. H.323</p>
<p>D. Q.931</p>
<p>E. MGCP</p>
<p><strong>Answer: A, C </strong></p>
<p><strong>QUESTION NO: 27 You are the Voice engineer at TestKing. TestKing has an H.323 gatekeeper. Your newly appointed TestKing trainee wants to know what functions are supported by this gatekeeper. </strong></p>
<p><strong>What will your reply be? (Choose four.) </strong></p>
<p>A. It provides services to registered endpoints.</p>
<p>B. It converts an alias address to an IP address.</p>
<p>C. It responds to bandwidth requests and modifications.</p>
<p>D. It provides translation between audio, video, and data formats.</p>
<p>E. It provides conversion between call setup signals and procedures.</p>
<p>F. It limits access to network resources based on call bandwidth restrictions.</p>
<p>G. It provides conversion between communication control signals and procedures.</p>
<p><strong>Answer: A, B, C, F </strong></p>
<p><strong>QUESTION NO: 28 You are the network engineer at TestKing. You are configuring a connection to a SIP proxy server. </strong></p>
<p><strong>Which command would you use to specify the IP address of the server? </strong></p>
<p>A. sip-ua  sip-server ipv4:1.2.3.4</p>
<p>B.      sip-ua  sip-server target:1.2.3.4</p>
<p>C.      dial-peer voice 1 voip session target sip:1.2.3.4</p>
<p>D.      dial-peer voice 1 voip session target sip-server:1.2.3.4</p>
<p><strong>Answer: A </strong></p>
<p><strong>QUESTION NO: 29 With regard to SIP and SDP, which of the following statements is true? </strong></p>
<p>A. SIP is similar to RAS and SDP is similar to RTP</p>
<p>B. SIP is similar to RTP and SDP is similar to RAS</p>
<p>C. SIP is similar to H.225 and SDP is similar to H.245</p>
<p>D. SIP is similar to H.245 and SDP is similar to H.323</p>
<p>E. SIP is similar to H.323 and SDP is similar to H.225</p>
<p><strong>Answer: C </strong></p>
<p><strong>QUESTION NO: 30 You are the Voice technician at TestKing 60. Your newly appointed TestKing trainee wants to know on what type of port you would set impedance. </strong></p>
<p><strong>What will your reply be? </strong></p>
<p>A. T1</p>
<p>B. E1</p>
<p>C. FXS</p>
<p>D. FXO</p>
<p>E. E&amp;M</p>
<p><strong>Answer: D </strong></p>
<p><strong>QUESTION NO: 31 You are the network engineer at TestKing. You are deploying an IP telephony solution using MGCP. The call agent expects the gateway to use UDP port 2427 but an application on the TestKing network is already using that port. You want to use port 4662 instead. </strong></p>
<p><strong>Which command would allow you to change the UDP port that the call agents and gateway communicate on? </strong></p>
<p>A. Router(config)# mgcp UDP 4662</p>
<p>B. Router(config)# mgcp gateway 4662</p>
<p>C. Router(config)# mgcp call-agent 4662</p>
<p>D. Router(config-dial-peer)#application MGCPAPP 4662</p>
<p>E. Router(config)# mgcp default-package gm-package 4662</p>
<p><strong>Answer: C </strong></p>
<p><strong>QUESTION NO: 32 Upon which protocol model is the SIP protocol based? </strong></p>
<p>A. HTML</p>
<p>B. H.323</p>
<p>C. Q.931</p>
<p>D. MGCP</p>
<p>E. HTPP/WWW</p>
<p><strong>Answer: E </strong></p>
<p><strong>QUESTION NO: 33 You are the network engineer at TestKing. Your newly appointed TestKing trainee wants to know how an endpoint determines the address of the gatekeeper. </strong></p>
<p><strong>What will your reply be? (Choose two.) </strong></p>
<p>A. The endpoint issues a GCP.</p>
<p>B. The endpoint issues a GRQ.</p>
<p>C. The endpoint queries the registrar server.</p>
<p>D. The endpoint is preconfigured to recognize the domain name or IP address of its gatekeeper.</p>
<p><strong>Answer: B, D </strong></p>
<p><strong><br />
</strong></p>
<p><strong>QUESTION NO: 34 You are the network engineer at TestKing. The TestKing network is shown in the following exhibit: </strong></p>
<p><strong><img class="alignnone" title="realexam" src="http://farm5.static.flickr.com/4095/4824079648_672ddb5fcf.jpg" alt="" width="334" height="170" /><br />
</strong></p>
<p><strong>If the show gatekeeper calls</strong><strong> command shows a total of five active calls on the gatekeeper, how many call legs would the show call active voice</strong><strong>command display on Gateway A? </strong></p>
<p>A. 2</p>
<p>B. 5</p>
<p>C. 6</p>
<p>D. 10</p>
<p>E. 15</p>
<p><strong>Answer: D </strong></p>
<p><strong>QUESTION NO: 35 You are the network engineer at TestKing. Your newly appointed TestKing trainee wants to know which functions use UDP as their transport mechanism. </strong></p>
<p><strong>What will your reply be? (Choose two) </strong></p>
<p>A. RTP</p>
<p>B. RAS control function</p>
<p>C. call signaling function</p>
<p>D. H.245 control function</p>
<p><strong>Answer: A, B </strong></p>
<div style='clear:both'></div><img src="http://www.realexam.net/?ak_action=api_record_view&id=4715&type=feed" alt="" /><img src="http://feeds.feedburner.com/~r/certting/~4/qghHWlUVawo" height="1" width="1"/><img src="http://feeds.feedburner.com/~r/certting/~4/3sClaaqpIdg" height="1" width="1"/><img src="http://feeds.feedburner.com/~r/certting/~4/lMx8lNNJGiQ" height="1" width="1"/>]]></content:encoded>
			<wfw:commentRss>http://www.realexam.net/cisco-642-432cisco-voice-certification-q1-q35/4715.html/feed</wfw:commentRss>
		<slash:comments>0</slash:comments>
		<feedburner:origLink>http://www.realexam.net/cisco-642-432cisco-voice-certification-q1-q35/4715.html</feedburner:origLink><feedburner:origLink>http://feedproxy.google.com/~r/certting/~3/qghHWlUVawo/4715.html</feedburner:origLink><feedburner:origLink>http://feedproxy.google.com/~r/certting/~3/3sClaaqpIdg/4715.html</feedburner:origLink></item>
		<item>
		<title>CCIE Security: Certificate-based ACLs</title>
		<link>http://feedproxy.google.com/~r/certting/~3/Lde4MlrStaU/4713.html</link>
		<comments>http://www.realexam.net/ccie-security-certificate-based-acls/4713.html#comments</comments>
		<pubDate>Fri, 23 Jul 2010 13:39:15 +0000</pubDate>
		<dc:creator>Johnny</dc:creator>
				<category><![CDATA[CCIE Training]]></category>
		<category><![CDATA[CCSP Training]]></category>
		<category><![CDATA[ccie security]]></category>
		<category><![CDATA[cisco acl]]></category>
		<category><![CDATA[cisco lab]]></category>

		<guid isPermaLink="false">http://www.realexam.net/?p=4713</guid>
		<description><![CDATA[A big shout out to all the students in the Raleigh Security CCIE bootcamp last week.   I had a blast!   Thank you for all your hard work, as well as the after hours discussions about the unknown, and why people feel they know it. I promised a few blo... ]]></description>
			<content:encoded><![CDATA[<p>A big shout out to all the students in the Raleigh Security CCIE  bootcamp last week.   I had a blast!   Thank you for all your hard work,  as well as the after hours discussions about the unknown, and why  people feel they know it.</p>
<p>I promised a few blog posts related to security over the next few  weeks, and this one is regarding Certificate-based ACLs.</p>
<p>This blog may also serve as a review on how to configure the CA  clients so that their certificates contain various fields and values,  such as subject-name.</p>
<p>Let’s use this diagram for the backdrop of our discussion:</p>
<p><img title="3 routers in a  row-NO-user" src="http://blog.ine.com/wp-content/uploads/2010/06/3-routers-in-a-row-NO-user.png" alt="3 routers in a row-NO-user" width="505" height="71" /></p>
<p>R2 will be the NTP and CA server with R1 and R3 as IPSec VPN peers.   (Remember, with certificates we really do need time to be on “our  side”).  <img src="http://blog.ine.com/wp-includes/images/smilies/icon_smile.gif" alt=":)" /></p>
<p>R1’s configuration for the trustpoint is as follows:</p>
<pre>crypto pki trustpoint R2
enrollment url http://2.2.2.2:80
serial-number
ip-address 10.0.0.1
subject-name cn=R1,ou=ccsp,o=ine,st=NV,c=US
revocation-check none</pre>
<p>R3’s configuration for the trustpoint is here:</p>
<pre>crypto pki trustpoint R2
enrollment url http://2.2.2.2:80
serial-number
ip-address 23.0.0.3
subject-name cn=R3,ou=ccie,o=ine,st=NV,c=US
revocation-check none</pre>
<p>The problem, is that any device that has a valid certificate from R2,  would be able to authenticate with R1 and R3 (from a CA perspective  regarding certificates).   If R3 wanted to limit the peers it would  authenticate with, we can use a certificate map, which acts as  Certificate based Access Control.  A certificate map looks for specific  fields from the peers certificate, and values for those fields  (specified by the certificate map).   The router will only accept a  certificate from a peer if the certificate map specified fields/values  from the would-be peer’s certificate match, and if they don’t match,  then the IKE phase 1 won’t complete.     We could match several fields  from the peers certificate.  The <em>field-name </em>is one of the  following case-insensitive name strings or a date:</p>
<p><a name="wp1052978"></a></p>
<p><a name="wp1052979"></a> –<img src="http://www.cisco.com/en/US/i/templates/blank.gif" border="0" alt="" width="17" height="2" /><strong>subject-name</strong></p>
<p><a name="wp1052979"></a>–<img src="http://www.cisco.com/en/US/i/templates/blank.gif" border="0" alt="" width="17" height="2" /><strong>issuer-name</strong></p>
<p><a name="wp1052980"></a>–<img src="http://www.cisco.com/en/US/i/templates/blank.gif" border="0" alt="" width="17" height="2" /><strong>unstructured-subject-name</strong></p>
<p><a name="wp1052981"></a>–<img src="http://www.cisco.com/en/US/i/templates/blank.gif" border="0" alt="" width="17" height="2" /><strong>alt-subject-name</strong></p>
<p><a name="wp1052982"></a>–<img src="http://www.cisco.com/en/US/i/templates/blank.gif" border="0" alt="" width="17" height="2" /><strong>name</strong></p>
<p><a name="wp1052983"></a>–<img src="http://www.cisco.com/en/US/i/templates/blank.gif" border="0" alt="" width="17" height="2" /><strong>valid-start</strong></p>
<p><a name="wp1052984"></a>–<img src="http://www.cisco.com/en/US/i/templates/blank.gif" border="0" alt="" width="17" height="2" /><strong>expires-on</strong></p>
<p>The <em>match-criteria</em> is one of the following :</p>
<p><a name="wp1053261"></a>–<img src="http://www.cisco.com/en/US/i/templates/blank.gif" border="0" alt="" width="17" height="2" /><strong>eq</strong>—equal (valid  for name and  date fields)</p>
<p><a name="wp1053262"></a>–<img src="http://www.cisco.com/en/US/i/templates/blank.gif" border="0" alt="" width="17" height="2" /><strong>ne</strong>—not equal (valid for name and  date fields)</p>
<p><a name="wp1053263"></a>–<img src="http://www.cisco.com/en/US/i/templates/blank.gif" border="0" alt="" width="17" height="2" /><strong>co</strong>—contains (valid only for name  fields)</p>
<p><a name="wp1053264"></a>–<img src="http://www.cisco.com/en/US/i/templates/blank.gif" border="0" alt="" width="17" height="2" /><strong>nc</strong>—does not contain (valid only  for name fields)</p>
<p><a name="wp1053265"></a>–<img src="http://www.cisco.com/en/US/i/templates/blank.gif" border="0" alt="" width="17" height="2" /><strong>lt</strong>—less than (valid only for  date fields)</p>
<p><a name="wp1053266"></a>–<img src="http://www.cisco.com/en/US/i/templates/blank.gif" border="0" alt="" width="17" height="2" /><strong>ge</strong>—greater than or equal (valid  only for date fields)</p>
<p>To begin, lets look at what is in R1’s certificate.</p>
<pre>R1#show crypto pki certificates
Certificate
 Status: Available
 Certificate Serial Number: 0x2
 Certificate Usage: General Purpose
 Issuer:
 cn=R2
 ou=CA-OF-THE-WORLD
 o=INE
 st=NV
 c=US
<strong> Subject:</strong>
 Name: R1.ine.com
 IP Address: 10.0.0.1
 Serial Number: XXXXXXXXXXX
 serialNumber=XXXXXXXXXXX+ipaddress=10.0.0.1+hostname=R1.ine.com
<strong> cn=R1</strong>
 ou=ccsp
 o=ine
 st=NV
 c=US
 Validity Date:
 start date: 14:05:12 PDT Jun 15 2010
 end   date: 14:05:12 PDT Jun 15 2011
 Associated Trustpoints: R2</pre>
<p>We have several choices, but let’s select the <strong>cn</strong> field in our example.    On  R3, we will create a certificate map, that is looking for the  subject-name to contain the value of “R1″.  The certificate map is  inserted into the PKI trustpoint configuration.</p>
<pre><strong>R3:</strong></pre>
<pre>crypto pki certificate map CERT-MAP 1
 subject-name <strong>co R1
 </strong>exit<strong> </strong></pre>
<pre>crypto pki trustpoint R2
 match certificate CERT-MAP
 exit</pre>
<p>With this in place, the IKE phase 1 works, and encrypted traffic  flows between the peers.</p>
<p>If we <em>change </em>the Certificate Map to look for for the string  R9 (which won’t match inside of R1’s certificate) and then test the VPN  connection, we can see the debug messages and the certificate error:</p>
<pre>R3(config)#crypto pki certificate map CERT-MAP 1
R3(ca-certificate-map)#<strong>no</strong> subject-name co r1
R3(ca-certificate-map)# subject-name co <strong>r9</strong></pre>
<pre>R3#debug crypto isakmp
Crypto ISAKMP debugging is on

R3#clear crypto sa
R3#clear crypto isakmp

R3#ping 1.1.1.1 so lo 0 re 1

Type escape sequence to abort.
Sending 1, 100-byte ICMP Echos to 1.1.1.1, timeout is 2 seconds:
Packet sent with a source address of 3.3.3.3

IPSEC(sa_request): ,
 (key eng. msg.) OUTBOUND local= 23.0.0.3, remote= 10.0.0.1,
 local_proxy= 3.3.3.3/255.255.255.255/0/0 (type=1),
 remote_proxy= 1.1.1.1/255.255.255.255/0/0 (type=1),
 protocol= ESP, transform= esp-aes esp-sha-hmac  (Tunnel),
 lifedur= 3600s and 4608000kb,
 spi= 0x0(0), conn_id= 0, keysize= 128, flags= 0x0
ISAKMP:(0): SA request profile is (NULL)
ISAKMP: Created a peer struct for 10.0.0.1, peer port 500
ISAKMP: New peer created peer = 0x66031B38 peer_handle = 0x80000009
ISAKMP: Locking peer struct 0x66031B38, refcount 1 for isakmp_initiator
ISAKMP: local port 500, remote port 500
ISAKMP: set new node 0 to QM_IDLE
ISAKMP: Find a dup sa in the avl tree during calling isadb_insert sa = 66033338
ISAKMP:(0):Can not start Aggressive mode, trying Main mode.
ISAKMP:(0):No pre-shared key with 10.0.0.1!
ISAKMP:(0): constructed NAT-T vendor-rfc3947 ID
ISAKMP:(0): constructed NAT-T vendor-07 ID
ISAKMP:(0): constructed NAT-T vendor-03 ID
ISAKMP:(0): constructed NAT-T vendor-02 ID
ISAKMP:(0):Input = IKE_MESG_FROM_IPSEC, IKE_SA_REQ_MM
ISAKMP:(0):Old State = IKE_READY  New State = IKE_I_MM1

ISAKMP:(0): beginning Main Mode exchange
ISAKMP:(0): sending packet to 10.0.0.1 my_port 500 peer_port 500 (I) MM_NO_STATE
ISAKMP:(0):Sending an IKE IPv4 Packet.
ISAKMP (0:0): received packet from 10.0.0.1 dport 500 sport 500 Global (I) MM_NO_STATE
ISAKMP:(0):Input = IKE_MESG_FROM_PEER, IKE_MM_EXCH
ISAKMP:(0):Old State = IKE_I_MM1  New State = IKE_I_MM2

ISAKMP:(0): processing SA payload. message ID = 0
ISAKMP:(0): processing vendor id payload
ISAKMP:(0): vendor ID seems Unity/DPD but major 69 mismat.
Success rate is 0 percent (0/1)
R3#ch
ISAKMP (0:0): vendor ID is NAT-T RFC 3947
ISAKMP : Scanning profiles for xauth ...
ISAKMP:(0):Checking ISAKMP transform 1 against priority 65535 policy
ISAKMP:      encryption DES-CBC
ISAKMP:      hash SHA
ISAKMP:      default group 1
ISAKMP:      auth RSA sig
ISAKMP:      life type in seconds
ISAKMP:      life duration (VPI) of  0x0 0x1 0x51 0x80
<strong>ISAKMP:(0):atts are acceptable. Next payload is 0</strong>
ISAKMP:(0):Acceptable atts:actual life: 0
ISAKMP:(0):Acceptable atts:life: 0
%CRYPTO-4-IKE_DEFAULT_POLICY_ACCEPTED: IKE default policy was matched and is being used.
ISAKMP:(0):Fill atts in sa vpi_length:4
ISAKMP:(0):Fill atts in sa life_in_seconds:86400
ISAKMP:(0):Returning Actual lifetime: 86400
ISAKMP:(0)::Started lifetime timer: 86400.

