Index

Symbols

2-way state (neighbor relationships), 186, 628

3G wireless, 393

4G wireless, 393

802.1D STP, 58, 62

802.1Q, 20-21

headers, 500-501

trunking. See ROAS

802.1w RSTP

defined, 58

port roles, 60

port states, 62

802.11 headers, 501

A

aaa authentication login default command, 149

aaa new-model command, 149

AAA servers

authentication

configuration, 148-150

login authentication rules, 150

login process, 147

TACACS+/RADIUS protocols, 148

configuring for 802.1x, 145

defining, 149

enabling, 149

username/passwords, verifying, 145

aaS (as a Service), 742

ABR (Area Border Router), 190, 625

interface OSPF areas, verifying, 210-211

OSPFv2 multiarea configuration, 209-210

OSPFv3 multiarea configuration, 625

access

Internet, 389

cable Internet, 391

DSLs (digital subscriber lines), 390-391

fiber, 393

WANs, 389

wireless WANs, 392-393

IPv6 restrictions, 685

public cloud services

Internet, 745-746

private WANs, 746-749

VPNs, 747

securing with IEEE 802.1x, 144-146

AAA servers, configuring, 145

authentication process, 145

EAP, 146

switches as 802.1x authenticators, 145

username/password combinations, verifying, 145

access-class command, 486

access control lists. See ACLs

Access Control Server (ACS), 147

access interfaces, 24, 113-114

access layer switches, 156-157

access links

MetroE, 365

MPLS, 378

access-list command, 445, 457, 463-466, 486

building ACLs with, 454

examples and logic explanations, 467

extended numbered ACL configuration commands, 467

keywords

any, 448

deny, 448-449

log, 452

permit, 445, 448-449

tcp keyword, 464

upd keyword, 464

reverse engineering from ACL to address range, 454-456

ACI (Application Centric Infrastructure), 773-774

ACLs (access control lists), 586

ACL Analysis tool, 777-778

classification, 497

comparison of ACL types, 442-443

extended numbered ACLs

configuration, 467-470

matching protocol, source IP, and destination IP, 463-464

matching TCP and UDP port numbers, 464-467

overview, 462

GRE tunnel issues, 409-410

HSRP packets, blocking, 563

implementation considerations, 476-477

IPv4, 666-667

IPv6, 664-666

access-list commands, building, 678-679

access restrictions, 685

blocking, 683

capabilities, 669

extended, 674-678

filtering ICMPv6 NDP messages, 679-683

filtering policies, 668

ICMPv6 message filtering, 668-669

implicit filtering ICMPv6 NDP messages, 683-684

IPv4 ACL, compared, 666-667

limitations, 669-670

logging, 670

management control, 685

prefix lengths, 670

problems, 612

router originated packets, 670

standard, configuring, 671-674

testing, 677

tunneled traffic matching, 670

location and direction, 440-441

matching packets, 441-442

named ACLs

configuration, 472

editing, 473-475

overview, 471-472

numbered ACLs, 475-476

overview, 440

QoS tools, compared, 496

SNMP security, 698

standard numbered ACLs

access-list command, 454

command syntax, 445

configuration examples, 448-452

list logic, 444-445

matching any/all addresses, 448

matching exact IP address, 445-446

matching subset of address, 446-447

overview, 443

reverse engineering from ACL to address range, 454-456

troubleshooting, 452-453

verification, 452-453

wildcard masks, 446-448

troubleshooting, 477

ACL behavior in network, 477-479

ACL interactions with router-generated packets, 483-485

commands, 479-480

common syntax mistakes, 481

inbound ACL filters routing protocol packets, 481-482

reversed source/destination IP address, 480-481

ACL Analysis tool, 777-778

ACS (Access Control Server), 147

active HSRP routers, 558

address blocks. See prefixes

addresses

families, 619

global unicast, 593

IPv4, 197

IPv6

assigning to hosts, 595-597

connectivity, verifying, 600-603

multicast, 682

router configuration, 598-599

static route configuration, 599

unicast, 593-595

link, 311-312

link-local, 595

MAC, 49

public cloud assignment services, 756-757

source/destination, 406

unique local unicast, 593

adjacent neighbors, 186, 633

administrative distance, 177-178

administratively shutdown interfaces, 49

ADSL (asymmetric DSL), 391

advertising

BGP routes, 303-304

eBPG enterprise public prefixes, 307-308

subnets to ISPs, 318

AF (Assured Forwarding), 502-503

agents (SNMP), 695

Get/Set messages, 696

MIB, 697

NMS polling, 696

notifications, 696-697

algorithms

Dijkstra SPF, 180

DUAL (Diffusing Update Algorithm), 242-243, 646

IGP routing protocol algorithm, 175

SPF (Shortest Path First), 180, 186-188

STA (spanning-tree algorithm), 48

all IP addresses, matching, 448

alternate ports, 60-61, 91-92

Amazon Web Services (AWS), 742

American Registry for Internet Numbers (ARIN), 174

analyzers (network), 719

answering exam questions, 790-792

anti-replay (Internet VPNs), 394

any keyword, 448

any/all IP addresses, matching, 448

APIs (application programming interfaces), 768-769

APIC (Application Policy Infrastructure Controller), 774

APIC EM (APIC Enterprise Module), 774-776

ACL Analysis tool, 777

controller, 777

labs website, 777

Path Trace ACL Analysis tool, 777-778

Path Trace app, 777

Application Centric Infrastructure (ACI), 773-774

Application Policy Infrastructure Controller (APIC), 774

application signatures, 498

application-specific integrated circuit (ASIC), 765

architectures (SDN), 770

APIC Enterprise Module (APIC-EM), 774-776

controller, 777

labs website, 778

Path Trace ACL Analysis tool, 777-778

Path Trace app, 777

Application Centric Infrastructure (ACI), 773-774

comparisons, 776

Open SDN, 771

Open SDN Controller (OSC), 772

OpenDaylight (ODL), 771-772

OpenFlow, 771

Area Border Router. See ABR

area design (OSPF), 189-190

ABR, 190, 210-211

areas, 189-190

backbone areas, 190

multiarea on ABR configuration, 625

super, 381

backbone routers, 190

benefits, 191

interarea routes, 190

internal routers, 190

intra-area routes, 190

mismatches, finding, 290-291

MPLS VPNs, 381-382

network size, 189

problems, 188, 281

single-area, 188

SPF workload, reducing, 190

three-area, 189

ARIN (American Registry for Internet Numbers), 174

AS (autonomous system), 174, 304

as a Service (-aaS), 742

ASAv (virtual ASA firewall), 754

ASIC (application-specific integrated circuit), 765

ASNs (AS numbers), 174

BGP, 304

EIGRP, 248

for IPv6, 649

neighbors, 235, 288

Assured Forwarding (AF), 502-503

asymmetric DSL (ADSL), 391

attacks

DHCP-based, 152

types, 150

auth keyword (snmp-server group command), 707

authentication

802.1x, 145

AAA servers

configuration examples, 148-150

login authentication rules, 150

login process, 147

TACACS+/RADIUS protocols, 148

EIGRP neighbors, 235, 286

Internet VPNs, 393

PPP, 342-343

PPP CHAP, 356

PPP PAP, 356

SNMPv3, 699, 707-708

authentication ppp pap command, 346

authenticators, switches as, 145

auto-cost reference-bandwidth command, 222, 643

autonomous system (AS), 174, 304

auto-summary command, 267

defined, 270

EIGRP, 247

EIGRP for IPv4, 648

autosummarization, 266

classful network boundaries, 266-267

discontiguous classful networks, 267-268

AWS (Amazon Web Services), 742

B

backbone areas (OSPF), 190

multiarea on ABR configuration, 625

super, 381

backbone routers, 190

backup DRs (BDRs), 185, 211-212

backup port role (RSTP), 62-63

backup ports, 60, 91-92

bandwidth

EIGRP

for IPv6 routes, 650-651

metrics, 237-239, 265

routes, tuning, 259

interfaces

defaults, 216

higher, 217

OSPF costs based on, 216-217

least-bandwidth, 237

managing, 491

MetroE, 373-374

reference, 216-217

bandwidth command, 216, 359

defined, 222, 270

EIGRP, 247, 647

for IPv6, 662

metrics, 237, 265

OSPFv3 interface, 643

batch traffic, 493

BDRs (backup DRs), 185, 211-212

Bellman-Ford protocols. See DV protocols

best path selection (BGP), 305-306

BGP (Border Gateway Protocol), 174, 300, 303

AS, 304

ASNs, 304

best path selection, 305-306

configuring, 310

external. See eBGP

IGPs, compared, 302

internal (iBGP), 304

ISP default routes, learning, 320-321

neighbors, 303

disabling, 314

states, 313

prefixes, 303

reachability, 302

route advertising, 303-304

routing table analysis reports website, 303

table entries, injecting, 314

advertising subnets to ISPs, 318

classful network routes, 315-318

static discard routes, 319-320

update messages, 303-310

bgp commands, 311

BIDs (bridge IDs)

STP, 49

root switch election, 50-52

verification, 77

system ID extensions, 73-74

binary-to-hexadecimal conversion, 808

binary wildcard masks, 447

blocking state

interfaces, 47-49

RSTP ports, 92

Border Gateway Protocol. See BGP

BPDUs (bridge protocol data units), 49

BPDU Guard, 66

configuring, 81

enabling/disabling, 83

global settings, displaying, 83

verifying, 82-83

branch offices public cloud example, 749-752

email services traffic flow, 750-751

Internet connections, 751

private WAN connections, 751

bridge IDs. See BIDs

bridges. See switches

broadcast storms, 45-47

burned-in MAC addresses, 49

C

cable Internet, 391

cabling

DTE cables, 335

leased-line WANs, 332-333

stacking cables, 156

CAC (Call Admission Control) tools, 507

carrier Ethernet, 366

Catalyst switches RSTP modes, 88-90

Catalyst switches STP modes, 88-89

CBWFQ (Class-Based Weighted Fair Queuing), 505

CCENT/CCNA ICND1 100-105 Official Cert Guide, 272

CCNA ICND2 200-105 Official Cert Guide Premium Edition eBook and Practice Test, 792

CCNA ICND2 Config Labs website, 796

CCNA Routing and Switching ICND2 Official Cert Guide website, 777

CCNA R&S practice exam, 790

CE (customer edge), 377

centralized control planes, 766

CFN (Cisco Feature Navigator), 531

challenge messages, 342

channel-group command (EtherChannels), 84, 95, 543

incorrect options, troubleshooting, 106-108

Layer 3, troubleshooting, 541

channel service unit (CSU)/data service unit (DSU), 332-334

CHAP (Challenge-Handshake Authentication Protocol)

