19.07.2013 Views

CCNP TSHOOT 6.0 - Cisco Learning Home

CCNP TSHOOT 6.0 - Cisco Learning Home

CCNP TSHOOT 6.0 - Cisco Learning Home

SHOW MORE
SHOW LESS

Create successful ePaper yourself

Turn your PDF publications into a flip-book with our unique Google optimized e-Paper software.

<strong>CCNP</strong>v6 <strong>TSHOOT</strong><br />

Section 1—Trouble Tickets and Troubleshooting Logs<br />

Task 1: Trouble Ticket Lab 9-3 TT-A<br />

Step 1: Review trouble ticket Lab 9-3 TT-A.<br />

As a security measure, your company has decided to implement stateful packet inspection using a <strong>Cisco</strong> IOS<br />

firewall on edge router R1. The firewall will allow traffic from external hosts only if it is a response to a<br />

legitimate request from an internal host. The only exception is that Internet access to the internal SRV1 webbased<br />

application will be allowed. Internal users should be able to access the Internet (simulated by Lo1 on<br />

R2) using various protocols, such as ICMP, FTP, Telnet, DNS, and HTTP. The firewall implementation must<br />

work in conjunction with the dynamic NAT currently being employed on R1. In addition, internal network<br />

devices must be able to obtain the correct time from the ISP (R2).<br />

You colleague has configured the firewall and the necessary access lists on R1. However, users on the office<br />

VLAN cannot access Internet websites, and remote users on the Internet cannot access the web-based<br />

application on SRV1. Your colleague has asked for your help in diagnosing and solving the problem.<br />

Step 2: Load the device trouble ticket configuration files for TT-A.<br />

Using the procedure described in Lab 3-1, verify that the lab configuration files are present in flash. Load the<br />

proper configuration files as indicated in the Device Configuration File table.<br />

Note: The following device access methods are in effect after loading the configuration files:<br />

• Console access requires no username or password.<br />

• Telnet and SSH require username admin and password adminpa55.<br />

• The enable password is ciscoenpa55.<br />

Device Configuration File Table<br />

Device Name File to Load Notes<br />

ALS1 Lab93-ALS1-TT-A-Cfg.txt<br />

DLS1 Lab93-DLS1-TT-A-Cfg.txt<br />

DLS2 Lab93-DLS2-TT-A-Cfg.txt<br />

R1 Lab93-R1-TT-A-Cfg.txt<br />

R2 Lab93-R2-TT-A-Cfg.txt<br />

R3 Lab93-R3-TT-A-Cfg.txt<br />

SRV1 N/A Static IP: 10.1.50.1<br />

Default gateway: 10.1.50.254<br />

PC-B N/A DHCP<br />

PC-C N/A DHCP<br />

Step 3: Configure SRV1.<br />

Configure SRV1 with static IP address 10.1.50.1/24 and default gateway 10.1.50.254.<br />

Step 4: Release and renew the DHCP lease on PC-B.<br />

a. Ensure that PC-B is configured as a DHCP client in the OFFICE VLAN.<br />

b. After loading all TT-A device configuration files, issue the ipconfig /release and ipconfig<br />

/renew commands on PC-B.<br />

All contents are Copyright © 1992–2010 <strong>Cisco</strong> Systems, Inc. All rights reserved. This document is <strong>Cisco</strong> Public Information. Page 4 of 16

Hooray! Your file is uploaded and ready to be published.

Saved successfully!

Ooh no, something went wrong!