ISAKMP:(0): processing vendor id payload
ISAKMP:(0): vendor ID seems Unity/DPD but major 69 mismatch
ISAKMP (0:0): vendor ID is NAT-T RFC 3947
ISAKMP:(0):Input = IKE_MESG_INTERNAL, IKE_PROCESS_MAIN_MODE
ISAKMP:(0):Old State = IKE
R3#_I_MM2  New State = IKE_I_MM2

ISAKMP (0:0): constructing CERT_REQ for issuer cn=R2,ou=CA-OF-THE-WORLD,o=INE,st=NV,c=US
ISAKMP:(0): sending packet to 10.0.0.1 my_port 500 peer_port 500 (I) MM_SA_SETUP
ISAKMP:(0):Sending an IKE IPv4 Packet.
ISAKMP:(0):Input = IKE_MESG_INTERNAL, IKE_PROCESS_COMPLETE
ISAKMP:(0):Old State = IKE_I_MM2  New State = IKE_I_MM3

ISAKMP (0:0): received packet from 10.0.0.1 dport 500 sport 500 Global (I) MM_SA_SETUP
ISAKMP:(0):Input = IKE_MESG_FROM_PEER, IKE_MM_EXCH
ISAKMP:(0):Old State = IKE_I_MM3  New State = IKE_I_MM4

ISAKMP:(0): processing KE payload. message ID = 0
ISAKMP:(0): processing NONCE payload. message ID = 0
ISAKMP:(1008): processing CERT_REQ payload. message ID = 0
ISAKMP:(1008): peer wants a CT_X509_SIGNATURE cert
ISAKMP:(1008): peer wants cert issued by cn=R2,ou=CA-OF-THE-WORLD,o=INE,st=NV,c=US
 Choosing trustpoint R2 as issuer
ISAKMP:(1008): processing vendor id payload
ISAKMP:(1008): vendor ID is Unity
ISAKMP:(1008): pr
R3#ocessing vendor id payload
ISAKMP:(1008): vendor ID is DPD
ISAKMP:(1008): processing vendor id payload
ISAKMP:(1008): speaking to another IOS box!
ISAKMP:received payload type 20
ISAKMP:received payload type 20
ISAKMP:(1008):Input = IKE_MESG_INTERNAL, IKE_PROCESS_MAIN_MODE
ISAKMP:(1008):Old State = IKE_I_MM4  New State = IKE_I_MM4

ISAKMP:(1008):Send initial contact
ISAKMP:(1008):SA is doing RSA signature authentication using id type<strong> ID_IPV4_ADDR</strong>
ISAKMP (0:1008): ID payload
 next-payload : 6
 type         : 1
 address      : 23.0.0.3
 protocol     : 17
 port         : 500
 length       : 12
ISAKMP:(1008):Total payload length: 12
ISAKMP (0:1008): constructing CERT payload for serialNumber=XXXXXXXXXXX+ipaddress=23.0.0.3+hostname=R3.ine.com,cn=R3,ou=ccie,o=ine,st=NV,c=US
ISAKMP:(1008): using the R2 trustpoint's keypair to sign
ISAKMP:(1008): sending packet to 10.0.0.1 my_port 500 peer_port 500 (I) MM_KEY_EXCH
ISAKMP:(1008):Sending an IKE IPv4 Packet.
ISAKMP:(
R3#1008):Input = IKE_MESG_INTERNAL, IKE_PROCESS_COMPLETE
ISAKMP:(1008):Old State = IKE_I_MM4  New State = IKE_I_MM5

ISAKMP (0:1008): received packet from 10.0.0.1 dport 500 sport 500 Global (I) MM_KEY_EXCH
ISAKMP:(1008): processing ID payload. message ID = 0
ISAKMP (0:1008): ID payload
 next-payload : 6
 type         : 1
 address      : 10.0.0.1
 protocol     : 17
 port         : 500
 length       : 12
ISAKMP:(0):: peer matches *none* of the profiles
ISAKMP:(1008): processing CERT payload. message ID = 0
ISAKMP:(1008): processing a CT_X509_SIGNATURE cert
ISAKMP:(1008): peer's pubkey isn't cached
<strong>%PKI-3-CERTIFICATE_INVALID_UNAUTHORIZED: Certificate chain validation has failed. Unauthorized
%CRYPTO-5-IKMP_INVAL_CERT: Certificate received from 10.0.0.1 is bad: certificate invalid</strong>
ISAKMP:(1008):Input = IKE_MESG_FROM_PEER, IKE_MM_EXCH
ISAKMP:(1008):Old State = IKE_I_MM5  New State = IKE_I_MM6

%CRYPTO-6-IKMP_MODE_FAILURE: Processing of Main mode failed with peer a
R3#t 10.0.0.1
ISAKMP:(1008): sending packet to 10.0.0.1 my_port 500 peer_port 500 (I) MM_KEY_EXCH
ISAKMP:(1008):Sending an IKE IPv4 Packet.
ISAKMP:(1008):peer does not do paranoid keepalives.

ISAKMP:(1008):deleting SA reason "Phase1 SA policy proposal not accepted" state (I) MM_KEY_EXCH (peer 10.0.0.1)
ISAKMP (0:1008): received packet from 10.0.0.1 dport 500 sport 500 Global (I) MM_KEY_EXCH
ISAKMP:(1008):Input = IKE_MESG_INTERNAL, IKE_PROCESS_MAIN_MODE
ISAKMP:(1008):Old State = IKE_I_MM6  New State = IKE_I_MM6

ISAKMP:(1008):Input = IKE_MESG_INTERNAL, IKE_PROCESS_ERROR
ISAKMP:(1008):Old State = IKE_I_MM6  New State = IKE_I_MM5

ISAKMP:(1008):deleting SA reason "Phase1 SA policy proposal not accepted" state (I) MM_KEY_EXCH (peer 10.0.0.1)
ISAKMP: Unlocking peer struct 0x66031B38 for isadb_mark_sa_deleted(), count 0
ISAKMP: Deleting peer node by peer_reap for 10.0.0.1: 66031B38
ISAKMP:(1008):deleting node -1424120631 error FALSE reason "IKE deleted"
ISAKMP:(1008):Input
R3# = IKE_MESG_INTERNAL, IKE_PHASE1_DEL
ISAKMP:(1008):Old State = IKE_I_MM5  New State = IKE_DEST_SA

IPSEC(key_engine): got a queue event with 1 KMI message(s)
ISAKMP (0:1008): received packet from 10.0.0.1 dport 500 sport 500 Global (I) MM_NO_STATE
R3#un all
All possible debugging has been turned off
R3#</pre>
<p>This is another important technique to put in our ever expanding tool  belt.   On an upcoming post, we will take a closer look at the  ID  type, including:</p>
<p>ID type ID_KEY_ID<br />
ID type ID_IPV4_ADDR<br />
ID type ID_FQDN<br />
ID type ID_USER_FQDN</p>
<div style='clear:both'></div><img src="http://www.realexam.net/?ak_action=api_record_view&id=4713&type=feed" alt="" /><img src="http://feeds.feedburner.com/~r/certting/~4/sXlokYNVA9g" height="1" width="1"/><img src="http://feeds.feedburner.com/~r/certting/~4/PleutBOhnTQ" height="1" width="1"/><img src="http://feeds.feedburner.com/~r/certting/~4/Lde4MlrStaU" height="1" width="1"/>]]></content:encoded>
			<wfw:commentRss>http://www.realexam.net/ccie-security-certificate-based-acls/4713.html/feed</wfw:commentRss>
		<slash:comments>0</slash:comments>
		<feedburner:origLink>http://www.realexam.net/ccie-security-certificate-based-acls/4713.html</feedburner:origLink><feedburner:origLink>http://feedproxy.google.com/~r/certting/~3/sXlokYNVA9g/4713.html</feedburner:origLink><feedburner:origLink>http://feedproxy.google.com/~r/certting/~3/PleutBOhnTQ/4713.html</feedburner:origLink></item>
		<item>
		<title>MPLS Components, Part 2</title>
		<link>http://feedproxy.google.com/~r/certting/~3/kXBlFjG4BT4/4711.html</link>
		<comments>http://www.realexam.net/mpls-components-part-2/4711.html#comments</comments>
		<pubDate>Fri, 23 Jul 2010 13:37:26 +0000</pubDate>
		<dc:creator>Johnny</dc:creator>
				<category><![CDATA[CCIE Training]]></category>
		<category><![CDATA[ccie lab]]></category>
		<category><![CDATA[ccie mpls]]></category>
		<category><![CDATA[cisco lab]]></category>

		<guid isPermaLink="false">http://www.realexam.net/?p=4711</guid>
		<description><![CDATA[In the previous MPLS Components post, we discussed the many benefits that MPLS can bring to the network, and we detailed the typical components found in a Layer 3 MPLS VPN design. In this post, we will provide more details for the MPLS components and the... ]]></description>
			<content:encoded><![CDATA[<p>In the previous MPLS  Components post, we discussed the many benefits that MPLS can bring  to the network, and we detailed the typical components found in a Layer  3 MPLS VPN design. In this post, we will provide more details for the  MPLS components and their important, inner workings. We will make  reference to the previous diagram in this post as well:</p>
<div id="attachment_3674"><a href="http://blog.ine.com/wp-content/uploads/2010/02/mpls-components.png"><img title="mpls components" src="http://blog.ine.com/wp-content/uploads/2010/02/mpls-components.png" alt="MPLS Components" width="600" height="371" /></a>MPLS Components</p>
</div>
<p>When PE1 receives a packet from CE1, it will engage in what we call a  Push operation. PE1 is considered the ingress PE router and engages in  label imposition. (Notice that we like to speak in fancy terminology  here; when we add a label to a packet, it is termed a push or an  imposition).</p>
<p>The P routers in the scenario will move  the packets by simply swapping labels. How are the labels used in the  Label Switch Path (LSP) learned by all of the routers? This is the job  of the Label Distribution Protocol, or other existing protocols, but  that is for later blog posts.</p>
<p>At the egress PE2 device, we have label disposition, or what we call a  Pop of the label. (Fancy language for the removal of the label). If the  second to last device in the path removes the label for us, this is  termed Penultimate Hop Popping (PHP) and is the default Cisco  implementation.</p>
<p>So we have pointed out that our example relies upon the Label  Distribution Protocol (LDP) for the assignment of labels through the  Label Switch Path (LSP). But how does LDP assign these labels? On what  does it base its information?</p>
<p>It turns out that LDP relies upon the underlying IGP to build the  best path for the LSP through the network. In fact, it also relies upon  the IGP for loop free pathing.</p>
<p>This relationship between LDP and the IGP has many interesting  aspects. For example, if the IGP reconverges on a new best path, so will  the LSP through LDP. If there is a loop created or a blackhole  situation created by the IGP reconvergence, this will also impact the  LSP. Also, consider convergence times. LDP is certainly bound by the  convergence time of the underlying IGP. Finally, consider the fact that  this reliance brings up the need for inter-AS MPLS mechanisms for LDP.</p>
<p>The last point I want to discuss in this part is the fact that we  often have label stacking with MPLS. In the case of our Layer 3 MPLS  VPNs in the R&amp;S track, the outer label (or transport label), is used  to move the packet through the LSP, while the inner label is used to  identify the VPN site. This is often called the VPN label.</p>
<div style='clear:both'></div><img src="http://www.realexam.net/?ak_action=api_record_view&id=4711&type=feed" alt="" /><img src="http://feeds.feedburner.com/~r/certting/~4/XkuDpS-POO4" height="1" width="1"/><img src="http://feeds.feedburner.com/~r/certting/~4/RZPNGf3bBKQ" height="1" width="1"/><img src="http://feeds.feedburner.com/~r/certting/~4/kXBlFjG4BT4" height="1" width="1"/>]]></content:encoded>
			<wfw:commentRss>http://www.realexam.net/mpls-components-part-2/4711.html/feed</wfw:commentRss>
		<slash:comments>0</slash:comments>
		<feedburner:origLink>http://www.realexam.net/mpls-components-part-2/4711.html</feedburner:origLink><feedburner:origLink>http://feedproxy.google.com/~r/certting/~3/XkuDpS-POO4/4711.html</feedburner:origLink><feedburner:origLink>http://feedproxy.google.com/~r/certting/~3/RZPNGf3bBKQ/4711.html</feedburner:origLink></item>
		<item>
		<title>Do You Need the New INE QoS Class?</title>
		<link>http://feedproxy.google.com/~r/certting/~3/D_TjGMWp4Kk/4709.html</link>
		<comments>http://www.realexam.net/do-you-need-the-new-ine-qos-class/4709.html#comments</comments>
		<pubDate>Fri, 23 Jul 2010 13:35:54 +0000</pubDate>
		<dc:creator>Johnny</dc:creator>
				<category><![CDATA[CCIE Training]]></category>
		<category><![CDATA[ccie lab]]></category>
		<category><![CDATA[CCIE Voice]]></category>
		<category><![CDATA[cisco lab]]></category>
		<category><![CDATA[qos]]></category>