authentication, 342, 356

configuring, 344-345

verifying, 345-346

chassis aggregation, 159

benefits, 161

design, improving, 160

distribution/core switches high availability, 159-160

switch stacking, 159-161

CIR (committed information rate), 373, 509

Cisco

Access Control Server (ACS), 147

Application Centric Infrastructure (ACI), 773-774

BPDU Guard, 66

Catalyst switches RSTP modes, 88-90

Catalyst switches STP modes, 88-89

DevNet, 777

Feature Navigator (CFN), 531

Intercloud Fabric, 749

nondisclosure agreement (NDA), 788

Open SDN Controller (OSC), 772

Prime management products website, 695

server hardware, 732-733

Unified Communication Manager (CUCM), 35

virtual ASA firewall (ASAv), 754

Class-Based Weighted Fair Queuing (CBWFQ), 505

Class of Service (CoS) fields (802.1Q header), 500-501

Class Selector (CS), 503

classful networks

autosummarization at boundaries, 266-267

discontiguous, 267-268

routes, injecting, 315-318

classful routing protocols, 177, 266

classic mode (EIGRP configuration), 249

classification (QoS), 495

ACLs, 497

matching, 496-497

NBAR, 498

router queuing, 496

routers, 497

with marking, 497

classless routing protocols, 177

clear ip ospf process command, 204, 223

clear-text passwords, 698

CLI skills, 794-796

client VPNs, 396-397

clock rate commands, 349, 359

clocking, 332

cloud computing

address assignment services, 756-757

cloud services catalogs, 740

Cloud Services Routers (CSRs), 747

DHCP services, 757

Infrastructure as a Service (IaaS), 742

NTP, 757-758

Platform as a Service (PaaS), 743-744

private, 739-741

public, 741

accessing with Internet, 745-746

accessing with private VPNs, 747

accessing with private WANs, 746-749

branch offices example, 749-752

DNS services, 754-756

email services traffic flow, 750-751

intercloud exchanges, 748-749

Internet connections, 751

private WAN connections, 751

VNFs, 752-754

services, 739

Software as a Service (SaaS), 743

Cloud Services Routers (CSRs), 747

codecs, 493

commands

aaa authentication login default, 149

aaa new-model, 149

access-class, 486

access-list, 445, 457, 463-466, 486

any keyword, 448

building ACLs with, 454

deny keyword, 448-449

examples and logic explanations, 467

extended numbered ACL configuration commands, 467

log keyword, 452

permit keyword, 445, 448-449

reverse engineering from ACL to address range, 454-456

tcp keyword, 464

upd keyword, 464

authentication ppp pap, 346

auto-cost reference-bandwidth, 222, 643

auto-summary, 267, 270

EIGRP, 247

EIGRP for IPv4, 648

bandwidth, 216, 222, 270, 359

EIGRP, 247, 647

EIGRP for IPv6, 662

EIGRP metrics, 237, 265

OSPFv3 interface, 643

bgp, 311

channel-group (EtherChannels), 84, 95, 543

incorrect options, troubleshooting, 106-108

Layer 3, troubleshooting, 541

clear ip ospf process, 204, 223

clock rate, 349, 359

command, 222

configure terminal, 28

debug, 286

debug eigrp fsm, 271

debug eigrp packets, 286, 298

debug ip ospf adj, 298

mismatched OSPF areas, 290

OSPF neighbors, troubleshooting, 289

debug ip ospf events, 298

debug ip ospf hello, 298

Hello/dead timer mismatches, 293

OSPF neighbors, troubleshooting, 289

debug ip ospf packet, 298

debug ipv6 ospf adj, 632

debug ppp authentication, 356, 360

debug ppp negotiation, 360

debug spanning-tree events, 79, 96

default-information originate, 223, 321, 628

default-information originate always, 214

delay, 247, 270, 472-474

EIGRP, 647

EIGRP for IPv6, 662

EIGRP metrics, 237, 265

extended IPv6 ACLs, 675

IPv6 ACLs, 672

deny icmp any any, 683

description, 359

dialer pool, 417, 432

dns-server, 571

eigrp router-id, 246, 252

EIGRP, 647

EIGRP for IPv6, 662

encapsulation, 359, 525

encapsulation dot1q, 543

encapsulation ppp, 344, 350, 417, 432

erase startup-config, 135

frequency, 728

history buckets-kept 6, 728

history enhanced, 717

history enhanced interval, 728

history filter all, 728

history lives-kept 1, 728

hostname, 345

icmp-echo, 728

ifconfig, 568, 600, 615

interface, 25, 37, 543

interface dialer, 432

interface loopback, 196, 222

interface multilink, 360

interface multilink1, 350

interface port-channel, 543

interface range, 27

interface tunnel, 400, 432

interface vlan, 543

ip -6 neighbor show, 615

ip access-group, 450, 457, 467, 477, 486

ip access-list, 472, 486

ip access-list extended, 473

ip address, 568, 584-585

IP addresses on loopback interfaces, 196

MLPPP, 350

subinterfaces, 525

ip address negotiated, 418, 432

ip domain-lookup, 572

ip hello-interval eigrp, 247, 270, 297, 648

ip helper-address, 573-574

ip hold-time eigrp, 247, 270, 297

ip mtu, 296, 637

ip name-server, 572

ip ospf, 222

ip ospf cost, 222

ip ospf dead-interval, 297

ip ospf hello-interval, 297

ip route, 323

ip routing, 543

ip sla, 728

ip sla restart, 728

ip sla schedule, 715

ipconfig, 568, 600, 615

ipv6 access-list

building, 678-679

IPv6 ACLs, 687

ipv6 access-list deny, 678

ipv6 access-list permit, 678

ipv6 address, 598, 614

ipv6 dhcp relay destination, 614

ipv6 eigrp, 648, 662

ipv6 hello-interval eigrp, 662

ipv6 hold-time eigrp, 662

ipv6 mtu, 637

ipv6 ospf, 614, 624, 643

ipv6 ospf cost, 643

ipv6 router eigrp, 647, 662

ipv6 router ospf, 614, 624, 643

ipv6 traffic-filter, 673, 687

ipv6 unicast routing, 614

ipv6 unicast-routing, 598

mac-address, 432

maximum-paths, 218

defined, 222, 270

EIGRP, 247, 647

EIGRP for IPv6, 651, 662

EIGRP load balancing, 263

OSPFv3, 627, 643

monitor session, 721, 728

mtu, 432

name, 25, 40, 135

ndp -an, 615

neighbor, 322

neighbor shutdown, 314

netsh interface ipv6 show neighbors, 615

network

BGP, 323

BGP table entries, injecting, 314-320

EIGRP, 248, 270

EIGRP, enabling, 246

EIGRP for IPv4, 648

EIGRP for IPv6 compatibility, 647

OSPF single-area configuration, 198-200

OSPFv2 interface configuration, 218

OSPFv2 multiarea configuration, 209

no auto-summary, 268

no ip access-group, 476

no ip address, 539

no ip domain-lookup, 572

no ip sla schedule 1, 715

no neighbor shutdown, 314

no passive-interface, 223, 270

no shutdown, 40, 359

EIGRP for IPv6, 662

EIGRP for IPv6 routing, 650