		<guid isPermaLink="false">http://www.realexam.net/?p=4709</guid>
		<description><![CDATA[Try these questions on for size! Learn all this and much more in the new QoS class. 1. Based on the following configuration, what traffic will be policed? class-map C_MUSIC match protocol kazaa2 match protocol napster ! class-map match-any C_WEB match pr... ]]></description>
			<content:encoded><![CDATA[<p>Try these questions on for size! Learn all this and much more in the  new QoS class.</p>
<div id="_mcePaste">1. Based on the following  configuration, what traffic will be policed?</div>
<div id="_mcePaste">class-map C_MUSIC</div>
<div id="_mcePaste">match protocol kazaa2</div>
<div id="_mcePaste">match protocol napster</div>
<div id="_mcePaste">!</div>
<div id="_mcePaste">class-map match-any C_WEB</div>
<div id="_mcePaste">match protocol http</div>
<div id="_mcePaste">match class-map C_MUSIC</div>
<div id="_mcePaste">!</div>
<div id="_mcePaste">policy-map P_WEB</div>
<div id="_mcePaste">class C_WEB</div>
<div id="_mcePaste">police 64000</div>
<div id="_mcePaste">!</div>
<div id="_mcePaste">interface serial 0/0</div>
<div id="_mcePaste">service-policy output P_WEB</div>
<blockquote>
<div id="_mcePaste">A. All Kazaa version 2 traffic is policed</div>
<div id="_mcePaste">B. All Napster traffic is policed</div>
<div id="_mcePaste">C. All web traffic is policed</div>
<div id="_mcePaste">D. All Kazaa version 2, Napster, and web traffic is policed</div>
<div id="_mcePaste">E. No traffic is policed</div>
</blockquote>
<div></div>
<div id="_mcePaste">2. You are configuring a  Cisco Catalyst 3550 switch port to trust CoS markings if, and only if,  the marking originated from a Cisco IP Phone. In an attempt to perform  this configuration, you enter the mls qos trust device cisco-phone  command. However, your configuration does not seem to be working  properly. Why is the switch not trusting CoS markings coming from an  attached Cisco IP Phone?</div>
<blockquote>
<div id="_mcePaste">A. A Cisco Catalyst 3550 switch supports the mls qos trust  device cisco-phone command, but the Cisco Catalyst 2950 does not support  this command.</div>
<div id="_mcePaste">B. The mls qos trust cos command is missing.</div>
<div id="_mcePaste">C. The mls qos trust extend command is missing.</div>
<div id="_mcePaste">D. The mls qos cos 5 command is missing.</div>
</blockquote>
<div id="_mcePaste"></div>
<div>3. You administer a network  that transports both voice and interactive video traffic. Since these  traffic types are both latency-sensitive, you decide to implement the  following configuration. Which statement is true regarding the  configuration?</div>
<div id="_mcePaste">class-map C_VOICE</div>
<div id="_mcePaste">match protocol rtp audio</div>
<div id="_mcePaste">class-map C_VIDEO</div>
<div id="_mcePaste">match protocol rtp video</div>
<div id="_mcePaste">!</div>
<div id="_mcePaste">policy-map P_HIGH_PRIORITY</div>
<div id="_mcePaste">class C_VOICE</div>
<div id="_mcePaste">priority percent 15</div>
<div id="_mcePaste">class C_VIDEO</div>
<div id="_mcePaste">priority percent 35</div>
<div id="_mcePaste">class class-default</div>
<div id="_mcePaste">fair-queue</div>
<div id="_mcePaste">!</div>
<div id="_mcePaste">interface serial 0/0</div>
<div id="_mcePaste">service-policy output  P_HIGH_PRIORITY</div>
<blockquote>
<div id="_mcePaste">A. The configuration results in three queues, one for the  C_VOICE class, one for the C_VIDEO class, and one queue for the  class-default class.</div>
<div id="_mcePaste">B. The configuration results in two queues, one priority  queue and one queue for the class-default class.</div>
<div id="_mcePaste">C. The class-default class uses FIFO as its queuing  mechanism for traffic flows within its queue.</div>
<div id="_mcePaste">D. The two priority queues use WFQ for queuing traffic  within those queues.</div>
</blockquote>
<div></div>
<div id="_mcePaste">4. CB-WRED is configured  using the random-detect command. Which two of the following statements  are true concerning the random-detect command? (Choose 2)</div>
<blockquote>
<div id="_mcePaste">A. The random-detect command cannot be issued for the  class-default class.</div>
<div id="_mcePaste">B. The random-detect command cannot be issued for the  priority class(es).</div>
<div id="_mcePaste">C. The random-detect command must be issued in conjunction  with the bandwidth command (with the exception of the class-default  class).</div>
<div id="_mcePaste">D. The random-detect command should be issued in conjunction  with the priority command.</div>
</blockquote>
<div></div>
<div id="_mcePaste">5. Consider the following  configuration:</div>
<div id="_mcePaste">class-map TRANSACTIONAL</div>
<div id="_mcePaste">match protocol http</div>
<div id="_mcePaste">!</div>
<div id="_mcePaste">policy-map CBPOLICING</div>
<div id="_mcePaste">class TRANSACTIONAL</div>
<div id="_mcePaste">police 128000  conform-action set-dscp-transmit af11 exceed-action set-dscp-transmit  af13 violate-action drop</div>
<div id="_mcePaste">!</div>
<div id="_mcePaste">interface serial 0/1</div>
<div id="_mcePaste">service-policy input  CBPOLICING</div>
<div id="_mcePaste">What type of class-based  policing configuration is represented by this configuration?</div>
<blockquote>
<div id="_mcePaste">A. Single rate, single bucket</div>
<div id="_mcePaste">B. Single rate, dual bucket</div>
<div id="_mcePaste">C. Dual rate, single bucket</div>
<div id="_mcePaste">D. Dual rate, dual bucket</div>
</blockquote>
<div></div>
<div id="_mcePaste">6. You configure CB-Shaping  by issuing the command shape peak 8000 2000 2000. This configuration  shapes to what peak rate?</div>
<blockquote>
<div id="_mcePaste">A. 4000 bps</div>
<div id="_mcePaste">B. 8000 bps</div>
<div id="_mcePaste">C. 16000 bps</div>
<div id="_mcePaste">D. 32000 bps</div>
</blockquote>
<div></div>
<div id="_mcePaste">7. You are configuring  Multilink PPP (MLP) as your Link Fragmentation and Interleaving (LFI)  mechanism for a WAN link. Identify the correct statements regarding the  configuration of MLP. (Choose 2)</div>
<blockquote>
<div id="_mcePaste">A. The configuration of Multilink PPP requires at least two  physical links (e.g. two serial interfaces).</div>
<div id="_mcePaste">B. The IP address is removed from any serial interface that  makes up the MLP bundle.</div>
<div id="_mcePaste">C. Any policy-map that was previously assigned to a physical  interface should be reassigned to the multilink interface, that the  physical interface is associated with, in order for the policy to take  effect.</div>
<div id="_mcePaste">D. The virtual multilink interface does not use an IP  address. Rather, it uses the IP unnumbered feature which allows the  multilink interface to share an IP address with the multilink bundle  member that has the highest IP address.</div>
</blockquote>
<p><strong>1.</strong> Based on the following configuration, what  traffic will be policed?</p>
<pre>class-map C_MUSIC
  match protocol kazaa2
  match protocol napster
!
class-map match-any C_WEB
  match protocol http
  match class-map C_MUSIC
!
policy-map P_WEB
  class C_WEB
    police 64000
!
interface serial 0/0
  service-policy output P_WEB</pre>
<p>A. All Kazaa version 2 traffic  is policed</p>
<p>B. All Napster traffic is  policed</p>
<p>C. All web traffic is policed</p>
<p>D. All Kazaa version 2,  Napster, and web traffic is policed</p>
<p>E. No traffic is policed</p>
<p><strong>2.</strong> You are configuring a Cisco Catalyst 3560 switch  port to trust CoS markings if, and only if, the marking originated from a  Cisco IP Phone. In an attempt to perform this configuration, you enter  the <strong>mls qos trust device cisco-phone</strong> command. However,  your configuration does not seem to be working properly. Why is the  switch not trusting CoS markings coming from an attached Cisco IP Phone?</p>
<p>A. A Cisco Catalyst 2950  switch supports the <strong>mls qos trust device cisco-phone</strong> command, but the Cisco Catalyst 3560 does not support this command</p>
<p>B. The <strong>mls qos trust  cos</strong> command is missing</p>
<p>C. The <strong>mls qos trust  extend</strong> command is missing</p>
<p>D. The <strong>mls qos cos 5</strong> command is missing</p>
<p>E. The PC attached to the phone is overriding the CoS markings</p>
<p>3. You administer a network that transports both voice and  interactive video traffic. Since these traffic types are both  latency-sensitive, you decide to implement the following configuration.  Which statement is true regarding the configuration?</p>
<pre>class-map C_VOICE
  match protocol rtp audio
!
class-map C_VIDEO
  match protocol rtp video
!
policy-map P_HIGH_PRIORITY
  class C_VOICE
    priority percent 15
  class C_VIDEO
    priority percent 35
  class class-default
    fair-queue
!
interface serial 0/0
  service-policy output P_HIGH_PRIORITY</pre>
<p>A. The configuration results  in three queues, one for the C_VOICE class, one for the C_VIDEO class,  and one queue for the class-default class</p>
<p>B. The configuration results  in two queues, one priority queue and one queue for the class-default  class</p>
<p>C. The class-default class  uses FIFO as its queuing mechanism for traffic flows within its queue</p>
<p>D. The two priority queues use  WFQ for queuing traffic within those queues</p>
<p><strong>4.</strong> CB-WRED is configured using the <strong>random-detect</strong> command. Which two of the following statements are true concerning the <strong>random-detect</strong> command? (Choose 2)</p>
<p>A. The <strong>random-detect</strong> command cannot be issued for the class-default class.</p>
<p>B. The <strong>random-detect</strong> command cannot be issued for the priority class(es).</p>
<p>C. The <strong>random-detect</strong> command must be issued in conjunction with the bandwidth command (with  the exception of the class-default class).</p>
<p>D. The <strong>random-detect</strong> command should be issued in conjunction with the priority command.</p>
<p><strong>5.</strong> Consider the following configuration:</p>
<pre>class-map TRANSACTIONAL
  match protocol http
!
policy-map CBPOLICING
  class TRANSACTIONAL
    police 128000 conform-action set-dscp-transmit af11 exceed-action set-dscp-transmit af13 violate-action drop
!
interface serial 0/1
  service-policy input CBPOLICING</pre>
<p>What type of class-based policing configuration is represented by  this configuration?</p>
<p>A. Single rate, single bucket</p>
<p>B. Single rate, dual bucket</p>
<p>C. Dual rate, single bucket</p>
<p>D. Dual rate, dual bucket</p>
<p>6. You configure CB-Shaping by issuing the command <strong>shape peak  8000 2000 2000</strong>. This configuration shapes to what peak rate?</p>
<p>A. 4000 bps</p>
<p>B. 8000 bps</p>
<p>C. 16000 bps</p>
<p>D. 32000 bps</p>
<p><strong>7.</strong> You are configuring Multilink PPP (MLP) as your  Link Fragmentation and Interleaving (LFI) mechanism for a WAN link.  Identify the correct statements regarding the configuration of MLP.  (Choose 2)</p>
<p>A. The configuration of  Multilink PPP requires at least two physical links (e.g. two serial  interfaces)</p>
<p>B. The IP address is removed  from any serial interface that makes up the MLP bundle</p>
<p>C. Any policy-map that was  previously assigned to a physical interface should be reassigned to the  multilink interface, that the physical interface is associated with, in  order for the policy to take effect</p>
<p>D. The virtual multilink  interface does not use an IP address. Rather, it uses the IP unnumbered  feature which allows the multilink interface to share an IP address with  the multilink bundle member that has the highest IP address</p>
<p>1. Based on the following  configuration, what traffic will be policed?class-map C_MUSICmatch protocol kazaa2match protocol napster!class-map match-any C_WEBmatch protocol httpmatch class-map C_MUSIC!policy-map P_WEBclass C_WEBpolice 64000!interface serial 0/0service-policy output P_WEBA. All Kazaa version 2 traffic is policedB. All Napster traffic is policedC. All web traffic is policedD. All Kazaa version 2, Napster, and web traffic is policedE. No traffic is policed2. You are configuring a  Cisco Catalyst 3550 switch port to trust CoS markings if, and only if,  the marking originated from a Cisco IP Phone. In an attempt to perform  this configuration, you enter the mls qos trust device cisco-phone  command. However, your configuration does not seem to be working  properly. Why is the switch not trusting CoS markings coming from an  attached Cisco IP Phone?A. A Cisco Catalyst 3550 switch supports the mls qos trust  device cisco-phone command, but the Cisco Catalyst 2950 does not support  this command.B. The mls qos trust cos command is missing.C. The mls qos trust extend command is missing.D. The mls qos cos 5 command is missing.3. You administer a network  that transports both voice and interactive video traffic. Since these  traffic types are both latency-sensitive, you decide to implement the  following configuration. Which statement is true regarding the  configuration?class-map C_VOICEmatch protocol rtp audioclass-map C_VIDEOmatch protocol rtp video!policy-map P_HIGH_PRIORITYclass C_VOICEpriority percent 15class C_VIDEOpriority percent 35class class-defaultfair-queue!interface serial 0/0service-policy output  P_HIGH_PRIORITYA. The configuration results in three queues, one for the  C_VOICE class, one for the C_VIDEO class, and one queue for the  class-default class.B. The configuration results in two queues, one priority  queue and one queue for the class-default class.C. The class-default class uses FIFO as its queuing  mechanism for traffic flows within its queue.D. The two priority queues use WFQ for queuing traffic  within those queues.4. CB-WRED is configured  using the random-detect command. Which two of the following statements  are true concerning the random-detect command? (Choose 2)A. The random-detect command cannot be issued for the  class-default class.B. The random-detect command cannot be issued for the  priority class(es).C. The random-detect command must be issued in conjunction  with the bandwidth command (with the exception of the class-default  class).D. The random-detect command should be issued in conjunction  with the priority command.5. Consider the following  configuration:class-map TRANSACTIONALmatch protocol http!policy-map CBPOLICINGclass TRANSACTIONALpolice 128000  conform-action set-dscp-transmit af11 exceed-action set-dscp-transmit  af13 violate-action drop!interface serial 0/1service-policy input  CBPOLICINGWhat type of class-based  policing configuration is represented by this configuration?A. Single rate, single bucketB. Single rate, dual bucketC. Dual rate, single bucketD. Dual rate, dual bucket6. You configure CB-Shaping  by issuing the command shape peak 8000 2000 2000. This configuration  shapes to what peak rate?A. 4000 bpsB. 8000 bpsC. 16000 bpsD. 32000 bps7. You are configuring  Multilink PPP (MLP) as your Link Fragmentation and Interleaving (LFI)  mechanism for a WAN link. Identify the correct statements regarding the  configuration of MLP. (Choose 2)A. The configuration of Multilink PPP requires at least two  physical links (e.g. two serial interfaces).B. The IP address is removed from any serial interface that  makes up the MLP bundle.C. Any policy-map that was previously assigned to a physical  interface should be reassigned to the multilink interface, that the  physical interface is associated with, in order for the policy to take  effect.D. The virtual multilink interface does not use an IP  address. Rather, it uses the IP unnumbered feature which allows the  multilink interface to share an IP address with the multilink bundle  member that has the highest IP address.</p>
<div style='clear:both'></div><img src="http://www.realexam.net/?ak_action=api_record_view&id=4709&type=feed" alt="" /><img src="http://feeds.feedburner.com/~r/certting/~4/9z8T23Rm4pw" height="1" width="1"/><img src="http://feeds.feedburner.com/~r/certting/~4/6yOlrY84iBI" height="1" width="1"/><img src="http://feeds.feedburner.com/~r/certting/~4/D_TjGMWp4Kk" height="1" width="1"/>]]></content:encoded>
			<wfw:commentRss>http://www.realexam.net/do-you-need-the-new-ine-qos-class/4709.html/feed</wfw:commentRss>
		<slash:comments>0</slash:comments>
		<feedburner:origLink>http://www.realexam.net/do-you-need-the-new-ine-qos-class/4709.html</feedburner:origLink><feedburner:origLink>http://feedproxy.google.com/~r/certting/~3/9z8T23Rm4pw/4709.html</feedburner:origLink><feedburner:origLink>http://feedproxy.google.com/~r/certting/~3/6yOlrY84iBI/4709.html</feedburner:origLink></item>
		<item>
		<title>The Five Tracks of CCIE</title>
		<link>http://feedproxy.google.com/~r/certting/~3/dLWmnQWwPwc/4707.html</link>
		<comments>http://www.realexam.net/the-five-tracks-of-ccie/4707.html#comments</comments>
		<pubDate>Fri, 23 Jul 2010 13:31:43 +0000</pubDate>
		<dc:creator>Johnny</dc:creator>
				<category><![CDATA[CCIE Training]]></category>
		<category><![CDATA[ccie lab]]></category>
		<category><![CDATA[ccie tracks]]></category>
		<category><![CDATA[cisco certification]]></category>