Layer 1 leased-line WAN problems, 354

OSPF processes, 294

ROAS subinterfaces, 527

no spanning-tree portfast bpduguard default, 95

no spanning-tree portfast default, 95

no switchport

Layer 3 EtherChannels, 539

Layer 3 switches, 543

routed ports, 535

passive-interface, 205

defined, 222, 297

EIGRP, 270

EIGRP support, 251

OSPF interfaces as passive, configuring, 196

OSPFv3, 624

passive-interface default, 205, 270

permit, 471-474, 487

extended IPv6 ACLs, 675

GRE tunnel ACLs, 410

IPv6 ACLs, 672

permit gre, 432

permit icmp any any router-advertisement, 684

permit icmp any any router-solicitation, 684

permit ipv6, 687

ping, 483, 571-574, 615

IPv6 host connectivity, testing, 600

IPv6 routes, testing, 602, 614

leased-line WANs, 353

self-ping, 483-485

ping6, 615

IPv6 ACLs, 674

IPv6 connectivity, testing, 601

ppp authentication, 349, 359

ppp authentication chap, 345

ppp chap hostname, 432

ppp chap password, 432

ppp multilink, 350, 360

ppp multilink group, 360

ppp multilink group 1, 350

ppp pap sent-username, 346, 359

pppoe-client dial-pool-number, 417, 432

pppoe enable, 417, 432

remark, 472, 487

router bgp, 311

router eigrp, 246, 270, 647

router-id, 222, 614, 624

OSPFv3, 643

RIDs, defining, 196

router ospf, 196, 222

router ospf 1, 198

sdm prefer, 532

sdm prefer lanbase-routing, 543

show

IPv6 ACLs, 673

routing protocol-enabled interfaces, verifying, 275

STP status, 68

show access-list, 473

show access-lists, 450, 457, 479, 487, 687

show arp, 572

show controllers, 352

show controllers serial, 360

show etherchannel, 96, 543

show etherchannel 1 summary, 86

show etherchannel summary, 107, 540

show interfaces, 298, 360, 543, 569

EIGRP neighbor requirements, verifying, 286

MLPPP, 352

OSPF interfaces, troubleshooting, 283

OSPF neighbors, troubleshooting, 289

OSPFv3 interface bandwidth, 640

PPP CHAP status, 345

PPP PAP, 346

routed ports, 536

show interfaces description, 298, 576

show interfaces dialer, 421, 433

show interfaces PPP status, 344

show interfaces status

Layer 3 EtherChannels, 539

routed ports, 536

show interfaces switchport, 31-34, 37, 41, 114-116, 135

show interfaces trunk, 32-34, 38, 41, 116-117

show interfaces tunnel, 405, 433

show interfaces virtual-access, 433

show interfaces virtual-access configuration, 423

show interfaces vlan, 543

show ip access-list, 457, 474-476

show ip access-lists, 450, 479, 487

show ip bgp, 323

show ip bgp summary, 313, 323

show ip eigrp interfaces, 271, 297

EIGRP enabled interfaces, 250-251, 275

EIGRP neighbor requirements, verifying, 286

multilink interfaces, 352

show ip eigrp interfaces detail, 250, 271

show ip eigrp neighbors, 271, 297

neighbor status, displaying, 253

neighbor verification checks, 285

show ip eigrp topology, 259, 271

metrics, 262

successor routes, 258

topology table, 256

show ip eigrp topology all-links, 260

show ip interface, 450, 457, 479

show ip interface brief, 360

GRE tunnels, 404

multilink interfaces, 352

OSPF interfaces, troubleshooting, 283

show ip interfaces, 286

show ip ospf, 223, 298

duplicate OSPF RIDs, 291

OSPF neighbors, troubleshooting, 289

show ip ospf database, 179, 201, 223

show ip ospf interface, 223, 298

DRs/BDRs details, displaying, 211

Hello/dead timer mismatches, 293

OSPF areas for ABR interfaces, 210

OSPF neighbors, troubleshooting, 289

OSPFv2 interface configuration, 220

passive interface, 206

show ip ospf interface brief, 205, 223, 298

OSPF areas for ABR interfaces, 210

OSPF-enabled interfaces, identifying, 275

OSPF neighbors, troubleshooting, 289

OSPF status on interfaces, 281

OSPFv2 interface configuration, 221

show ip ospf neighbor, 182, 223, 298

DRs/BDRs details, displaying, 211

neighbors, listing, 288

OSPF processes shutdown, 295

show ip ospf neighbor interface brief, 295

show ip protocols, 223, 271, 297

EIGRP-enabled interfaces, 251-252, 275

EIGRP neighbor requirements, verifying, 286

EIGRP neighbor status, displaying, 253

IPv4 routing protocols, 202

OSPF configuration errors, 282-283

OSPFv2 interface configuration, 219

show ip route, 223, 271, 323, 577-580

administrative distance, 178

dialer interface Layer 3 orientation, 425

EIGRP-learned routes, displaying, 254

IPv4 routes added by OSPF, 201

routing tables, displaying, 543

show ip route eigrp, 254, 271, 297

show ip route ospf, 223, 298, 577-578

show ip route static, 214

show ip sla enhanced-history distribution-statistics, 729

show ip sla history, 717, 729

show ip sla statistics, 729

show ip sla summary, 729

show ipv6 access-list, 677, 687

show ipv6 eigrp interfaces, 654, 662

show ipv6 eigrp interfaces detail, 662

show ipv6 eigrp neighbors, 663

show ipv6 eigrp topology, 663

show ipv6 eigrp topology | section, 663

show ipv6 interface, 614, 687

show ipv6 neighbors, 614

IPv6 ACL ICMPv6 NDP message filtering, 681

IPv6 IPv4 replacement, 603

show ipv6 ospf, 640, 643

show ipv6 ospf database, 636, 643

show ipv6 ospf interface, 630-631, 643

show ipv6 ospf interface brief, 630, 640, 643

show ipv6 ospf neighbor, 635, 643

show ipv6 protocols, 614, 643

EIGRP for IPv6, 662

EIGRP for IPv6 interfaces, 654

OSPFv3 interfaces, 630

show ipv6 route, 614, 643

EIGRP for IPv6, 663

IPv6 router connectivity, 603

show ipv6 route eigrp, 663

show ipv6 route ospf, 638, 643

show ipv6 route | section, 663

show ipv6 routers, 614, 681

show mac address-table, 114

show mac address-table dynamic, 111

show monitor detail, 724, 729

show monitor session, 724, 729

show monitor session all, 723

show ppp all, 346-347, 360

show ppp multilink, 353, 360

show pppoe session, 424, 433

show running-config, 135, 449, 473-475

show snmp, 703, 729

show snmp community, 702, 728

show snmp contact, 728

show snmp group, 709, 729

show snmp host, 702, 729

show snmp location, 728

show snmp user, 708, 729

show spanning-tree, 96

show spanning-tree bridge, 81

show spanning-tree interface, 96

show spanning-tree interface detail, 82

show spanning-tree root, 77, 81

show spanning-tree summary, 83, 96

show spanning-tree vlan, 96

show spanning-tree vlan 10, 75-77