		<guid isPermaLink="false">http://www.realexam.net/?p=4707</guid>
		<description><![CDATA[Cisco Certified Internetworking Expert (CCIE) is recognized as the most respected IT certification today. CertMag even voted it as the most technically advanced, while other reports claim that it is the highest salaried certification in salary surveys. I... ]]></description>
			<content:encoded><![CDATA[<p>Cisco Certified Internetworking Expert (CCIE) is recognized as the most respected IT certification today. CertMag even voted it as the most technically advanced, while other reports claim that it is the highest salaried certification in salary surveys. Indeed, passing CCIE is really worth all the efforts and money that candidates have to consider in taking both the written and <a href="http://www.realexam.net/tag/lab" class="st_tag internal_tag" rel="tag" title="Posts tagged with lab">lab</a> exams. Though there are really no formal prerequisites, Cisco recommends candidates to have at least 3 to 5 years of experience in networking before making their first attempt on becoming a CCIE. Unlike other certification programs such as the ones offered by Microsoft, there is no need to pass lower Cisco certifications such as associate and professional exams before taking an expert level exam as CCIE.</p>
<p>There are 5 CCIE tracks that candidates can choose from, making it possible to hold multiple CCIE certifications at the same time. These are:</p>
<blockquote><p>(a) CCIE <a href="http://www.realexam.net/tag/routing" class="st_tag internal_tag" rel="tag" title="Posts tagged with routing">Routing</a> and Switching  the most popular track that covers a variety of networking protocols and concepts such as Multicast <a href="http://www.realexam.net/tag/routing" class="st_tag internal_tag" rel="tag" title="Posts tagged with routing">Routing</a> and Border Gateway Protocol;</p>
<p>(b) <a href="http://www.realexam.net/tag/ccie-security" class="st_tag internal_tag" rel="tag" title="Posts tagged with ccie security">CCIE Security</a>   focuses on network security, covering topics such as IOS Security and IDS;</p>
<p>(c) CCIE Service Provider  concentrates on networking in the service provider industry such as DSL, Cable and Voice over IP;</p>
<p>(d) CCIE Voice   covers subjects such as Cisco Unity and Call Manager as voice solutions for the enterprise; and</p>
<p>(e) CCIE Storage Networking  the latest addition on CCIE tracks that concentrates on storage networking topics that include FCIP, FICON and iSCSI.</p></blockquote>
<p>As of November of 2007, there are 1,344 individuals who hold multiple CCIE certifications and 210 of them hold three or more CCIE certifications.</p>
<div style='clear:both'></div><img src="http://www.realexam.net/?ak_action=api_record_view&id=4707&type=feed" alt="" /><img src="http://feeds.feedburner.com/~r/certting/~4/qAoV_7ITHGM" height="1" width="1"/><img src="http://feeds.feedburner.com/~r/certting/~4/GSf8E5XWEr0" height="1" width="1"/><img src="http://feeds.feedburner.com/~r/certting/~4/dLWmnQWwPwc" height="1" width="1"/>]]></content:encoded>
			<wfw:commentRss>http://www.realexam.net/the-five-tracks-of-ccie/4707.html/feed</wfw:commentRss>
		<slash:comments>0</slash:comments>
		<feedburner:origLink>http://www.realexam.net/the-five-tracks-of-ccie/4707.html</feedburner:origLink><feedburner:origLink>http://feedproxy.google.com/~r/certting/~3/qAoV_7ITHGM/4707.html</feedburner:origLink><feedburner:origLink>http://feedproxy.google.com/~r/certting/~3/GSf8E5XWEr0/4707.html</feedburner:origLink></item>
		<item>
		<title>CCIE Written Exams The Most Critical Part of the CCIE Certification</title>
		<link>http://feedproxy.google.com/~r/certting/~3/Dl65OKTCyPw/4705.html</link>
		<comments>http://www.realexam.net/ccie-written-exams-the-most-critical-part-of-the-ccie-certification/4705.html#comments</comments>
		<pubDate>Fri, 23 Jul 2010 13:30:27 +0000</pubDate>
		<dc:creator>Johnny</dc:creator>
				<category><![CDATA[CCIE Training]]></category>
		<category><![CDATA[CCIE certification]]></category>
		<category><![CDATA[ccie lab]]></category>
		<category><![CDATA[ccie written]]></category>

		<guid isPermaLink="false">http://www.realexam.net/?p=4705</guid>
		<description><![CDATA[If you would like to be a Cisco Certified Internetworking Ex­pert (CCIE), then it is very crucial to pass the written exam. A CCIE written exam is one of two certification exams that you need to take. Before jumping to the next type of exam, which happe... ]]></description>
			<content:encoded><![CDATA[<p>If you would like to be a Cisco Certified Internetworking Ex­pert (CCIE), then it is very crucial to pass the written exam. A CCIE written exam is one of two certification exams that you need to take. Before jumping to the next type of exam, which happens to be a <a href="http://www.realexam.net/tag/lab" class="st_tag internal_tag" rel="tag" title="Posts tagged with lab">lab</a> exam, you have to first give your best shot in passing the written exam of 100 multiple choice questions. Each CCIE written exam will cost you around US $300 on every attempt. Because of this, it is indeed a must to pass the exam on the first try to give you more time to focus on the <a href="http://www.realexam.net/tag/lab" class="st_tag internal_tag" rel="tag" title="Posts tagged with lab">lab</a> exam, which should be taken within 18 months. Failure to do so means nullifying your CCIE written exam score so you have to take the written exam again if ever you are still interested in getting CCIE certified.</p>
<p>To register for a CCIE written exam, you can check out the Pearson VUE web site for more information. Prometric has discon­tinued administering CCIE exams since August 1, 2007. It is a computer-based exam that should be completed in a span of 2 hours.</p>
<p>Candidates can also use exam vouchers to pay for the written exam. These test vouchers can be purchased on testing centers and other academic institutions. Exam vouchers are non-refundable and non-returnable, aside from the fact that these will expire after 12 months of being purchased.</p>
<p>Other candidates also take on beta written exams when available at a discounted price of US $50. Getting a passing grade on the beta exam earns you a slot on the <a href="http://www.realexam.net/tag/lab" class="st_tag internal_tag" rel="tag" title="Posts tagged with lab">lab</a> exam. However, beta exams can only be taken during the beta period.</p>
<div style='clear:both'></div><img src="http://www.realexam.net/?ak_action=api_record_view&id=4705&type=feed" alt="" /><img src="http://feeds.feedburner.com/~r/certting/~4/r-v6kZCg6b8" height="1" width="1"/><img src="http://feeds.feedburner.com/~r/certting/~4/bHibTkRa2RE" height="1" width="1"/><img src="http://feeds.feedburner.com/~r/certting/~4/Dl65OKTCyPw" height="1" width="1"/>]]></content:encoded>
			<wfw:commentRss>http://www.realexam.net/ccie-written-exams-the-most-critical-part-of-the-ccie-certification/4705.html/feed</wfw:commentRss>
		<slash:comments>0</slash:comments>
		<feedburner:origLink>http://www.realexam.net/ccie-written-exams-the-most-critical-part-of-the-ccie-certification/4705.html</feedburner:origLink><feedburner:origLink>http://feedproxy.google.com/~r/certting/~3/r-v6kZCg6b8/4705.html</feedburner:origLink><feedburner:origLink>http://feedproxy.google.com/~r/certting/~3/bHibTkRa2RE/4705.html</feedburner:origLink></item>
		<item>
		<title>CCIE Voice Becoming an Expert on VoIP</title>
		<link>http://feedproxy.google.com/~r/certting/~3/Wp-ZKNGD0MY/4703.html</link>
		<comments>http://www.realexam.net/ccie-voice-becoming-an-expert-on-voip/4703.html#comments</comments>
		<pubDate>Fri, 23 Jul 2010 13:29:23 +0000</pubDate>
		<dc:creator>Johnny</dc:creator>
				<category><![CDATA[CCIE Training]]></category>
		<category><![CDATA[ccie lab]]></category>
		<category><![CDATA[CCIE Voice]]></category>
		<category><![CDATA[ccie voip]]></category>

		<guid isPermaLink="false">http://www.realexam.net/?p=4703</guid>
		<description><![CDATA[Are you an expert in providing VoIP solutions in a certain enterprise? If yes, then you can consider on getting a certification for Cisco Certified Internetworking Expert (CCIE) in Voice. If you happen to know the process of installing, configuring and m... ]]></description>
			<content:encoded><![CDATA[<p>Are you an expert in providing VoIP solutions in a certain enterprise? If yes, then you can consider on getting a certification for Cisco Certified Internetworking Expert (CCIE) in Voice. If you happen to know the process of installing, configuring and maintain­ing Voice solutions over an IP network and you are in a way good at it, CCIE Voice track is just right for you. There are no formal pre­requisites such as professional or associate certifications or training courses for this CCIE certification. All you have to do is first pass a written exam and then a <a href="http://www.realexam.net/tag/lab" class="st_tag internal_tag" rel="tag" title="Posts tagged with lab">lab</a> exam, after which you can already consider yourself as a CCIE certified professional.</p>
<p>The CCIE Voice written exam is made up of 100 multiple choice questions that should be completed in two hours. The exam covers applications and technologies that comprise a Cisco Enter­prise VoIP solution. It usually costs around US $300 and may vary depending on your location. Exam results are available immediately after you have completed the exam. Once you have successfully passed the written exam, bear in mind that you should be taking the <a href="http://www.realexam.net/tag/lab" class="st_tag internal_tag" rel="tag" title="Posts tagged with lab">lab</a> exam within 18 months. Or else, you have to start from scratch as written exam scores expire after 18 months.</p>
<p>On the other hand, the CCIE Voice <a href="http://www.realexam.net/tag/lab" class="st_tag internal_tag" rel="tag" title="Posts tagged with lab">lab</a> exam is an 8-hour test that will measure your ability to get a VoIP solution up and running within specified time constraints. You are the one in charge in configuring pre-installed applications to satisfy certain require­ments to pass the <a href="http://www.realexam.net/tag/lab" class="st_tag internal_tag" rel="tag" title="Posts tagged with lab">lab</a> exam. The <a href="http://www.realexam.net/tag/lab" class="st_tag internal_tag" rel="tag" title="Posts tagged with lab">lab</a> exam may cost you about US $1,400 and is offered on certain Cisco locations in Brussels, Tokyo and Sydney.</p>
<div style='clear:both'></div><img src="http://www.realexam.net/?ak_action=api_record_view&id=4703&type=feed" alt="" /><img src="http://feeds.feedburner.com/~r/certting/~4/yQ1a_Pvnvfc" height="1" width="1"/><img src="http://feeds.feedburner.com/~r/certting/~4/wFaHWVn54dk" height="1" width="1"/><img src="http://feeds.feedburner.com/~r/certting/~4/Wp-ZKNGD0MY" height="1" width="1"/>]]></content:encoded>
			<wfw:commentRss>http://www.realexam.net/ccie-voice-becoming-an-expert-on-voip/4703.html/feed</wfw:commentRss>
		<slash:comments>0</slash:comments>
		<feedburner:origLink>http://www.realexam.net/ccie-voice-becoming-an-expert-on-voip/4703.html</feedburner:origLink><feedburner:origLink>http://feedproxy.google.com/~r/certting/~3/yQ1a_Pvnvfc/4703.html</feedburner:origLink><feedburner:origLink>http://feedproxy.google.com/~r/certting/~3/wFaHWVn54dk/4703.html</feedburner:origLink></item>
		<item>
		<title>CCIE Training The Best Line of Defense Against Failure</title>
		<link>http://feedproxy.google.com/~r/certting/~3/8WT73Xtwb08/4701.html</link>
		<comments>http://www.realexam.net/ccie-training-the-best-line-of-defense-against-failure/4701.html#comments</comments>
		<pubDate>Fri, 23 Jul 2010 13:28:28 +0000</pubDate>
		<dc:creator>Johnny</dc:creator>
				<category><![CDATA[CCIE Training]]></category>
		<category><![CDATA[ccie exam]]></category>
		<category><![CDATA[ccie lab]]></category>

		<guid isPermaLink="false">http://www.realexam.net/?p=4701</guid>
		<description><![CDATA[It is indeed a fact that getting a certification for Cisco Certi­fied Internetworking Expert (CCIE) is not a joke. This is because it requires candidates to give their 100% attention for them to be able to pass two exams that they need to take one writt... ]]></description>
			<content:encoded><![CDATA[<p>It is indeed a fact that getting a certification for Cisco Certi­fied Internetworking Expert (CCIE) is not a joke. This is because it requires candidates to give their 100% attention for them to be able to pass two exams that they need to take one written and one <a href="http://www.realexam.net/tag/lab" class="st_tag internal_tag" rel="tag" title="Posts tagged with lab">lab</a> exam. Though it is true that there are no normal prerequisites for the CCIE exam, still there is a need to have a working knowledge and adept experience in networking. This is where proper CCIE training comes in.</p>
<p>CCIE has five tracks in place and it is the candidate s pre­rogative which among these -</p>
<blockquote><p>(a) <a href="http://www.realexam.net/tag/routing" class="st_tag internal_tag" rel="tag" title="Posts tagged with routing">Routing</a> and Switching,</p>
<p>(b) Security,</p>
<p>(c) Service Provider,</p>
<p>(d) Storage Networking or ( e) Voice suits his capabilities as a networking expert.</p></blockquote>
<p>Training plays a major role in defining certain key strengths that will help candidates decide on which track to take. To enhance their skills, they have the option to take training courses or read books to ease their way out of the CCIE exams. There are a lot of training institutions that offer such services, facilitated in by ex­perts themselves. Though it may cost CCIE aspirants valuable amount of money by attending training classes alone (roughly $1,500 &#8211; $3,000 per class), still the rewards are truly unimaginable once they have stepped up, conquered the exam and achieved CCIE certification.</p>
<p>Aside from attending training classes, a candidate has also the option to train at home on Cisco systems. He or she can also check out web sites that offer sample CCIE test questions and assess oneself on how prepared he or she is in taking the exam. Taking advantage of all the resources around will boost candidates confidence and give them more chances on getting CCIE certified.</p>
<div style='clear:both'></div><img src="http://www.realexam.net/?ak_action=api_record_view&id=4701&type=feed" alt="" /><img src="http://feeds.feedburner.com/~r/certting/~4/Ie_k5tldUyM" height="1" width="1"/><img src="http://feeds.feedburner.com/~r/certting/~4/4TD1OO8AXzI" height="1" width="1"/><img src="http://feeds.feedburner.com/~r/certting/~4/8WT73Xtwb08" height="1" width="1"/>]]></content:encoded>
			<wfw:commentRss>http://www.realexam.net/ccie-training-the-best-line-of-defense-against-failure/4701.html/feed</wfw:commentRss>
		<slash:comments>0</slash:comments>
		<feedburner:origLink>http://www.realexam.net/ccie-training-the-best-line-of-defense-against-failure/4701.html</feedburner:origLink><feedburner:origLink>http://feedproxy.google.com/~r/certting/~3/Ie_k5tldUyM/4701.html</feedburner:origLink><feedburner:origLink>http://feedproxy.google.com/~r/certting/~3/4TD1OO8AXzI/4701.html</feedburner:origLink></item>
		<item>
		<title>CCIE Security Learning the Principles of Network Security</title>
		<link>http://feedproxy.google.com/~r/certting/~3/yWQ0VQHEYEM/4699.html</link>
		<comments>http://www.realexam.net/ccie-security-learning-the-principles-of-network-security/4699.html#comments</comments>
		<pubDate>Fri, 23 Jul 2010 13:26:59 +0000</pubDate>
		<dc:creator>Johnny</dc:creator>
				<category><![CDATA[CCIE Training]]></category>
		<category><![CDATA[ccie lab]]></category>
		<category><![CDATA[ccie network security]]></category>
		<category><![CDATA[ccie security]]></category>

		<guid isPermaLink="false">http://www.realexam.net/?p=4699</guid>
		<description><![CDATA[CCIE Security is one of the five tracks that candidates can choose from. Getting a CCIE certification in Security indicates a candidate s expert level knowledge of IP and IP Routing, as well as network security protocols and components with subjects that... ]]></description>
			<content:encoded><![CDATA[<p><a href="http://www.realexam.net/tag/ccie-security" class="st_tag internal_tag" rel="tag" title="Posts tagged with ccie security">CCIE Security</a> is one of the five tracks that candidates can choose from. Getting a CCIE certification in Security indicates a candidate s expert level knowledge of IP and IP <a href="http://www.realexam.net/tag/routing" class="st_tag internal_tag" rel="tag" title="Posts tagged with routing">Routing</a>, as well as network security protocols and components with subjects that include IOS Security, IDS, ASA and many others. There are no prerequisites for this type of CCIE certification, though candidates are encouraged to undergo training to enhance their knowledge and skills as far as network security is concerned.</p>
<p>There are barely two steps that candidates need to take be­fore getting <a href="http://www.realexam.net/tag/ccie-security" class="st_tag internal_tag" rel="tag" title="Posts tagged with ccie security">CCIE Security</a> certified. The first step is to pass the written exam. It is a two-hour test with 100 multiple choice ques­tions that needs to be answered within specific time constraints. No open books or other reference materials allowed when taking the exam. It usually costs around US $300, which also depends on exchange rates and local taxes. Results of the CCIE exam are avail­able immediately after the exam. Passing it means that the candi­date is ready to move on to the next step and that is to take the <a href="http://www.realexam.net/tag/lab" class="st_tag internal_tag" rel="tag" title="Posts tagged with lab">lab</a> exam within a period of 18 months only. Failure to do so may mean expiration of the written exam score.</p>
<p>The <a href="http://www.realexam.net/tag/ccie-security" class="st_tag internal_tag" rel="tag" title="Posts tagged with ccie security">CCIE Security</a> <a href="http://www.realexam.net/tag/lab" class="st_tag internal_tag" rel="tag" title="Posts tagged with lab">lab</a> exam is an 8-hour hands-on test that requires candidates to configure, troubleshoot and solve problems presented to them. It usually costs around US $1,400 per attempt and exam scores are available online within 48 hours. Scores are evaluated by proctors to ensure that certain requirements or crite­ria are met. If a candidate is doubtful and would like proctors to reevaluate his or her score, he or she has to pay an additional US $250 to request for reread. However, this is possible only if 14 days have passed following the exam date.</p>
<div style='clear:both'></div><img src="http://www.realexam.net/?ak_action=api_record_view&id=4699&type=feed" alt="" /><img src="http://feeds.feedburner.com/~r/certting/~4/VYMqliKwrk4" height="1" width="1"/><img src="http://feeds.feedburner.com/~r/certting/~4/nb89gkSqXbE" height="1" width="1"/><img src="http://feeds.feedburner.com/~r/certting/~4/yWQ0VQHEYEM" height="1" width="1"/>]]></content:encoded>
			<wfw:commentRss>http://www.realexam.net/ccie-security-learning-the-principles-of-network-security/4699.html/feed</wfw:commentRss>
		<slash:comments>0</slash:comments>
		<feedburner:origLink>http://www.realexam.net/ccie-security-learning-the-principles-of-network-security/4699.html</feedburner:origLink><feedburner:origLink>http://feedproxy.google.com/~r/certting/~3/VYMqliKwrk4/4699.html</feedburner:origLink><feedburner:origLink>http://feedproxy.google.com/~r/certting/~3/nb89gkSqXbE/4699.html</feedburner:origLink></item>
		<item>
		<title>CCIE Resume The Need for CCIE Recerti-fication</title>
		<link>http://feedproxy.google.com/~r/certting/~3/VpTzZUkpkOE/4696.html</link>
		<comments>http://www.realexam.net/ccie-resume-the-need-for-ccie-recerti-fication/4696.html#comments</comments>
		<pubDate>Fri, 23 Jul 2010 13:25:30 +0000</pubDate>
		<dc:creator>Johnny</dc:creator>
				<category><![CDATA[CCIE Training]]></category>
		<category><![CDATA[CCIE]]></category>
		<category><![CDATA[ccie lab]]></category>
		<category><![CDATA[ccie recerti-fication]]></category>

		<guid isPermaLink="false">http://www.realexam.net/?p=4696</guid>
		<description><![CDATA[Getting a Cisco certification means a lot to today s IT profes­sionals. This is because nowadays, most companies require appli­cants to present certifications to signify their qualification for the vacant position available. It is indeed an ingredient ... ]]></description>
			<content:encoded><![CDATA[<p>Getting a Cisco certification means a lot to today s IT profes­sionals. This is because nowadays, most companies require appli­cants to present certifications to signify their qualification for the vacant position available. It is indeed an ingredient that brings flavor to a comprehensive resume, giving the applicant better chances of getting the job. In addition, getting a certification also gives one a feeling of self-worth, something that should be proud of while earning the respect of fellow IT experts.</p>
<p>But then again, Cisco certifications such as the one for Cisco Certified Internetworking Expert (CCIE) are not permanent. This means that CCIEs are required to recertify every two years to show their commitment to maintaining expert level knowledge in any industry that is critical to the success of almost every organization. Since there are a lot of new technologies presented in the world of IT, there is a need to continually expand technical knowledge and redevelop new skills to regain expert status making recertification just the right solution to this slight dilemma.</p>
<p>If one is unaware of when to recertify, an online resource can be accessed at the Cisco web site. CCIEs can log in anytime to view one s certification deadline. Succeeding recertification deadlines are always based on the original certification date, not on the last recertification exam. CCIEs have at lease a year to reinstate CCIE status before it becomes inactive, after which they must begin the certification process all over again. Recertification exams can be taken at Pearson VUE testing centers worldwide. Exam scores are then automatically downloaded to the CCIE database.</p>
<div style='clear:both'></div><img src="http://www.realexam.net/?ak_action=api_record_view&id=4696&type=feed" alt="" /><img src="http://feeds.feedburner.com/~r/certting/~4/kMuhLMon5J8" height="1" width="1"/><img src="http://feeds.feedburner.com/~r/certting/~4/xUeHp8VVTGk" height="1" width="1"/><img src="http://feeds.feedburner.com/~r/certting/~4/VpTzZUkpkOE" height="1" width="1"/>]]></content:encoded>
			<wfw:commentRss>http://www.realexam.net/ccie-resume-the-need-for-ccie-recerti-fication/4696.html/feed</wfw:commentRss>
		<slash:comments>0</slash:comments>
		<feedburner:origLink>http://www.realexam.net/ccie-resume-the-need-for-ccie-recerti-fication/4696.html</feedburner:origLink><feedburner:origLink>http://feedproxy.google.com/~r/certting/~3/kMuhLMon5J8/4696.html</feedburner:origLink><feedburner:origLink>http://feedproxy.google.com/~r/certting/~3/xUeHp8VVTGk/4696.html</feedburner:origLink></item>
		<item>
		<title>CCIE Lab Exam A Hands-on Test to Prove One s Qualification</title>
		<link>http://feedproxy.google.com/~r/certting/~3/DnFy0JZfnCo/4694.html</link>
		<comments>http://www.realexam.net/ccie-lab-exam-a-hands-on-test-to-prove-one-s-qualification/4694.html#comments</comments>
		<pubDate>Fri, 23 Jul 2010 13:24:23 +0000</pubDate>
		<dc:creator>Johnny</dc:creator>
				<category><![CDATA[CCIE Training]]></category>
		<category><![CDATA[CCIE]]></category>
		<category><![CDATA[ccie lab]]></category>
		<category><![CDATA[cisco certification]]></category>

		<guid isPermaLink="false">http://www.realexam.net/?p=4694</guid>
		<description><![CDATA[Each of the five tracks of CCIE ­ (a) Routing and Switching, (b) Security, (c) Service Provider, (d) Storage Networking and (e) Voice, has its own written and lab exams that candidates should successfully pass before getting a Cisco Certified Internet-w... ]]></description>
			<content:encoded><![CDATA[<p>Each of the five tracks of CCIE ­</p>
<blockquote><p>(a) <a href="http://www.realexam.net/tag/routing" class="st_tag internal_tag" rel="tag" title="Posts tagged with routing">Routing</a> and Switching,</p>
<p>(b) Security,</p>
<p>(c) Service Provider,</p>
<p>(d) Storage Networking and</p>
<p>(e) Voice, has its own written and <a href="http://www.realexam.net/tag/lab" class="st_tag internal_tag" rel="tag" title="Posts tagged with lab">lab</a> exams that candidates should successfully pass before getting a Cisco Certified Internet-working Expert (CCIE) certification.</p></blockquote>
<p>A written exam is just like any other exam that consists of multiple choice questions taken from various subjects, depending on the candidates chosen track. It is because of this very nature of the written exam that makes it easier for exam takers to pass mostly on first attempt. But then again, the challenge lies on the <a href="http://www.realexam.net/tag/lab" class="st_tag internal_tag" rel="tag" title="Posts tagged with lab">lab</a> exam, requiring candidates to think of possible practical <a href="http://www.realexam.net/tag/lab" class="st_tag internal_tag" rel="tag" title="Posts tagged with lab">lab</a> scenarios that will most likely appear on the actual exam.</p>
<p>The exam for the <a href="http://www.realexam.net/tag/lab" class="st_tag internal_tag" rel="tag" title="Posts tagged with lab">lab</a> is what makes CCIE different from other certification programs. It costs around US $1,400 per at­tempt. It is usually a full day (8 hour) hands-on tests that measure a candidate s ability to configure and troubleshoot equipment. Be­cause of this, there are only quite a few who pass this exam while others may need multiple attempts to complete it. This is not administered by Pearson VUE as there are only 10 specific Cisco <a href="http://www.realexam.net/tag/lab" class="st_tag internal_tag" rel="tag" title="Posts tagged with lab">lab</a> exam locations worldwide &#8211; Bangalore, India; Beijing, China; Brussels, Belgium; Dubai, UAE; Hong Kong, China; Research Triangle Park, NC, USA; San Jose, CA, USA; Sao Paolo, Brazil; Sydney, Australia; and Tokyo, Japan. However, <a href="http://www.realexam.net/tag/lab" class="st_tag internal_tag" rel="tag" title="Posts tagged with lab">lab</a> exams for a particular CCIE track are not available at all testing locations so it is better to inquire about it first. Say for example, the <a href="http://www.realexam.net/tag/lab" class="st_tag internal_tag" rel="tag" title="Posts tagged with lab">lab</a> exam for Storage Networking is only available at Research Triangle Park, NC and Brussels testing centers.</p>
<div style='clear:both'></div><img src="http://www.realexam.net/?ak_action=api_record_view&id=4694&type=feed" alt="" /><img src="http://feeds.feedburner.com/~r/certting/~4/wYhVm_oZU0M" height="1" width="1"/><img src="http://feeds.feedburner.com/~r/certting/~4/XQgtv2E-yHk" height="1" width="1"/><img src="http://feeds.feedburner.com/~r/certting/~4/DnFy0JZfnCo" height="1" width="1"/>]]></content:encoded>
			<wfw:commentRss>http://www.realexam.net/ccie-lab-exam-a-hands-on-test-to-prove-one-s-qualification/4694.html/feed</wfw:commentRss>
		<slash:comments>0</slash:comments>
		<feedburner:origLink>http://www.realexam.net/ccie-lab-exam-a-hands-on-test-to-prove-one-s-qualification/4694.html</feedburner:origLink><feedburner:origLink>http://feedproxy.google.com/~r/certting/~3/wYhVm_oZU0M/4694.html</feedburner:origLink><feedburner:origLink>http://feedproxy.google.com/~r/certting/~3/XQgtv2E-yHk/4694.html</feedburner:origLink></item>
		<item>
		<title>BGP Path Manipulation</title>
		<link>http://feedproxy.google.com/~r/certting/~3/PRACNV3iBjs/4692.html</link>
		<comments>http://www.realexam.net/bgp-path-manipulation/4692.html#comments</comments>
		<pubDate>Wed, 21 Jul 2010 11:42:15 +0000</pubDate>
		<dc:creator>Johnny</dc:creator>
				<category><![CDATA[CCIE Training]]></category>
		<category><![CDATA[CCIP Training]]></category>
		<category><![CDATA[CCNP Training]]></category>
		<category><![CDATA[BGP]]></category>
		<category><![CDATA[CCIE]]></category>
		<category><![CDATA[ccie lab]]></category>
		<category><![CDATA[routing]]></category>

		<guid isPermaLink="false">http://www.realexam.net/?p=4692</guid>
		<description><![CDATA[Summer was in full swing, and it was over 105 degrees Fahrenheit outside.   Bob was told it was a “dry heat”, but he thought “so is my oven”.  Needless to say, Bob was glad to be in the data center, where the temperature and humidity controls ... ]]></description>
			<content:encoded><![CDATA[<p>Summer was in full swing, and it was over 105 degrees Fahrenheit outside.   Bob was told it was a “dry heat”, but he thought “so is my oven”.  Needless to say, Bob was glad to be in the data center, where the temperature and humidity controls kept it very cold.   He had been asked to setup up a basic route-map with BGP, and here is the diagram he worked from.</p>
<p><img title="BGP Triangle" src="http://blog.ine.com/wp-content/uploads/2010/06/BGP-Triangle.png" alt="BGP Triangle" width="598" height="346" /><br />
The goal, was to modify BGP,  so that all traffic going towards the 1.1.1.0 network (which is sourced from AS1), traveling either from or through AS23, would only use the 13.0.0.0/24 segment (between R3 and R1), and not use the 10.0.0.0/24 segment (between R2 and R1) as a transit path.<br />
Bob reviewed some of the BGP topics he had recently learned.   Here is the list he made of possibilities:<br />
R1 could pre-pend to the AS path for advertisements of the 1.1.1.0/24 prefix when it is sent to R2 from R1.   This way, AS23 would see a better path through R3 rather than R2.  He tried this using the following on R1:</p>
<pre>ip prefix-list JUST-1.1.1.0 seq 5 permit 1.1.1.0/24

route-map PRE-PEND permit 10
 match ip address prefix-list JUST-1.1.1.0
 set as-path prepend 1
route-map PRE-PEND permit 20

router bgp 1
 neighbor 10.0.0.2 route-map PRE-PEND out</pre>
<p>Bob cleared the BGP session, just to be sure.    Unfortunately, some traffic destined to 1.1.1.0 was still flowing over the 10.0.0.0 network between R2 and R1.</p>
<p>Bob decided to try another approach, and instead of R1 trying to make AS23 think the path on 10.0.0.0 was worse, perhaps he would tell R3 to make the path on 13.0.0.0 look better.    He considered weight, but then realized that would only work for R3, and not every other device in AS23.    So Bob decided to use local-preference.  On R3, he tried using local-preference, to specify that when a BGP update came in from R1 for 1.1.1.0, R3 would set the local-preference to 250 for that prefix, in hopes that this would allow traffic destined for 1.1.1.0 go exclusively through the 13.0.0.0 segment between R3 and R1.   Unfortunately, even with this change, Bob noticed that traffic destined to 1.1.1.0 from our through AS23 still crossed on the link between R2 and R1.</p>
<p>Below are the configurations for R1, R2 and R3 along with the relevant show commands.</p>
<p>Can you assist Bob?   What can he do?  What did he do wrong, if anything?</p>
<p>Post your ideas and comments below!</p>
<p>R1:</p>
<pre>version 12.4
hostname R1
interface Loopback0
 ip address 1.1.1.1 255.255.255.0
 ip ospf network point-to-point

interface FastEthernet0/0
 ip address 10.0.0.1 255.255.255.0
 ip ospf 1 area 1

interface FastEthernet1/0
 ip address 13.0.0.1 255.255.255.0
 ip ospf 1 area 1

router bgp 1
 no synchronization
 bgp log-neighbor-changes
 network 1.1.1.0 mask 255.255.255.0
 neighbor 10.0.0.2 remote-as 23
 neighbor 10.0.0.2 route-map PRE-PEND out
 neighbor 13.0.0.3 remote-as 23
 no auto-summary

ip prefix-list JUST-1.1.1.0 seq 5 permit 1.1.1.0/24

route-map PRE-PEND permit 10
 match ip address prefix-list JUST-1.1.1.0
 set as-path prepend 1

route-map PRE-PEND permit 20</pre>
<p>R2:</p>
<pre>version 12.4
hostname R2
interface FastEthernet0/0
 ip address 10.0.0.2 255.255.255.0
 ip ospf 1 area 1

interface FastEthernet0/1
 ip address 23.0.0.2 255.255.255.0
 ip ospf 1 area 1

router bgp 23
 no synchronization
 bgp log-neighbor-changes
 neighbor 10.0.0.1 remote-as 1
 neighbor 23.0.0.3 remote-as 23
 no auto-summary
!</pre>
<p>R3:</p>
<pre>version 12.4
hostname R3
interface FastEthernet0/0
 ip address 13.0.0.3 255.255.255.0
 ip ospf 1 area 1

interface FastEthernet0/1
 ip address 23.0.0.3 255.255.255.0
 ip ospf 1 area 1

router bgp 23
 no synchronization
 bgp log-neighbor-changes
 neighbor 13.0.0.1 remote-as 1
 neighbor 13.0.0.1 route-map SET-LOCAL-PREF in
 neighbor 23.0.0.2 remote-as 23
 no auto-summary

ip prefix-list LOCAL-PREF-250 seq 5 permit 1.1.1.0/24

route-map SET-LOCAL-PREF permit 10
 match ip address prefix-list LOCAL-PREF-250
 set local-preference 250

route-map SET-LOCAL-PREF permit 20</pre>
<p><strong>Show commands R1:</strong></p>
<pre><strong>R1#show ip bgp summary</strong>
BGP router identifier 1.1.1.1, local AS number 1
BGP table version is 2, main <a href="http://www.realexam.net/tag/routing" class="st_tag internal_tag" rel="tag" title="Posts tagged with routing">routing</a> table version 2
1 network entries using 120 bytes of memory
1 path entries using 52 bytes of memory
2/1 BGP path/bestpath attribute entries using 248 bytes of memory
0 BGP route-map cache entries using 0 bytes of memory
0 BGP filter-list cache entries using 0 bytes of memory
Bitfield cache entries: current 1 (at peak 2) using 32 bytes of memory
BGP using 452 total bytes of memory
BGP activity 2/1 prefixes, 2/1 paths, scan interval 60 secs