show spanning-tree vlan 10 bridge, 77

show spanning-tree vlan 10 interface gigabitethernet0/2 state, 92

show standby, 556, 560, 565

show standby brief, 555, 565

show tcp brief, 313

show tcp summary, 323

show vlan, 41, 114, 141

show vlan brief, 26-29, 114

show vlan id, 27, 114

show vlan status, 135

show vlans, 527, 543

show vtp password, 134, 141

show vtp status, 29, 41, 131, 134, 141

shutdown, 40, 359

EIGRP for IPv6, 662

EIGRP for IPv6 routing, 650

Layer 1 leased-line WAN problems, 354

OSPF processes, 294

ROAS subinterfaces, 527

shutdown vlan, 135, 140

snmp-server, 700

snmp-server community, 727

snmp-server contact, 727

snmp-server enable traps, 727

snmp-server group, 705

snmp-server host, 701, 710, 727

snmp-server location, 727

snmp-server user, 707

spanning-tree, 95

spanning-tree bpduguard disable, 95

spanning-tree bpduguard enable, 75, 81, 95

spanning-tree mode, 88, 95

spanning-tree mode mst, 72

spanning-tree mode pvst, 72

spanning-tree mode rapid-pvst, 72, 90

spanning-tree pathcost method long, 55

spanning-tree portfast, 75, 81, 95

spanning-tree portfast bpduguard, 95

spanning-tree portfast default, 83, 95

spanning-tree portfast disable, 83, 95

spanning-tree vlan, 74

spanning-tree vlan 10 port-priority 112, 103

speed, 576

standby, 554, 564

standby 1 preempt, 558

standby version, 559

standby version 1 | 2, 564

switchport

Layer 3 switches, 543

routed ports, 535

switchport access vlan, 25, 28-29, 37-38, 40, 113, 135

switchport mode, 30, 40

switchport mode access, 25, 28, 37-38, 139

switchport mode dynamic auto, 116

switchport mode dynamic desirable, 32

switchport mode trunk, 30, 116, 524

switchport nonegotiate, 34, 40, 116, 139

switchport trunk allowed vlan, 41, 117

switchport trunk encapsulation, 30, 40

switchport trunk native vlan, 40, 118

switchport voice vlan, 36-38, 41, 135

traceroute, 574

GRE tunnels, 406

IPv6 host connectivity, testing, 600

IPv6 network router problems, troubleshooting, 611

IPv6 router connectivity, testing, 602, 614

traceroute6, 615

tracert, 615

tunnel destination, 406-408, 432

tunnel mode gre ip, 404, 432

tunnel mode gre multipoint, 404

tunnel source, 406-407, 432

undebug all, 298

username, 345, 359

variance, 270

EIGRP, 247, 263, 647

EIGRP for IPv6, 651, 662

verification, 75

vlan, 25, 37, 40, 135

vlan 10, 122

vlan 200, 137

vtp, 134

vtp domain, 134, 140

vtp mode, 40, 134, 140

vtp mode off, 29, 135

vtp mode transparent, 29, 135

vtp password, 134, 140

vtp pruning, 134, 140

vtp version, 140

committed information rate (CIR), 373, 509

communities (SNMP), 698-699

Community-based SNMP Version 2 (SNMPv2c), 699

community strings (SNMP), 698

confidentiality (Internet VPNs), 393

Config Checklist app, 796

configure terminal command, 28

configuring

AAA servers, 148-150

AAA servers for 802.1x, 145

ACLs (access control lists)

extended numbered, 467-470

named, 472

numbered, 475-476

standard numbered, 448-452

BGP, 310

disabling eBGP neighbors, 314

eBGP neighbor verification, 312-313

eBGP neighbors using link addresses, 311-312

ISP default routes, learning, 320-321

table entries, injecting, 314-320

transporting messages with TCP, 310

update messages, 310

BPDU Guard, 81-83

DHCP snooping, 153-154

EIGRP, 246

ASNs, 248

checklist, 246

classful network numbers, 248

classic versus named mode, 249

sample internetwork, 247

verification. See verifying, EIGRP configuration

wildcard masks, 248-249

EIGRP for IPv6, 647

commands, 647

example, 648-649

load balancing, 651-652

route metrics, 650-651

timers, 652

EtherChannels, 84

dynamic, 86-87

manual, 84-86

GRE tunnels, 402-404

HDLC, 337-340

HSRP, 554, 560-561

ICMP-Echo operations, 714-715

IGPs, 310

interfaces as passive, 205

IPv6

addressing on routers, 598-599

extended ACLs, 674-676

hosts, 595-597

routing, 598

standard ACLs, 671-674

static routes, 599

ISL, 525

ISP routers, 419

Layer 3

EtherChannels, 537-539

switch routed ports, 535-537

switching with SVIs, 529-531

local SPAN, 721-724

MLPPP, 349-350

multiarea OSPFv2, 206-210

network commands, 209

single-area configurations, 207-208

subnets, 206

verifying, 210-212

OSPFv2 interfaces, 218-221

OSPFv3, 621

default routes, 627-628

load balancing, 627

multiarea example, 622

multiarea on ABR, 625

route selection metrics, setting, 626

single-area, 623-624

overlapping VLSM subnets, 584-585

PortFast, 81-83

PPP, 343-344

CHAP, 344-345

PAP, 346-347

PPPoE, 415-416

ISP router configuration example, 419

Layer 1, 416-417

Layer 2, 417-418

summary, 418-419

verification, 420-425

RIDs (OSPF), 203-204

ROAS, 524

native VLANs, 525-526

subinterface numbers, 525

subinterfaces, creating, 524-525

troubleshooting, 528-529

verifying, 526-527

single-area OSPFv2, 197-198

IPv4 addresses, 197

matching with network command, 198-200

multiarea configurations, 207-208

network command, 198

organization, 196-197

passive interfaces, 204-206

RIDs, 203-204

verifying, 200-202

wildcard masks, 199

SNMPv2

Get/Set messages, 699-701

Trap/Inform messages, 701-702

verifying, 702-704

SNMPv3, 704

authentication, 707-708

encryption, 707-708

groups, 705-707

notifications, 710-711

requirements, 704

summary, 711-712

users, 707

verifying, 708-709

STP, 71

modes, 72

options, 74-75

per-VLAN port costs, 74

port costs, 78-79

PVST+, 72-73

root election influence, 80-81

system ID extensions, 73-74

topology changes, influencing, 55

verification commands, 75

VLANs (virtual LANs), 24-25

data and voice VLANs, 36-38

full VLAN configuration example, 25-28

shorter VLAN configuration example, 28-29

trunking, 30-34

VTP

common rejections, troubleshooting, 137

default VTP settings, 129

example, 130-131

new VTP configuration settings, 130

planning, 129

steps, 129

storing configuration, 134-135

transparent mode, 135

congestion avoidance, 512

TCP windowing, 512-513

tools, 513-514

congestion management, 504

Low Latency Queuing (LLQ), 505-507

multiple queues, 504

output queuing, 504

prioritization, 505

round robin scheduling, 505

strategy, 507

connections (public cloud access)