Neighbor        V    AS MsgRcvd MsgSent   TblVer  InQ OutQ Up/Down  State/PfxRcd
10.0.0.2        4    23      77      73        2    0    0 00:29:01        0
13.0.0.3        4    23      74      74        2    0    0 00:29:01        0

<strong>R1#show ip bgp</strong>
BGP table version is 2, local router ID is 1.1.1.1
Status codes: s suppressed, d damped, h history, * valid, &gt; best, i - internal,
r RIB-failure, S Stale
Origin codes: i - IGP, e - EGP, ? - incomplete

Network          Next Hop            Metric LocPrf Weight Path
*&gt; 1.1.1.0/24       0.0.0.0                  0         32768 i

<strong>R1#show ip route | begin resort</strong>
Gateway of last resort is not set

1.0.0.0/24 is subnetted, 1 subnets
C       1.1.1.0 is directly connected, Loopback0
23.0.0.0/24 is subnetted, 1 subnets
O       23.0.0.0 [110/2] via 13.0.0.3, 00:48:43, FastEthernet1/0
                 [110/2] via 10.0.0.2, 00:48:09, FastEthernet0/0
10.0.0.0/24 is subnetted, 1 subnets
C       10.0.0.0 is directly connected, FastEthernet0/0
13.0.0.0/24 is subnetted, 1 subnets
C       13.0.0.0 is directly connected, FastEthernet1/0</pre>
<p><strong>Show commands R2:</strong></p>
<pre><strong>R2#show ip bgp summary</strong>
BGP router identifier 2.2.2.2, local AS number 23
BGP table version is 14, main <a href="http://www.realexam.net/tag/routing" class="st_tag internal_tag" rel="tag" title="Posts tagged with routing">routing</a> table version 14
1 network entries using 120 bytes of memory
2 path entries using 104 bytes of memory
3/1 BGP path/bestpath attribute entries using 372 bytes of memory
2 BGP AS-PATH entries using 48 bytes of memory
0 BGP route-map cache entries using 0 bytes of memory
0 BGP filter-list cache entries using 0 bytes of memory
Bitfield cache entries: current 1 (at peak 2) using 32 bytes of memory
BGP using 676 total bytes of memory
BGP activity 1/0 prefixes, 4/2 paths, scan interval 60 secs

Neighbor        V    AS MsgRcvd MsgSent   TblVer  InQ OutQ Up/Down  State/PfxRcd
10.0.0.1        4     1      73      77       14    0    0 00:29:07        1
23.0.0.3        4    23      71      73       14    0    0 01:04:54        1

<strong>R2#show ip bgp</strong>
BGP table version is 14, local router ID is 2.2.2.2
Status codes: s suppressed, d damped, h history, * valid, &gt; best, i - internal,
r RIB-failure, S Stale
Origin codes: i - IGP, e - EGP, ? - incomplete

Network          Next Hop            Metric LocPrf Weight Path
*&gt;i1.1.1.0/24       13.0.0.1                 0    250      0 1 i
*                   10.0.0.1                 0             0 1 1 i

<strong>R2#show ip route | begin resort</strong>
Gateway of last resort is not set

1.0.0.0/24 is subnetted, 1 subnets
B       1.1.1.0 [200/0] via 13.0.0.1, 00:28:37
2.0.0.0/24 is subnetted, 1 subnets
C       2.2.2.0 is directly connected, Loopback0
23.0.0.0/24 is subnetted, 1 subnets
C       23.0.0.0 is directly connected, FastEthernet0/1
10.0.0.0/24 is subnetted, 1 subnets
C       10.0.0.0 is directly connected, FastEthernet0/0
13.0.0.0/24 is subnetted, 1 subnets
O       13.0.0.0 [110/2] via 23.0.0.3, 00:48:16, FastEthernet0/1
                 [110/2] via 10.0.0.1, 00:49:19, FastEthernet0/0</pre>
<p><strong>Show commands R3:</strong></p>
<pre><strong>R3#show ip bgp summary</strong>
BGP router identifier 3.3.3.3, local AS number 23
BGP table version is 6, main <a href="http://www.realexam.net/tag/routing" class="st_tag internal_tag" rel="tag" title="Posts tagged with routing">routing</a> table version 6
1 network entries using 120 bytes of memory
1 path entries using 52 bytes of memory
3/1 BGP path/bestpath attribute entries using 372 bytes of memory
1 BGP AS-PATH entries using 24 bytes of memory
0 BGP route-map cache entries using 0 bytes of memory
0 BGP filter-list cache entries using 0 bytes of memory
Bitfield cache entries: current 1 (at peak 2) using 32 bytes of memory
BGP using 600 total bytes of memory
BGP activity 1/0 prefixes, 5/4 paths, scan interval 60 secs

Neighbor        V    AS MsgRcvd MsgSent   TblVer  InQ OutQ Up/Down  State/PfxRcd
13.0.0.1        4     1      74      74        6    0    0 00:29:09        1
23.0.0.2        4    23      73      71        6    0    0 01:04:56        0

<strong>R3#show ip bgp</strong>
BGP table version is 6, local router ID is 3.3.3.3
Status codes: s suppressed, d damped, h history, * valid, &gt; best, i - internal,
r RIB-failure, S Stale
Origin codes: i - IGP, e - EGP, ? - incomplete

Network          Next Hop            Metric LocPrf Weight Path
*&gt; 1.1.1.0/24       13.0.0.1                 0    250      0 1 i

<strong>R3#show ip route | begin resort</strong>
Gateway of last resort is not set

1.0.0.0/24 is subnetted, 1 subnets
B       1.1.1.0 [20/0] via 13.0.0.1, 00:28:39
3.0.0.0/24 is subnetted, 1 subnets
C       3.3.3.0 is directly connected, Loopback0
23.0.0.0/24 is subnetted, 1 subnets
C       23.0.0.0 is directly connected, FastEthernet0/1
10.0.0.0/24 is subnetted, 1 subnets
O       10.0.0.0 [110/2] via 23.0.0.2, 00:48:18, FastEthernet0/1
                 [110/2] via 13.0.0.1, 00:48:48, FastEthernet0/0
13.0.0.0/24 is subnetted, 1 subnets
C       13.0.0.0 is directly connected, FastEthernet0/0</pre>
<p>Best wishes,</p>
<p>Keith</p>
<p><strong>And the answer is:</strong></p>
<p>Thanks to you, and your 50+ posts, bob got his answer.   By reading your responses, Bob learned the following:</p>
<p>For R2, the BGP next hop for the best route, is still 13.0.0.1, even though it is learned from R3.     R3 doesn’t bother to change the next-hop attribute when learning routes via a eBGP neighbor (R1).    With R2 having 2 equal cost paths (OSPF) for the next hop of 13.0.0.1, R2 would load balance the traffic over the 10.0.0.0 and 23.0.0.0 networks for traffic going to 1.1.1.0/24</p>
<p>One solution would be to have R3 use next-hop-self for updates sent to R2.  Then R2 would see the next hop as 23.0.0.3, and all the traffic would be forwarded to R3 as desired.</p>
<p>The update on R3 would look like this:</p>
<pre>router bgp 23
 neighbor 23.0.0.2 next-hop-self</pre>
<p>This would cause R2, to have the BGP table of this:</p>
<pre>R2#show ip bgp
BGP table version is 4, local router ID is 2.2.2.2
Status codes: s suppressed, d damped, h history, * valid, &gt; best, i - internal,
r RIB-failure, S Stale
Origin codes: i - IGP, e - EGP, ? - incomplete

Network          Next Hop            Metric LocPrf Weight Path
<strong>*&gt;i1.1.1.0/24       23.0.0.3                 0    250      0 1 i</strong>
*                   10.0.0.1                 0             0 1 1 i</pre>
<p>Another option would be increasing the OSPF cost on R2’s 10.0.0.0/24 interface, so that it wouldn’t be considered an equal cost to get to 13.0.0.1 (the previous next hop before the change we just made).</p>
<div style='clear:both'></div><img src="http://www.realexam.net/?ak_action=api_record_view&id=4692&type=feed" alt="" /><img src="http://feeds.feedburner.com/~r/certting/~4/K775IdOthsU" height="1" width="1"/><img src="http://feeds.feedburner.com/~r/certting/~4/uCwpmHLSwGE" height="1" width="1"/><img src="http://feeds.feedburner.com/~r/certting/~4/PRACNV3iBjs" height="1" width="1"/>]]></content:encoded>
			<wfw:commentRss>http://www.realexam.net/bgp-path-manipulation/4692.html/feed</wfw:commentRss>
		<slash:comments>0</slash:comments>
		<feedburner:origLink>http://www.realexam.net/bgp-path-manipulation/4692.html</feedburner:origLink><feedburner:origLink>http://feedproxy.google.com/~r/certting/~3/K775IdOthsU/4692.html</feedburner:origLink><feedburner:origLink>http://feedproxy.google.com/~r/certting/~3/uCwpmHLSwGE/4692.html</feedburner:origLink></item>
		<item>
		<title>New QoS Class : Answers and Explanations</title>
		<link>http://feedproxy.google.com/~r/certting/~3/YLNGOspvjhY/4690.html</link>
		<comments>http://www.realexam.net/new-qos-class-answers-and-explanations/4690.html#comments</comments>
		<pubDate>Wed, 21 Jul 2010 11:39:44 +0000</pubDate>
		<dc:creator>Johnny</dc:creator>
				<category><![CDATA[CCIE Training]]></category>
		<category><![CDATA[CCSP Training]]></category>
		<category><![CDATA[CCVP Training]]></category>
		<category><![CDATA[CCIE]]></category>
		<category><![CDATA[exam]]></category>
		<category><![CDATA[lab]]></category>
		<category><![CDATA[practice]]></category>
		<category><![CDATA[qos]]></category>