branch offices, 751

Internet, 745-746

private WANs, 746-749

VPNs, 747

contiguous networks, 267

control planes

centralized, 766

distributed, 766

networking devices, 763-764

control protocols (CP), 341

controllers, 766

APIC-EM, 777

centralized control, 766-767

Northbound Interfaces (NBIs), 768-770

OpenDaylight SDN controller, 771

Southbound Interfaces (SBIs), 767-768

convergence

EIGRP, 239

DUAL process, 242-243

feasible successor routes, 260-261

successors, 241-242

routing protocols, 173

STP, 48, 105-106

converting

binary to hexadecimal, 808

decimal to binary, 805-807

hexadecimal to binary, 808

core switches, 159-160

CoS (Class of Service) fields (802.1Q header), 500-501

costs. See metrics

counters, 715-716

CP (control protocols), 341

CPE (customer premises equipment), 332

CS (Class Selector), 503

CS DSCP values, marking, 503

CSRs (Cloud Services Routers), 747

CSU/DSU (channel service unit/data service unit), 332-334

CUCM (Cisco Unified Communication Manager), 35

customer edge (CE), 377

D

data

application traffic, 492-493

EIGRP for IPv6 topology, 657-658

integrity, 393

usage (MetroE), 373

bandwidth used, charging for, 373-374

overages, controlling, 374-375

data centers (virtual)

networking, 735

physical networks, 736

vendors, 735

workflow, 737-738

data circuit-terminating equipment (DCE), 334

data plane

EtherChannel impact on MAC tables, 111-112

networking devices, 762-763

STP impact on MAC tables, 110

VLAN of incoming frames, 112-113

data terminal equipment (DTE), 334-335

databases

LSDB, 179

area design, 190

best routes, finding, 180

contents, displaying, 201

exchanging between neighbors, 183-186

LSAs relationship, 179

OSPFv3, 636

MIB, 695-697

OIDs, 697

variable numbering/names, 697

variables, monitoring, 696

views, 705

topology, 188

VLAN, 131-133

DCE (data circuit-terminating equipment), 334

Dead Interval timer, 184

dead timers, 293-294

debug command, 286

debug eigrp fsm command, 271

debug eigrp packets command, 286, 298

debug ip ospf adj command, 298

mismatched OSPF areas, 290

OSPF neighbors, troubleshooting, 289

debug ip ospf events command, 298

debug ip ospf hello command, 298

Hello/dead timer mismatches, 293

OSPF neighbors, troubleshooting, 289

debug ip ospf packet command, 298

debug ipv6 ospf adj command, 632

debug messages, 261

debug ppp authentication command, 356, 360

debug ppp negotiation command, 360

debug spanning-tree events command, 79, 96

decimal-to-binary conversion, 805-807

decimal wildcard masks, 446-447

default-information originate always command, 214

default-information originate command, 223, 321

OSPF default routes, 214

OSPFv3, 628

default routes, 627-628

default VLANs, 25

delay command, 270

EIGRP, 247, 647

EIGRP for IPv6, 662

EIGRP metrics, 237, 265

delays

EIGRP

IPv6 routes, 650-651

metrics, 237, 265

managing, 491

delivery headers, 400

deny command, 472-474, 487

extended IPv6 ACLs, 675

IPv6 ACLs, 672

deny icmp any any command, 683

deny keyword, 442, 448-449

dependencies (SPAN), 722

description command, 359

design

improving with chassis aggregation, 160

Internet edge, 306

MetroE Layer 3, 370

E-LAN service, 371-372

E-Line service, 370-371

E-Tree service, 372

MetroE physical, 365-366

MPLS Layer 3, 377

MPLS VPNs Layer 3, 379-382

OSPF area, 189

ABR, 190, 210-211

areas, 189-190

backbone areas, 190

backbone routers, 190

benefits, 191

interarea routes, 190

internal routers, 190

intra-area routes, 190

MPLS VPNs, 381-382

network size, 189

problems, 188, 281

single-area, 188

SPF workload, reducing, 190

three-area, 189

OSPFv3 multiarea, 622

designated ports. See DPs

designated routers. See DRs

destination addresses, 406

destination IP, matching, 463-464

destination ports (SPAN), 719

devices, networking, 762

control, centralizing, 766-767

control plane, 763-764

data plane, 762-763

management plane, 764

switch internal processing, 765-766

DevNet, 777

DHCP (Dynamic Host Control Protocol)

Binding Table, 153

DHCP Relay, 573

public cloud services, 757

snooping

configuration settings, 153

DHCP-based attacks, 152

DHCP Binding Table, 153

features, 151

ports as trusted, configuring, 153

rate limiting, 154

rules summary, 153

trusted/untrusted ports, 151-154

stateful, 608-609

troubleshooting, 573-574

DHCP-based attacks, 152

DHCPv6, 596

dialer interfaces

Layer 3 orientation, 425

PPPoE

configuration, 416-417

verifying, 421-422

dialer pool command, 417, 432

Differentiated Services Code Point. See DSCP

Diffusing Update Algorithm (DUAL), 242-243, 646

Digital Signal level 0 (DS0), 334

Digital Signal level 1 (DS1), 334

Digital Signal level 3 (DS3), 334

digital subscriber lines (DSLs), 390-391

Dijkstra SPF algorithm, 180

direction (ACLs), 440-441

disabling

BGP neighbors, 314

BPDU Guard, 83

DTP, 116

EIGRP for IPv6 routing, 650

PortFast, 83

ports, 60

VLANs, 114-115

VLAN trunking, 139

discard routes, 319

discarding state

interfaces, 47-49

RSTP, 61

discontiguous classful networks, 266-268

discontiguous networks, 267

discovery (EIGRP neighbors), 234

displaying

BPDU Guard global settings, 83

DRs/BDRs details, 211

EIGRP

enabled interfaces, 275

IPv4 routing table, 253-254

neighbor status, 253

topology table, 255-257

LSDB contents, 201

OSPF-enabled interfaces, 275

passive interfaces, 206

PortFast global settings, 83

TCP connections, 313

distance vector protocols. See DV protocols

distributed control planes, 766

distribution switches, chassis aggregation, 159-160

DMVPN (Dynamic Multipoint VPN), 411

multipoint GRE tunnels, 411

NHRP (Next Hop Resolution Protocol), 412-413

DNS (Domain Name System)

IPv6 network troubleshooting, 607-608

public cloud services, 754-756

troubleshooting, 571-572

dns-server command, 571

down status (interfaces), 354

DP (designated port), LAN segments, 49, 60

choosing, 54, 104-105

problems, troubleshooting, 105

DR (designated router), 185

backup (BDRs), 185

discovering, 211-212

Ethernet links, 185-186

DROthers routers, 186

DS0 (Digital Signal level 0), 334

DS1 (Digital Signal level 1), 334

DS3 (Digital Signal level 3), 334

DSCP (Differentiated Services Code Point), 497

fields (QoS marking), 501

marking values

AF, 502-503

CS, 503

EF, 502

DSL (digital subscriber line), 390-391

DSLAMs (DSL access multiplexers), 390

DTE (data terminal equipment), 334-335

DTP (Dynamic Trunking Protocol), 116

DUAL (Diffusing Update Algorithm), 242-243, 646

dual Internet edge design, 306

dual stack

OSPFv2/OSPFv3, 619

OSPFv3 address families, 620

strategies, 598

DV (distance vector) protocols, 175, 228

distance/vector information learned, 228

EIGRP as, 232-233

route poisoning, 231-232

split horizon, 230-231

update messages, 229-230

dynamic EtherChannels configuration, 86-87

Dynamic Host Control Protocol. See DHCP

Dynamic Multipoint VPN. See DMVPN

Dynamic Trunking Protocol (DTP), 116

E

E1, 334

E3, 334

EAP (Extensible Authentication Protocol), 146

EAPoL (EAP over LAN), 146

earplugs (exam), 786

eBGP (External BGP), 304

Internet edge, 306

design, 306

enterprise public prefixes, advertising, 307-308

ISP default routes, learning, 309

neighbors

configuring, 312

disabling, 314

using link addresses, configuring, 311

verifying, 312-313

Eclipse IDE, 744

edge ports, 63

EF (Expedited Forwarding), 501

EF DSCP value marking, 502

EF RFC (RFC 3246), 502

EGP (exterior gateway protocol), 173, 302

EIGRP (Enhanced Interior Gateway Routing Protocol), 175

EIGRP for IPv4

as advanced DV protocol, 232-233

authentication, 286

autosummarization, 266

classful network boundaries, 266-267

discontiguous classful networks, 267-268

benefits, 227

configuration, 246

ASNs, 248

checklist, 246

classful network numbers, 248

classic versus named mode, 249

sample internetwork, 247

wildcard masks, 248-249

convergence, 239

DUAL process, 242-243

feasible successor routes, 260-261

successors, 241-242

disadvantages, 227

EIGRP for IPv6, compared, 644-646, 653

feasible successor routes

convergence, 260-261

identifying, 258-260

goals, 302

interfaces

configuration problems, 278-281

identifying, 275

OSPF interfaces, compared, 281

troubleshooting, 275-281

K-values, 286

metrics, 236

bandwidth, 265

calculation, 236-237

components, 262

delay settings, 265

EIGRP topology database, 262

example, 237-238

FD (feasible distance), 240-241

RD (reported distance), 240-241

route load balancing, 264

serial link bandwidth, 238-239

MPLS VPN challenges, 382

neighbors, 234-235

discovery, 234

requirements, 284-286

status, 233, 253

topology information, exchanging, 235-236

troubleshooting example, 286-288

verifying, 235, 285-286

OSPF, compared, 224

query/reply messages, 242

RIDs, configuring, 252

RIP metrics, compared, 176

RIPv2/OSPFv2, compared, 233

routes

choosing, 234

load balancing, 263-264

tuning with bandwidth changes, 259

variance, 263-264

successor routes, identifying, 257-258

topology

database metrics, 262

exchange, 234

table, displaying, 255-257

variance, 263-264

verification, 249

EIGRP enabled interfaces, finding, 250-252

IPv4 routing table, displaying, 253-254

neighbor status, displaying, 253

EIGRP for IPv6

configuration, 647

commands, 647

example, 648-649

load balancing, 651-652

route metrics, 650-651

timers, 652

DUAL, 646

EIGRP for IPv4, compared, 644-646, 653

FS, 646

interfaces, 654-655

neighbors, 656-657

routes

ASNs, 649

enabling/disabling, 650

FS, 646

successors, 646

troubleshooting, 660

verifying, 659-660

topology data, 657-658

eigrp router-id command, 246, 252, 647, 662

E-LAN (Ethernet LAN) service, 368-372

E-Line (Ethernet Line) service, 367-371

email, 750-751

enabling

AAA servers, 149

BPDU Guard, 83

EIGRP, 246

EIGRP for IPv6 routing, 650

IPv6 routing, 598

OSPF configuration mode, 198

PortFast, 83

PPPoE, 417

VLANs, 115

Encapsulated RSPAN (ERSPAN), 721

encapsulation command, 359, 525

encapsulation dot1q command, 543

encapsulation ppp command, 344, 350, 417, 432

encryption

IPsec, 395-396

keys, 395

SNMPv3, 699, 707-708

tunnel VPNs, 395

End-to-End QoS Network Design, Second Edition (Cisco Press), 494

end-user traffic, measuring, 713

endpoints, 773

enhanced history, 717

Enhanced Interior Gateway Routing Protocol (EIGRP), 175. See also EIGRP for IPv4; EIGRP for IPv6

Enterprise QoS Solution Reference Network Design Guide, 494

enterprises, classification matching, 496-497

eq 21 parameters, 465

erase startup-config command, 135

ERSPAN (Encapsulated RSPAN), 721

EtherChannels, 64-65

configuring, 84

dynamic, 86-87

manual, 84-86

Layer 3

configuring, 537-539

troubleshooting, 541

verifying, 539-540

MAC tables impact, predicting, 111-112

troubleshooting, 106

configuration checks before adding interfaces, 108-109

incorrect options, 106-108

Ethernet

802.1Q headers, 500-501

802.11 headers, 501

access links, 365

carrier, 366

IEEE standards, 366

links, 185-186

WANs, 747

Ethernet LANs

service, 368-372

troubleshooting, 575-576

VLANs (virtual LANs)