		<guid isPermaLink="false">http://www.realexam.net/?p=4690</guid>
		<description><![CDATA[Try these questions on for size! Learn all this and much more in the new QoS class. 1. Based on the following configuration, what traffic will be policed? class-map C_MUSIC match protocol kazaa2 match protocol napster ! class-map match-any C_WEB match p... ]]></description>
			<content:encoded><![CDATA[<p>Try these questions on for size! Learn all this and much more in the new QoS class.</p>
<div id="_mcePaste">1. Based on the following configuration, what traffic will be policed?</div>
<div id="_mcePaste">class-map C_MUSIC</div>
<div id="_mcePaste">match protocol kazaa2</div>
<div id="_mcePaste">match protocol napster</div>
<div id="_mcePaste">!</div>
<div id="_mcePaste">class-map match-any C_WEB</div>
<div id="_mcePaste">match protocol http</div>
<div id="_mcePaste">match class-map C_MUSIC</div>
<div id="_mcePaste">!</div>
<div id="_mcePaste">policy-map P_WEB</div>
<div id="_mcePaste">class C_WEB</div>
<div id="_mcePaste">police 64000</div>
<div id="_mcePaste">!</div>
<div id="_mcePaste">interface serial 0/0</div>
<div id="_mcePaste">service-policy output P_WEB</div>
<div></div>
<blockquote>
<div id="_mcePaste">A. All Kazaa version 2 traffic is policed</div>
<div id="_mcePaste">B. All Napster traffic is policed</div>
<div id="_mcePaste">C. All web traffic is policed</div>
<div id="_mcePaste">D. All Kazaa version 2, Napster, and web traffic is policed</div>
<div id="_mcePaste">E. No traffic is policed</div>
</blockquote>
<div></div>
<div id="_mcePaste">2. You are configuring a Cisco Catalyst 3550 switch port to trust CoS markings if, and only if, the marking originated from a Cisco IP Phone. In an attempt to perform this configuration, you enter the mls qos trust device cisco-phone command. However, your configuration does not seem to be working properly. Why is the switch not trusting CoS markings coming from an attached Cisco IP Phone?</div>
<blockquote>
<div id="_mcePaste">A. A Cisco Catalyst 3550 switch supports the mls qos trust device cisco-phone command, but the Cisco Catalyst 2950 does not support this command.</div>
<div id="_mcePaste">B. The mls qos trust cos command is missing.</div>
<div id="_mcePaste">C. The mls qos trust extend command is missing.</div>
<div id="_mcePaste">D. The mls qos cos 5 command is missing.</div>
</blockquote>
<div></div>
<div id="_mcePaste">3. You administer a network that transports both voice and interactive video traffic. Since these traffic types are both latency-sensitive, you decide to implement the following configuration. Which statement is true regarding the configuration?</div>
<div id="_mcePaste">class-map C_VOICE</div>
<div id="_mcePaste">match protocol rtp audio</div>
<div id="_mcePaste">class-map C_VIDEO</div>
<div id="_mcePaste">match protocol rtp video</div>
<div id="_mcePaste">!</div>
<div id="_mcePaste">policy-map P_HIGH_PRIORITY</div>
<div id="_mcePaste">class C_VOICE</div>
<div id="_mcePaste">priority percent 15</div>
<div id="_mcePaste">class C_VIDEO</div>
<div id="_mcePaste">priority percent 35</div>
<div id="_mcePaste">class class-default</div>
<div id="_mcePaste">fair-queue</div>
<div id="_mcePaste">!</div>
<div id="_mcePaste">interface serial 0/0</div>
<div id="_mcePaste">service-policy output P_HIGH_PRIORITY</div>
<blockquote>
<div id="_mcePaste">A. The configuration results in three queues, one for the C_VOICE class, one for the C_VIDEO class, and one queue for the class-default class.</div>
<div id="_mcePaste">B. The configuration results in two queues, one priority queue and one queue for the class-default class.</div>
<div id="_mcePaste">C. The class-default class uses FIFO as its queuing mechanism for traffic flows within its queue.</div>
<div id="_mcePaste">D. The two priority queues use WFQ for queuing traffic within those queues.</div>
</blockquote>
<div></div>
<div id="_mcePaste">4. CB-WRED is configured using the random-detect command. Which two of the following statements are true concerning the random-detect command? (Choose 2)</div>
<blockquote>
<div id="_mcePaste">A. The random-detect command cannot be issued for the class-default class.</div>
<div id="_mcePaste">B. The random-detect command cannot be issued for the priority class(es).</div>
<div id="_mcePaste">C. The random-detect command must be issued in conjunction with the bandwidth command (with the exception of the class-default class).</div>
<div id="_mcePaste">D. The random-detect command should be issued in conjunction with the priority command.</div>
</blockquote>
<div></div>
<div id="_mcePaste">5. Consider the following configuration:</div>
<div id="_mcePaste">class-map TRANSACTIONAL</div>
<div id="_mcePaste">match protocol http</div>
<div id="_mcePaste">!</div>
<div id="_mcePaste">policy-map CBPOLICING</div>
<div id="_mcePaste">class TRANSACTIONAL</div>
<div id="_mcePaste">police 128000 conform-action set-dscp-transmit af11 exceed-action set-dscp-transmit af13 violate-action drop</div>
<div id="_mcePaste">!</div>
<div id="_mcePaste">interface serial 0/1</div>
<div id="_mcePaste">service-policy input CBPOLICING</div>
<div id="_mcePaste">What type of class-based policing configuration is represented by this configuration?</div>
<blockquote>
<div id="_mcePaste">A. Single rate, single bucket</div>
<div id="_mcePaste">B. Single rate, dual bucket</div>
<div id="_mcePaste">C. Dual rate, single bucket</div>
<div id="_mcePaste">D. Dual rate, dual bucket</div>
</blockquote>
<div></div>
<div id="_mcePaste">6. You configure CB-Shaping by issuing the command shape peak 8000 2000 2000. This configuration shapes to what peak rate?</div>
<blockquote>
<div id="_mcePaste">A. 4000 bps</div>
<div id="_mcePaste">B. 8000 bps</div>
<div id="_mcePaste">C. 16000 bps</div>
<div id="_mcePaste">D. 32000 bps</div>
</blockquote>
<div></div>
<div id="_mcePaste">7. You are configuring Multilink PPP (MLP) as your Link Fragmentation and Interleaving (LFI) mechanism for a WAN link. Identify the correct statements regarding the configuration of MLP. (Choose 2)</div>
<blockquote>
<div id="_mcePaste">A. The configuration of Multilink PPP requires at least two physical links (e.g. two serial interfaces).</div>
<div id="_mcePaste">B. The IP address is removed from any serial interface that makes up the MLP bundle.</div>
<div id="_mcePaste">C. Any policy-map that was previously assigned to a physical interface should be reassigned to the multilink interface, that the physical interface is associated with, in order for the policy to take effect.</div>
<div id="_mcePaste">D. The virtual multilink interface does not use an IP address. Rather, it uses the IP unnumbered feature which allows the multilink interface to share an IP address with the multilink bundle member that has the highest IP address.</div>
</blockquote>
<p><strong>1.</strong> Based on the following configuration, what traffic will be policed?</p>
<pre>class-map C_MUSIC
  match protocol kazaa2
  match protocol napster
!
class-map match-any C_WEB
  match protocol http
  match class-map C_MUSIC
!
policy-map P_WEB
  class C_WEB
    police 64000
!
interface serial 0/0
  service-policy output P_WEB</pre>
<p>A. All Kazaa version 2 traffic is policed</p>
<p>B. All Napster traffic is policed</p>
<p>C. All web traffic is policed</p>
<p>D. All Kazaa version 2, Napster, and web traffic is policed</p>
<p>E. No traffic is policed</p>
<p><strong>Answer:</strong></p>
<p>C</p>
<p><strong>Explanation:</strong></p>
<p>The C_MUSIC class-map does not specify the <strong>match-any</strong> or<strong> match-all</strong> option. The default is <strong>match-all</strong>. Therefore, for traffic to be classified in the C_MUSIC class-map, a packet would simultaneously have to be a Kazaa version 2 packet and a Napster packet, which isn’t possible.</p>
<p>The C_WEB class-map uses the <strong>match-any</strong> option, meaning that traffic will be classified in this class-map if it is HTTP traffic or if it is traffic that was classified in the C_MUSIC class-map. Since, no traffic will be classified in the C_MUSIC class-map, as described above, the only traffic that will be classified by the C_WEB class-map is HTTP traffic.</p>
<p>The policy-map P_WEB is configured to police (i.e. rate limit) traffic classified by the C_WEB class-map to a bandwidth of 64 kbps. (NOTE: The default conform-action is transmit, and the default exceed-action is drop.) Since only HTTP (i.e. web) traffic is matched by the C_WEB class-map, web traffic is the only traffic that is policed.</p>
<p><strong>2.</strong> You are configuring a Cisco Catalyst 3560 switch port to trust CoS markings if, and only if, the marking originated from a Cisco IP Phone. In an attempt to perform this configuration, you enter the <strong>mls qos trust device cisco-phone</strong> command. However, your configuration does not seem to be working properly. Why is the switch not trusting CoS markings coming from an attached Cisco IP Phone?</p>
<p>A. A Cisco Catalyst 2950 switch supports the <strong>mls qos trust device cisco-phone</strong> command, but the Cisco Catalyst 3560 does not support this command</p>
<p>B. The <strong>mls qos trust cos</strong> command is missing</p>
<p>C. The <strong>mls qos trust extend</strong> command is missing</p>
<p>D. The <strong>mls qos cos 5</strong> command is missing</p>
<p>E. The PC attached to the phone is overriding the CoS markings</p>
<p><strong>Answer:</strong></p>
<p>B</p>
<p><strong>Explanation:</strong></p>
<p>A Cisco Catalyst 2950 switch port can be configured to trust Class of Service (CoS) markings, Differentiated Services Code Point (DSCP), or CoS markings originating from a Cisco IP Phone. The switch port can detect that a CoS marking is coming from a Cisco IP Phone via the Cisco Discovery Protocol (CDP). The <strong>mls qos trust device cisco-phone</strong> command does indeed tell the switch to trust a marking if, and only if, the marking comes from a Cisco IP Phone. However, the <strong>mls qos trust device cisco-phone </strong>command by itself does not tell the switch port which marking (i.e. CoS or DSCP) coming from the Cisco IP Phone to trust. Therefore, the <strong>mls qos trust cos</strong> command is also required.</p>
<p>3. You administer a network that transports both voice and interactive video traffic. Since these traffic types are both latency-sensitive, you decide to implement the following configuration. Which statement is true regarding the configuration?</p>
<pre>class-map C_VOICE
  match protocol rtp audio
!
class-map C_VIDEO
  match protocol rtp video
!
policy-map P_HIGH_PRIORITY
  class C_VOICE
    priority percent 15
  class C_VIDEO
    priority percent 35
  class class-default
    fair-queue
!
interface serial 0/0
  service-policy output P_HIGH_PRIORITY</pre>
<p>A. The configuration results in three queues, one for the C_VOICE class, one for the C_VIDEO class, and one queue for the class-default class</p>
<p>B. The configuration results in two queues, one priority queue and one queue for the class-default class</p>
<p>C. The class-default class uses FIFO as its queuing mechanism for traffic flows within its queue</p>
<p>D. The two priority queues use WFQ for queuing traffic within those queues</p>
<p><strong>Answer:</strong></p>
<p>B</p>
<p><strong>Explanation:</strong></p>
<p>While priority treatment (i.e. LLQ treatment) can be assigned to more than one class-map, an interface only has one priority queue. Therefore, in the above configuration, traffic classified in the C_VOICE and C_VIDEO class-maps shares the same priority queue. A second queue contains traffic classified in the class-default class-map. Therefore, the configuration only results in two queues, one shared priority queue and one queue for the class-default class. On most models of routers, only the class-default queue can be configured to use WFQ queuing for flows within the queue, while other queues use FIFO queuing for traffic within those queues.</p>
<p><strong>4.</strong> CB-WRED is configured using the <strong>random-detect</strong> command. Which two of the following statements are true concerning the <strong>random-detect</strong>command? (Choose 2)</p>
<p>A. The <strong>random-detect</strong> command cannot be issued for the class-default class.</p>
<p>B. The <strong>random-detect</strong> command cannot be issued for the priority class(es).</p>
<p>C. The <strong>random-detect</strong> command must be issued in conjunction with the bandwidth command (with the exception of the class-default class).</p>
<p>D. The <strong>random-detect</strong> command should be issued in conjunction with the priority command.</p>
<p><strong>Answer:</strong></p>
<p>B, C</p>
<p><strong>Explanation:</strong></p>
<p>Weighted Random Early Detection (WRED) is effective for TCP flows, because WRED can cause some TCP flows to enter TCP slow start. When configuring class-based WRED (i.e. CB-WRED), the <strong>random-detect</strong> command is issued in policy-map-class configuration mode. While the <strong>random-detect</strong> command can be used with the <strong>class-default</strong> class,<strong>random-detect </strong>cannot be issued in policy-map-class configuration mode for a class configured with the <strong>priority</strong> keyword. Also, with the exception of the class-default class, the <strong>random-detect</strong> command must be issued along with the<strong>bandwidth</strong> command.</p>
<p><strong>5.</strong> Consider the following configuration:</p>
<pre>class-map TRANSACTIONAL
  match protocol http
!
policy-map CBPOLICING
  class TRANSACTIONAL
    police 128000 conform-action set-dscp-transmit af11 exceed-action set-dscp-transmit af13 violate-action drop
!
interface serial 0/1
  service-policy input CBPOLICING</pre>
<p>What type of class-based policing configuration is represented by this configuration?</p>
<p>A. Single rate, single bucket</p>
<p>B. Single rate, dual bucket</p>
<p>C. Dual rate, single bucket</p>
<p>D. Dual rate, dual bucket</p>
<p><strong>Answer:</strong></p>
<p>B</p>
<p><strong>Explanation:</strong></p>
<p>Cisco IOS supports single rate, single bucket; single rate, dual bucket; and dual rate, dual bucket policers. With a single rate policer, only a committed information rate (CIR) is specified, as in this question. With a dual rate policer, both a CIR and a peak information rate (PIR) are specified. Also, a single rate policer is a single bucket policer, unless the <strong>violate</strong>action is specified. If the violate action is specified, as it is in this question, the single rate policer uses two buckets, a Bc bucket and a Be bucket. However, a dual rate policer always uses two buckets, one bucket to transmit traffic at the CIR and one bucket to transmit traffic at the PIR.</p>
<p>6. You configure CB-Shaping by issuing the command <strong>shape peak 8000 2000 2000</strong>. This configuration shapes to what peak rate?</p>
<p>A. 4000 bps</p>
<p>B. 8000 bps</p>
<p>C. 16000 bps</p>
<p>D. 32000 bps</p>
<p><strong>Answer:</strong></p>
<p>C</p>
<p><strong>Explanation:</strong></p>
<p>In the syntax, the <strong>8000</strong> represents the Committed Information Rate (CIR). The first <strong>2000</strong> is the Committed Burst (Bc), and the second <strong>2000</strong> is the Excess Burst (Be). When configuring CB-Shaping, you can either shape to “average” or shape to “peak.” When shaping to average, traffic rates don’t exceed the CIR. However, when shaping to peak, traffic rates can burst above the CIR, while some of that excess traffic could be dropped by the service provider. When shaping to peak, the peak shaping rate is calculated by the formula:</p>
<p><strong>peak_rate = CIR * (1 + Be/Bc)</strong></p>
<p>In this example: peak_rate = 8000 * (1 + 2000/2000) = 16,000 bps. Note that if the Bc and Be values are calculated by IOS rather than being statically configured, Bc will always equal Be, which means that the peak rate will be twice the CIR.</p>
<p><strong>7.</strong> You are configuring Multilink PPP (MLP) as your Link Fragmentation and Interleaving (LFI) mechanism for a WAN link. Identify the correct statements regarding the configuration of MLP. (Choose 2)</p>
<p>A. The configuration of Multilink PPP requires at least two physical links (e.g. two serial interfaces)</p>
<p>B. The IP address is removed from any serial interface that makes up the MLP bundle</p>
<p>C. Any policy-map that was previously assigned to a physical interface should be reassigned to the multilink interface, that the physical interface is associated with, in order for the policy to take effect</p>
<p>D. The virtual multilink interface does not use an IP address. Rather, it uses the IP unnumbered feature which allows the multilink interface to share an IP address with the multilink bundle member that has the highest IP address</p>
<p><strong>Answer:</strong></p>
<p>B, C</p>
<p><strong>Explanation:</strong></p>
<p>Multilink PPP (MLP) is a Link Fragmentation and Interleaving (LFI) mechanism for PPP links. Interestingly, even though the term “multilink” is in the title of this mechanism, MLP can be configured on a single link. Specifically, a virtual multilink interface is created. Then, one or more physical interfaces are added as members of a multilink bundle, all of which act as the single multilink interface. As a result, the virtual multilink interface is assigned an IP address, while the one or more physical interface member(s) do not have an IP address. Additionally, since the packets are logically transmitted over the virtual multilink interface, in order to apply a policy-map to the traffic using the virtual interface, the <strong>service-policy</strong>command should be applied to the virtual multilink interface, as opposed to the member interfaces</p>
<p>1. Based on the following configuration, what traffic will be policed?class-map C_MUSICmatch protocol kazaa2match protocol napster!class-map match-any C_WEBmatch protocol httpmatch class-map C_MUSIC!policy-map P_WEBclass C_WEBpolice 64000!interface serial 0/0service-policy output P_WEBA. All Kazaa version 2 traffic is policedB. All Napster traffic is policedC. All web traffic is policedD. All Kazaa version 2, Napster, and web traffic is policedE. No traffic is policed2. You are configuring a Cisco Catalyst 3550 switch port to trust CoS markings if, and only if, the marking originated from a Cisco IP Phone. In an attempt to perform this configuration, you enter the mls qos trust device cisco-phone command. However, your configuration does not seem to be working properly. Why is the switch not trusting CoS markings coming from an attached Cisco IP Phone?A. A Cisco Catalyst 3550 switch supports the mls qos trust device cisco-phone command, but the Cisco Catalyst 2950 does not support this command.B. The mls qos trust cos command is missing.C. The mls qos trust extend command is missing.D. The mls qos cos 5 command is missing.3. You administer a network that transports both voice and interactive video traffic. Since these traffic types are both latency-sensitive, you decide to implement the following configuration. Which statement is true regarding the configuration?class-map C_VOICEmatch protocol rtp audioclass-map C_VIDEOmatch protocol rtp video!policy-map P_HIGH_PRIORITYclass C_VOICEpriority percent 15class C_VIDEOpriority percent 35class class-defaultfair-queue!interface serial 0/0service-policy output P_HIGH_PRIORITYA. The configuration results in three queues, one for the C_VOICE class, one for the C_VIDEO class, and one queue for the class-default class.B. The configuration results in two queues, one priority queue and one queue for the class-default class.C. The class-default class uses FIFO as its queuing mechanism for traffic flows within its queue.D. The two priority queues use WFQ for queuing traffic within those queues.4. CB-WRED is configured using the random-detect command. Which two of the following statements are true concerning the random-detect command? (Choose 2)A. The random-detect command cannot be issued for the class-default class.B. The random-detect command cannot be issued for the priority class(es).C. The random-detect command must be issued in conjunction with the bandwidth command (with the exception of the class-default class).D. The random-detect command should be issued in conjunction with the priority command.5. Consider the following configuration:class-map TRANSACTIONALmatch protocol http!policy-map CBPOLICINGclass TRANSACTIONALpolice 128000 conform-action set-dscp-transmit af11 exceed-action set-dscp-transmit af13 violate-action drop!interface serial 0/1service-policy input CBPOLICINGWhat type of class-based policing configuration is represented by this configuration?A. Single rate, single bucketB. Single rate, dual bucketC. Dual rate, single bucketD. Dual rate, dual bucket6. You configure CB-Shaping by issuing the command shape peak 8000 2000 2000. This configuration shapes to what peak rate?A. 4000 bpsB. 8000 bpsC. 16000 bpsD. 32000 bps7. You are configuring Multilink PPP (MLP) as your Link Fragmentation and Interleaving (LFI) mechanism for a WAN link. Identify the correct statements regarding the configuration of MLP. (Choose 2)A. The configuration of Multilink PPP requires at least two physical links (e.g. two serial interfaces).B. The IP address is removed from any serial interface that makes up the MLP bundle.C. Any policy-map that was previously assigned to a physical interface should be reassigned to the multilink interface, that the physical interface is associated with, in order for the policy to take effect.D. The virtual multilink interface does not use an IP address. Rather, it uses the IP unnumbered feature which allows the multilink interface to share an IP address with the multilink bundle member that has the highest IP address.</p>
<div style='clear:both'></div><img src="http://www.realexam.net/?ak_action=api_record_view&id=4690&type=feed" alt="" /><img src="http://feeds.feedburner.com/~r/certting/~4/8YIEcgOgCME" height="1" width="1"/><img src="http://feeds.feedburner.com/~r/certting/~4/RShKWOEq_sM" height="1" width="1"/><img src="http://feeds.feedburner.com/~r/certting/~4/YLNGOspvjhY" height="1" width="1"/>]]></content:encoded>
			<wfw:commentRss>http://www.realexam.net/new-qos-class-answers-and-explanations/4690.html/feed</wfw:commentRss>
		<slash:comments>0</slash:comments>
		<feedburner:origLink>http://www.realexam.net/new-qos-class-answers-and-explanations/4690.html</feedburner:origLink><feedburner:origLink>http://feedproxy.google.com/~r/certting/~3/8YIEcgOgCME/4690.html</feedburner:origLink><feedburner:origLink>http://feedproxy.google.com/~r/certting/~3/RShKWOEq_sM/4690.html</feedburner:origLink></item>
		<item>
		<title>MPLS and EIGRP, going the Distance:Admin Distance</title>
		<link>http://feedproxy.google.com/~r/certting/~3/GKlE-Oqa54g/4688.html</link>
		<comments>http://www.realexam.net/mpls-and-eigrp-going-the-distance-admin-distance/4688.html#comments</comments>
		<pubDate>Wed, 21 Jul 2010 11:32:46 +0000</pubDate>
		<dc:creator>Johnny</dc:creator>
				<category><![CDATA[CCIE Training]]></category>
		<category><![CDATA[admin distance]]></category>
		<category><![CDATA[CCIE]]></category>
		<category><![CDATA[eigrp]]></category>
		<category><![CDATA[MPLS]]></category>