configuration, 24-29

default VLANs, 25

IDs, 18

IP telephony, 34-39

native VLANs, 20

overview, 16-18

routing between, 21-24

tagging, 18-20

trunking, 18-21, 29-34

Ethernet Line (E-Line) service, 367-371

E-Tree (Ethernet Tree) service, 369, 372

ETSI (European Telco standards body), 754

EUI-64 rules, 597-599

EVC (Ethernet Virtual Connection), 367

exact IP address matching, 445-446

exam

CLI skills, 794-796

earplugs, 786

exam-day suggestions, 787

knowledge gaps, finding, 792-793

practice exams

answering questions, 790-791

CCNA R&S, 790

checklist, 790

ICND2, 790

other, 792

taking, 789-790

pre-exam suggestions, 786-787

preparing for failure, 788

question types, 784

ready to pass assessment, 797

scores, 796-797

study tasks, 798

studying after failing to pass, 797-798

time budget versus number of questions, 785

time-check method, 786

tutorial, 784-785

Expedited Forwarding (EF), 501

extended IPv6 ACLs

configuring, 674-676

examples, 676-678

extended numbered IPv4 ACLs, 462

configuration, 467-470

matching protocol, source IP, and destination IP, 463-464

matching TCP and UDP port numbers, 464-467

Extensible Authentication Protocol (EAP), 146

exterior gateway protocol (EGP), 173, 302

external BGP. See eBGP

F

Facebook (Wendell Odom), 799

failed interfaces, 49

failing the exam, 788, 797-798

failures

CHAP authentication, 356

HSRP, 552

keepalive, 355

PAP authentication, 356

FCS (Frame Check Sequence), 336

FD (feasible distance), 240-241, 256

feasibility conditions, 242, 260

feasible successor (FS), 646

feasible successor routes, 241-242

convergence, 260-261

identifying, 258-260

FHRP (First Hop Redundancy Protocol), 544

features, 550

HSRP, 551

active/passive model, 551

active/standby routers, choosing, 555

active/standby rules, 557

configuring, 554

failover, 552

group numbers, 555

load balancing, 553

no preemption, 557

with preemption, 558

troubleshooting, 560-563

verifying, 555-556

versions, 559-560

need for, 549

options, 550-551

fiber Internet, 393

FIFO (first-in, first-out), 504

filtering

ICMPv6 messages, 668-669, 679-683

IPv6

ACL policies, 668

issues, 604

finding

EIGRP

enabled interfaces, 250-252

feasible successor routes, 258-260

successor routes, 257-258

mismatched Hello/dead timers, 293

OSPF area mismatches, 290-291

routers best routes, 180

wildcard masks, 448

firewalls, 754

First Hop Redundancy Protocol. See FHRP

first-in, first-out (FIFO), 504

FlexStack, 158

FlexStack-Plus, 158

flooding, 179

flow

networking, 493

public cloud traffic, 750-751

Forward delay timer (STP), 56

forwarding

data. See routing

interface state, 47-49

paths, 777-778

forwarding plane. See data plane

Fractional T1, 334

Fractional T3, 334

Frame Check Sequence (FCS), 336

Frame Relay, 362

frames

broadcast storms, 45-47

defined, 495

HDLC, 336

incoming, 112-113

looping, preventing, 44

multiple frame transmissions, 47

PPP, 341

switching, 113

frequency command, 728

FS (feasible successor), 646

full drops, 514

full mesh topology (MetroE), 368

full neighbor state, 186, 628

full updates, 229, 235

full VLAN configuration example, 25-28

fully adjacent neighbors, 186, 633

G

generic routing encapsulation (GRE), 398

“Get IEEE 802” program, 59

Get messages

agent information, 696

RO/RW communities, 699

SNMPv2 support, 699-701

GLBP (Gateway Load Balancing Protocol), 544

global unicast addresses, 593

Google App Engine PaaS, 744

GRE (generic routing encapsulation), 398

GRE tunnels, 398

between routers, 399

configuring, 402-404

details, displaying, 404

functionality, testing, 406

large scale environments, 411

multipoint with DMVPN, 411

point-to-point, 399

routes, 405

troubleshooting, 406

ACLs, 409-410

interface state, 407

Layer 3 issues, 409

source/destination addresses, 406

tunnel destination, 408

tunnel interfaces, 398

unsecured networks, 400-401

verifying, 404-406

group numbers (HSRP), 555

groups

endpoint, 773

SNMPv3, 705-707

MIB views, 705

security levels, 705

write views, 706

H

HDLC (High-level Data Link Control), 331, 336-340, 398

headers

802.1Q, 500-501

802.11, 501

delivery, 400

IP, 499-501

MPLS Label, 501

Hello BPDU, 49

Hello Interval, 184, 233

Hello messages (OSPF), 181-182

Hello timer

dead timer mismatches, troubleshooting, 293-294

STP, 56

hexadecimal-to-binary conversion, 808

high availability, 159-160

High-level Data Link Control (HDLC), 331, 336-340, 398

High-speed WICs (HWICs), 332

historical success/failure counters (IP SLAs), 716

history

IP SLA data, 717

OSPF, 619

SNMP, 695

history buckets-kept 6 command, 728

history enhanced command, 717

history enhanced interval command, 728

history filter all command, 728

history lives-kept 1 command, 728

Hold Interval, 233

hostname command, 345

hosts

IPv6, 595

connectivity, verifying, 600-601

issues, 604

missing settings, 608-610

name resolution problems, 607-608

pings fail from default router, 606-607

pings only working in some cases, 605-606

stateful DHCPv6, 596

stateless address autoconfiguration (SLAAC), 597

routes, 357

server virtualization, 734

troubleshooting IPv4 settings

default router IP address setting, 572

DNS problems, 571-572

ensuring IPv4 settings match, 568-569

mismatched masks, 569-571

HSRP (Hot Standby Router Protocol), 544, 551

active/passive model, 551

active/standby routers, choosing, 555

active/standby rules, 557

configuring, 554

failover, 552

group numbers, 555

load balancing, 553

no preemption, 557

with preemption, 558

troubleshooting, 560

ACL blocks HSRP packets, 563

configuration, 560-561

group number mismatches, 563

misconfiguration symptoms, 561

routers configuring different VIPs, 563

version mismatches, 562

verifying, 555-556

versions, 559-560

HSRPv2 (HSRP version 2), 559

hub and spoke topology (MetroE), 369

Huston, Geoff website, 303

HWICs (High-speed WICs), 332

hypervisors, 734

I

IaaS (Infrastructure as a Service), 742

IANA (Internet Assigned Numbers Authority), 174

ASNs, assigning, 174

ICMPv6 parameters, 669

IPv6 multicast address space registry website, 682

website, 174

iBGP (Internal BGP), 304

icmp-echo command, 728

ICMP-Echo operations, 714-715

ICMP Echo probe, 713

icmp keyword, 481

ICMPv6

Echo Request messages, 674

messages, filtering, 668-684

packets, matching, 675

ICND2 practice exam. See practice exams

IEEE (Institute of Electrical and Electronics Engineers)