		<guid isPermaLink="false">http://www.realexam.net/?p=4688</guid>
		<description><![CDATA[R2, R3 and R4 create the service provider network, with MPLS on all three routers, and iBGP at the PE routers.  R1 and R5 are the CE routers. R2, prefers the BGP next hop of 4.4.4.4 for network 5.5.5.5 (R5 loopback). R4, at 4.4.4.4 is an iBGP neighbor. ... ]]></description>
			<content:encoded><![CDATA[<p>R2, R3 and R4 create the service provider network, with MPLS on all three routers, and iBGP at the PE routers.  R1 and R5 are the CE routers.</p>
<p>R2, prefers the BGP next hop of 4.4.4.4 for network 5.5.5.5 (R5 loopback). R4, at 4.4.4.4 is an iBGP neighbor.</p>
<pre>R2#show ip route vrf v | inc 5.5.5.0
B       5.5.5.0 [200/409600] via 4.4.4.4, 00:06:47</pre>
<p>Is R2 preferring an iBGP learned route, which has an AD of 200, over a EIGRP route, which would have an AD of 90?</p>
<p>Can you identify why the <a href="http://www.realexam.net/tag/routing" class="st_tag internal_tag" rel="tag" title="Posts tagged with routing">routing</a> for 5.5.5.0 on the VRF of R2 is using BGP instead of EIGRP?</p>
<p><img title="EIGRP PATH with MPLS" src="http://blog.ine.com/wp-content/uploads/2010/07/EIGRP-PATH-with-MPLS.png" alt="EIGRP PATH with MPLS" width="669" height="271" /></p>
<p>Below are the relevant portions of the configuration, which also can serve as a great review of how to configure MPLS VPNs.<br />
R1, CE router:</p>
<pre><strong>R1#show run</strong>
interface Loopback0
 ip address 1.1.1.1 255.255.255.0
!
interface FastEthernet0/0
 ip address 10.1.12.1 255.255.255.0
 duplex auto
 speed auto
!
interface Serial0/0
 ip address 10.1.215.1 255.255.255.0
!

router eigrp 1
 network 0.0.0.0
 no auto-summary</pre>
<p>R2, PE Router:</p>
<pre><strong>R2#show run</strong>
!
ip vrf v
 rd 1:1
 route-target export 1:1
 route-target import 1:1
!
!
interface Loopback0
 ip address 2.2.2.2 255.255.255.255
 ip ospf 1 area 0
!
interface FastEthernet0/0
 ip vrf forwarding v
 ip address 10.1.12.2 255.255.255.0
!
interface FastEthernet0/1
 ip address 10.1.23.2 255.255.255.0
 ip ospf 1 area 0
 mpls ip
!
router eigrp 1
 no auto-summary
 !
 address-family ipv4 vrf v
  redistribute bgp 234 metric 1 10000 1 1 1
  network 10.1.12.2 0.0.0.0
  auto-summary
  autonomous-system 1
 exit-address-family
!
router ospf 1
 log-adjacency-changes
!
router bgp 234
 no bgp default ipv4-unicast
 bgp log-neighbor-changes
 neighbor 4.4.4.4 remote-as 234
 neighbor 4.4.4.4 update-source Loopback0
 !
 address-family vpnv4
  neighbor 4.4.4.4 activate
  neighbor 4.4.4.4 send-community extended
 exit-address-family
 !
 address-family ipv4 vrf v
  redistribute eigrp 1
  no synchronization
 exit-address-family
!
ip forward-protocol nd
!</pre>
<p>R3, P router:</p>
<pre><strong>R3#show run</strong>

interface Loopback0
 ip address 3.3.3.3 255.255.255.255
!
interface FastEthernet0/0
 ip address 10.1.34.3 255.255.255.0
 mpls ip
!
interface FastEthernet0/1
 ip address 10.1.23.3 255.255.255.0
 mpls ip
!
router ospf 1
 log-adjacency-changes
 network 0.0.0.0 255.255.255.255 area 0
!</pre>
<p>R4: PE Router</p>
<pre><strong>R4#show run</strong>
!
ip vrf v
 rd 1:1
 route-target export 1:1
 route-target import 1:1
!
!
interface Loopback0
 ip address 4.4.4.4 255.255.255.255
 ip ospf 1 area 0
!
interface FastEthernet0/0
 ip address 10.1.34.4 255.255.255.0
 ip ospf 1 area 0
 mpls ip
!
interface FastEthernet0/1
 ip vrf forwarding v
 ip address 10.1.45.4 255.255.255.0
!
router eigrp 1
 no auto-summary
 !
 address-family ipv4 vrf v
  redistribute bgp 234 metric 1 1 1 1 1
  network 10.1.45.4 0.0.0.0
  auto-summary
  autonomous-system 1
 exit-address-family
!
router ospf 1
 log-adjacency-changes
!
router bgp 234
 no bgp default ipv4-unicast
 bgp log-neighbor-changes
 neighbor 2.2.2.2 remote-as 234
 neighbor 2.2.2.2 update-source Loopback0
 !
 address-family vpnv4
  neighbor 2.2.2.2 activate
  neighbor 2.2.2.2 send-community extended
 exit-address-family
 !
 address-family ipv4 vrf v
  redistribute eigrp 1
  no synchronization
 exit-address-family</pre>
<p>R5: CE Router</p>
<pre><strong>R5#show run</strong>
!
interface Loopback0
 ip address 5.5.5.5 255.255.255.0
!
interface Serial0/0
 ip address 10.1.215.5 255.255.255.0
 clock rate 64000
!
interface FastEthernet0/1
 ip address 10.1.45.5 255.255.255.0
!
router eigrp 1
 network 0.0.0.0
 no auto-summary
!</pre>
<p>Now for a couple show commands on R1:</p>
<pre><strong>R1#show ip route eigrp</strong>
     5.0.0.0/24 is subnetted, 1 subnets
D       5.5.5.0 [90/435200] via 10.1.12.2, 00:19:08, FastEthernet0/0
     10.0.0.0/24 is subnetted, 3 subnets
D       10.1.45.0 [90/307200] via 10.1.12.2, 00:19:08, FastEthernet0/0
R1#

<strong>R1#show ip eigrp topology</strong>
IP-EIGRP Topology Table for AS(1)/ID(10.1.215.1)

Codes: P - Passive, A - Active, U - Update, Q - Query, R - Reply,
       r - reply Status, s - sia Status

P 1.1.1.0/24, 1 successors, FD is 128256
        via Connected, Loopback0
P 5.5.5.0/24, 1 successors, FD is 435200
        via 10.1.12.2 (435200/409600), FastEthernet0/0
        via 10.1.215.5 (2297856/128256), Serial0/0
P 10.1.12.0/24, 1 successors, FD is 281600
        via Connected, FastEthernet0/0
P 10.1.45.0/24, 1 successors, FD is 307200
        via 10.1.12.2 (307200/281600), FastEthernet0/0
        via 10.1.215.5 (2195456/281600), Serial0/0
P 10.1.215.0/24, 1 successors, FD is 2169856
        via Connected, Serial0/0
R1#</pre>
<p>And some on R2, the PE router:</p>
<pre><strong>R2#show ip route vrf v</strong>

<a href="http://www.realexam.net/tag/routing" class="st_tag internal_tag" rel="tag" title="Posts tagged with routing">Routing</a> Table: v
Codes: C - connected, S - static, R - RIP, M - mobile, B - BGP
       D - EIGRP, EX - EIGRP external, O - OSPF, IA - OSPF inter area
       N1 - OSPF NSSA external type 1, N2 - OSPF NSSA external type 2
       E1 - OSPF external type 1, E2 - OSPF external type 2
       i - IS-IS, su - IS-IS summary, L1 - IS-IS level-1, L2 - IS-IS level-2
       ia - IS-IS inter area, * - candidate default, U - per-user static route
       o - ODR, P - periodic downloaded static route

Gateway of last resort is not set

     1.0.0.0/24 is subnetted, 1 subnets
D       1.1.1.0 [90/409600] via 10.1.12.1, 00:31:48, FastEthernet0/0
     5.0.0.0/24 is subnetted, 1 subnets
B       5.5.5.0 [200/409600] via 4.4.4.4, 00:02:34
     10.0.0.0/24 is subnetted, 3 subnets
C       10.1.12.0 is directly connected, FastEthernet0/0
B       10.1.45.0 [200/0] via 4.4.4.4, 00:31:48
D       10.1.215.0 [90/2195456] via 10.1.12.1, 00:31:21, FastEthernet0/0

R2#show ip eigrp vrf v topology
IP-EIGRP Topology Table for AS(1)/ID(10.1.12.2) <a href="http://www.realexam.net/tag/routing" class="st_tag internal_tag" rel="tag" title="Posts tagged with routing">Routing</a> Table: v

Codes: P - Passive, A - Active, U - Update, Q - Query, R - Reply,
       r - reply Status, s - sia Status

P 1.1.1.0/24, 1 successors, FD is 409600
        via 10.1.12.1 (409600/128256), FastEthernet0/0
P 5.5.5.0/24, 1 successors, FD is 409600
        via VPNv4 Sourced (409600/0)
P 10.1.12.0/24, 1 successors, FD is 281600
        via Connected, FastEthernet0/0
P 10.1.45.0/24, 1 successors, FD is 281600
        via VPNv4 Sourced (281600/0)
P 10.1.215.0/24, 1 successors, FD is 2195456
        via 10.1.12.1 (2195456/2169856), FastEthernet0/0
R2#</pre>
<p>Take a minute to post your thoughts, and as always, happy studies.</p>
<p>It has been a few days, and we have received lots of great ideas.   Thank you.</p>
<p>When R4 receives the routes in VRF v, the EIGRP metrics are copied into extended BGP attributes, and include the information for metric, AS, route-type and more.  The iBGP updates from R4 to R2 contain all those attributes.   When R2 receives the updates, if the route type is internal (from EIGRP attributes) and the source EIGRP AS matches the local EIGRP AS we are importing to, it will then be up to the  metric to determine the best path.</p>
<p>If we decreased the bandwidth statement on R4 Fa0/1, or used an offset list (2,000,000 more should do the trick) on R5 out Fa0/1 (towards R4), the increase in metric would cause R2 to prefer the path through R1 for 5.5.5.0/24 instead of using the MPLS backbone.</p>
<p>BGP updates that contain the cost community attribute will use the EIGRP AD instead of the iBGP AD of 200 to compare routes on metric alone. In that light, another option, would be to tell R2 to ignore cost-community, with the BGP router command:</p>
<p>bgp bestpath cost-community ignore</p>
<p>Let’s take a look at the results.</p>
<p>Here is the baseline for before any changes:</p>
<pre>R2#show ip route vrf v | inc 5.5.5
B       5.5.5.0 [200/409600] via 4.4.4.4, 00:02:29
R2#show ip bgp vpnv4 all 5.5.5.0
BGP <a href="http://www.realexam.net/tag/routing" class="st_tag internal_tag" rel="tag" title="Posts tagged with routing">routing</a> table entry for 1:1:5.5.5.0/24, version 8
Paths: (1 available, best #1, table v)
Flag: 0x820
  Not advertised to any peer
  Local
    4.4.4.4 (metric 21) from 4.4.4.4 (4.4.4.4)
      Origin incomplete, metric 409600, localpref 100, valid, internal, best
      Extended Community: RT:1:1 <strong>Cost:pre-bestpath:128:409600</strong> 0x8800:32768:0
        0x8801:1:153600 0x8802:65281:256000 0x8803:65281:1500
      mpls labels in/out nolabel/19
R2#</pre>
<p>Now we will remove the default behavior</p>
<pre>R2(config)#router bgp 234
R2(config-router)#bgp bestpath cost-community ignore</pre>
<p>Cleared BGP sessions and <a href="http://www.realexam.net/tag/routing" class="st_tag internal_tag" rel="tag" title="Posts tagged with routing">routing</a> tables, and waited a minute before the following show commands:</p>
<pre>R2#show ip route vrf v | inc 5.5.5
D       5.5.5.0 [90/2323456] via 10.1.12.1, 00:00:08, FastEthernet0/0
R2#show ip bgp vpnv4 all 5.5.5.0
BGP <a href="http://www.realexam.net/tag/routing" class="st_tag internal_tag" rel="tag" title="Posts tagged with routing">routing</a> table entry for 1:1:5.5.5.0/24, version 8
Paths: (2 available, best #2, table v)
Flag: 0x820
  Advertised to update-groups:
        1
  Local
    4.4.4.4 (metric 21) from 4.4.4.4 (4.4.4.4)
      Origin incomplete, metric 409600, localpref 100, valid, internal
      Extended Community: RT:1:1 Cost:pre-bestpath:128:409600 0x8800:32768:0
        0x8801:1:153600 0x8802:65281:256000 0x8803:65281:1500
      mpls labels in/out 20/19
  Local
    10.1.12.1 from 0.0.0.0 (2.2.2.2)
      Origin incomplete, metric 2323456, localpref 100, weight 32768, valid, sourced, best
      Extended Community: RT:1:1
        Cost:pre-bestpath:128:2323456 (default-2145160191) 0x8800:32768:0
        0x8801:1:665600 0x8802:65282:1657856 0x8803:65281:1500
      mpls labels in/out 20/nolabel
R2#</pre>
<p>After setting it back to defaults, we could then try an offset list on R5 advertising to R4:</p>
<pre>R5(config)#router eigrp 1
R5(config-router)#offset-list 0 out 2000000 fastEthernet 0/1</pre>
<p>Cleared BGP sessions and <a href="http://www.realexam.net/tag/routing" class="st_tag internal_tag" rel="tag" title="Posts tagged with routing">routing</a> tables, and waited a minute before the following show commands:</p>
<pre>R2#show ip route vrf v | inc 5.5.5
D       5.5.5.0 [90/2323456] via 10.1.12.1, 00:06:28, FastEthernet0/0
R2#show ip bgp vpnv4 all 5.5.5.0
BGP <a href="http://www.realexam.net/tag/routing" class="st_tag internal_tag" rel="tag" title="Posts tagged with routing">routing</a> table entry for 1:1:5.5.5.0/24, version 12
Paths: (1 available, best #1, table v)
Flag: 0x820
  Advertised to update-groups:
        1
  Local
    10.1.12.1 from 0.0.0.0 (2.2.2.2)
      Origin incomplete, metric 2323456, localpref 100, weight 32768, valid, sourced, best
      Extended Community: RT:1:1
        Cost:pre-bestpath:128:2323456 (default-2145160191) 0x8800:32768:0
        0x8801:1:665600 0x8802:65282:1657856 0x8803:65281:1500
      mpls labels in/out 31/nolabel
R2#</pre>
<p>After resetting all that, implementing the following on R4, and then clearing BGP and <a href="http://www.realexam.net/tag/routing" class="st_tag internal_tag" rel="tag" title="Posts tagged with routing">routing</a>, we issue the show commands again.</p>
<pre>R4(config)#int fa 0/1
R4(config-if)#bandwidth 100

R2#show ip route vrf v | inc 5.5.5
D       5.5.5.0 [90/2323456] via 10.1.12.1, 00:00:05, FastEthernet0/0
R2#show ip bgp vpnv4 all 5.5.5.0
BGP <a href="http://www.realexam.net/tag/routing" class="st_tag internal_tag" rel="tag" title="Posts tagged with routing">routing</a> table entry for 1:1:5.5.5.0/24, version 20
Paths: (1 available, best #1, table v)
Flag: 0x820
  Advertised to update-groups:
        1
  Local
    10.1.12.1 from 0.0.0.0 (2.2.2.2)
      Origin incomplete, metric 2323456, localpref 100, weight 32768, valid, sourced, best
      Extended Community: RT:1:1
        Cost:pre-bestpath:128:2323456 (default-2145160191) 0x8800:32768:0
        0x8801:1:665600 0x8802:65282:1657856 0x8803:65281:1500
      mpls labels in/out 23/nolabel
R2#
</pre>
<p>Thanks again to all who contributed. I encourage all RS candidates to <a href="http://www.realexam.net/tag/lab" class="st_tag internal_tag" rel="tag" title="Posts tagged with lab">lab</a> this up, as well as practice MPLS with OSPF at the CEs.</p>
<div style='clear:both'></div><img src="http://www.realexam.net/?ak_action=api_record_view&id=4688&type=feed" alt="" /><img src="http://feeds.feedburner.com/~r/certting/~4/P3f9P2EqjZ8" height="1" width="1"/><img src="http://feeds.feedburner.com/~r/certting/~4/1Ub2Wrcvsdw" height="1" width="1"/><img src="http://feeds.feedburner.com/~r/certting/~4/GKlE-Oqa54g" height="1" width="1"/>]]></content:encoded>
			<wfw:commentRss>http://www.realexam.net/mpls-and-eigrp-going-the-distance-admin-distance/4688.html/feed</wfw:commentRss>
		<slash:comments>0</slash:comments>
		<feedburner:origLink>http://www.realexam.net/mpls-and-eigrp-going-the-distance-admin-distance/4688.html</feedburner:origLink><feedburner:origLink>http://feedproxy.google.com/~r/certting/~3/P3f9P2EqjZ8/4688.html</feedburner:origLink><feedburner:origLink>http://feedproxy.google.com/~r/certting/~3/1Ub2Wrcvsdw/4688.html</feedburner:origLink></item>
	</channel>
</rss>