802.1D Spanning-Tree states, 58

802.1D standard, 58

802.1w amendment, 58

802.1x

access, securing, 144-145

authenticators, 145

LAN access, securing, 145-146

default port costs, 55

Ethernet standards, 366

“Get IEEE 802” program, 59

ifconfig command, 568, 600, 615

IGP (interior gateway protocol), 173, 226

BGPs, compared, 302

classless/classful, 177

configuring, 310

goals, 302

metrics, 175-176

routing protocol algorithm, 175

subnets, 303

IGRP (Interior Gateway Routing Protocol), 175

implicit filtering, 683-684

incoming frames, 112-113

inferior Hello, 50

infinity, 231

Inform messages, 696-697

SNMPv2, 701-702

SNMPv3, 710-711

Infrastructure as a Service (IaaS), 742

injecting BGP table entries, 314

advertising subnets to ISPs, 318

classful network routes, 315-318

static discard routes, 319-320

instantiating VMs, 742

Institute of Electrical and Electronics Engineers. See IEEE

Integrated Intermediate System to Intermediate System (IS-IS), 175

interactive data application traffic, 492

interactive voice traffic, 494

interarea routes, 190, 212, 640

intercloud exchanges, 748-749

Intercloud Fabric, 749

interface command, 25, 37, 543

interface dialer command, 432

interface loopback command, 196, 222

interface multilink command, 360

interface multilink 1 command, 350

interface port-channel command, 543

interface range command, 27

interface tunnel command, 400, 432

interface vlan command, 543

interfaces

ABR OSPF areas, verifying, 210-211

access, 113-114

administratively shutdown, 49

application programming (APIs), 768-769

bandwidth

defaults, 216

EIGRP metric calculations, 265

EIGRP routes, tuning, 259

higher reference, 217

OSPF costs based on, 216-217

blocking state, 47

delays, 265

dialer

Layer 3 orientation, 425

PPPoE, 416-417, 421-422

down status, 354

EIGRP

configuration problems, 278-281

enabled, finding, 250-252, 275

OSPF interfaces, compared, 281

troubleshooting, 275-281

EIGRP for IPv6, 654-655

EtherChannels, adding, 108-109

failed, 49

forwarding state, 47

LAN speeds, 490

learning state, 58

listening state, 58

loopback, 203

multilink, 349

Northbound (NBIs), 768-770

OSPF

bandwidth, 216

costs, setting, 216-217

EIGRP interfaces, compared, 281

identifying, 275

passive, 196

troubleshooting, 281-283

OSPFv2 configuration, 218

example, 218

verifying, 219-221

OSPFv3, 630

influence route selections, setting, 626

troubleshooting, 631-632

verifying, 630-631, 638-640

passive

EIGRP, 251

OSPF, 204-206

OSFPv3, 624

per-VLAN STP costs, 74

routed, 535-537

routing protocol-enabled, verifying, 274

Southbound (SBIs), 767-768

states

changing with STP, 57-58

forwarding or blocking criteria, 48-49

status codes, 353

subinterfaces, 524-527

switched virtual. See SVIs

tunnel

ACLs, 409-410

creating, 400

destinations, 408

Layer 3 issues, 409

replacing serial links, 398

state, 407

virtual-access, 423

VLAN. See SVIs

WANs, 490

working, 49

interior gateway protocol. See IGP

Interior Gateway Routing Protocol (IGRP), 175

interior IP routing protocols, 233

internal BGP (iBGP), 304

internal processing (switches), 765-766

internal routers, 190, 623-624

Internet

access, 389

cable Internet, 391

DSLs (digital subscriber lines), 390-391

fiber, 393

WANs, 389

wireless WANs, 392-393

edge, eBGP and, 306

design, 306

enterprise public prefixes, advertising, 307-308

ISP default routes, learning, 309

public cloud

accessing, 745-746

computing branch office connections, 751

VPNs, 389

benefits, 394

clients, 396-397

security, 393

site-to-site, 395-396

as WAN service, 389

wireless, 393

Internet Assigned Numbers Authority. See IANA

Internet service providers. See ISPs

Inter-Switch Link (ISL), 20-21, 525

intra-area routes, 190

ip -6 neighbor show command, 615

ip access-group command, 450, 457, 467, 477, 486

ip access-list command, 472, 486

ip access-list extended command, 473

IP ACLs (access control lists). See ACLs

ip address command, 568, 584-585

IP addresses on loopback interfaces, 196

MLPPP, 350

subinterfaces, 525

ip address negotiated command, 418, 432

ip_address parameter (network command), 198

IP addressing

conversions

binary-to-hexadecimal, 808

decimal-to-binary, 805-807

hexadecimal-to-binary, 808

public clouds

address assignment services, 756-757

DHCP services, 757

ip domain-lookup command, 572

IP headers, 499-501

ip hello-interval eigrp command, 247, 270, 297, 648

ip helper-address command, 573-574

ip hold-time eigrp command, 247, 270, 297

IP IGP metrics, 175-176

ip mtu command, 296, 637

ip name-server command, 572

ip ospf command, 222

ip ospf cost command, 222

ip ospf dead-interval command, 297

ip ospf hello-interval command, 297

ip route command, 323

ip routing command, 543

ip sla command, 728

ip sla restart command, 728

IP SLAs (IP Service Level Agreements), 712

historical success/failure counters, 716

history data, troubleshooting with, 717

ICMP-Echo, 713-715

operations, 713

responders, 713

sources, 713

troubleshooting with

counters, 715-716

history data, 717

UDP Jitter probes, 713

ip sla schedule command, 715

IP telephony (VLANs), 34

data and voice VLAN concepts, 34-36

data and voice VLAN configuration and verification, 36-38

summary, 38-39

ipconfig command, 568, 600, 615

IPP (IP Precedence) fields (QoS marking), 501-503

IPsec, 395-396

IPv4 routing

ACLs, 666-667

addresses, 197, 619

EIGRP

configuration, 248-249

load balancing, 263-264

verifying, 253-254

EIGRP verification, 249

EIGRP enabled interfaces, finding, 250-252

IPv4 routing table, displaying, 253-254

neighbor status, displaying, 253

Layer 3 EtherChannels

configuring, 537-539

troubleshooting, 541

verifying, 539-540

Layer 3 switch routed ports, 534-537

Layer 3 switching with SVIs

configuring, 529-531

troubleshooting, 532-534

verifying, 531

matching addresses

any/all addresses, 448

exact IP address, 445-446

subset of address, 446-447

OSPF added, 201

QoS marking, 499

routing protocols

displaying, 202

troubleshooting, 273-274

subnet masks

mismatched masks, 569-571

VLSM (variable length subnet masking), 581

troubleshooting, 572

default router IP address setting, 572

DHCP issues, 573-574

DNS problems, 571-572

incorrect addressing plans, 581-585

IP forwarding issues, 577-580

LAN issues, 575-576

mismatched IPv4 settings, 568-569

mismatched masks, 569-571

packet filtering with access lists, 586

router WAN interface status, 585

ipv6 access-list commands

building, 678-679

IPv6 ACLs, 687

ipv6 access-list deny command, 678

ipv6 access-list permit command, 678

ipv6 address command, 598, 614

ipv6 dhcp relay destination command, 614

ipv6 eigrp command, 648, 662

ipv6 hello-interval eigrp command, 662

ipv6 hold-time eigrp command, 662

ipv6 mtu command, 637

ipv6 ospf command, 614, 624, 643

ipv6 ospf cost command, 643

ipv6 router eigrp command, 647, 662

ipv6 router ospf command, 614, 624, 643

IPv6 routing

access restrictions with IPv6 ACLs, 685

ACLs, 664-666

access-list commands, building, 678-679

access restrictions, 685

blocking, 683

capabilities, 669

extended, 674-678

filtering ICMPv6 NDP messages, 679-683

filtering policies, 668

ICMPv6 message filtering, 668-669

implicit filtering ICMPv6 NDP messages, 683-684

IPv4 ACL, compared, 666-667

limitations, 669-670

logging, 670

management control, 685

prefix lengths, 670

problems, 612

router originated packets, 670

standard, configuring, 671-674

testing, 677

tunneled traffic matching, 670

addressing on routers configuration, 598-599

connectivity, verifying, 600-601

hosts, 600-601

routers, 601-603

EIGRP

ASNs, 649

configuration, 647-649

DUAL, 646

EIGRP for IPv4, compared, 644-646, 653

FS, 646

interfaces, 654-655

load balancing, 651-652

neighbors, 656-657

routes, 650-651, 659-660

successors, 646

timers, 652

topology data, 657-658

global unicast addresses, 593

host configuration, 595

stateful DHCPv6, 596

stateless address autoconfiguration (SLAAC), 597

link-local addresses, 595

multicast addresses, 682

OSPF, 619-620

OSPFv3

configuration, 621-622

default routes, 627-628

interface cost metrics, 638-640

interfaces, 630

IPv6 MTU mismatches, 636-638

IPv6 routes, troubleshooting, 640-641

load balancing, 627

LSAs, 636

LSDBs, 636

multiarea on ABR configuration, 625

neighbors, 632

OSPFv2, compared, 621, 628-629

passive interfaces, 624

RIDs, 624

route selection metrics, 626

single-area configuration, 623-624

troubleshooting interfaces, 631-632

troubleshooting neighbors, 633-635

verifying interfaces, 630-631

verifying neighbors, 632-633

protocols, 619

QoS marking, 500

routers, enabling, 598

routes

EIGRP for IPv6 metrics, 650-651

OSPFv3 metrics, 626, 638-640

troubleshooting, 640-641

subnetting, 593

unique local unicast addresses, 593

static route configuration, 599

subnetting, 593-594

troubleshooting, 604

ACLs, 612

filtering issues, 604

host issues, 604

host pings fail from default router, 606-607

host pings only working in some cases, 605-606

missing IPv6 settings in host, 608-610

name resolution problems, 607-608

router issues, 604

routing, 611-612

unicast addresses, 593-595

ipv6 traffic-filter command, 673, 687

ipv6 unicast routing command, 598, 614

IS-IS (Integrated Intermediate System to Intermediate System), 175

ISL (Inter-Switch Link), 20-21, 525

ISPs (Internet service providers), 389

default routes, learning, 320-321

dial connections with PPP, 414

Internet edge, learning, 309

router configuration example, 419

subnets, advertising, 318

J

Jenkins continuous integration and automation tool, 744

jitter, managing, 491

K

keepalive failures, 355

keyboard, video display, or mouse (KVM), 733

keys (encryption), 395

keywords. See also commands

any, 448

deny, 442, 448-449

icmp, 481

log, 452, 670

permit, 442, 448-449

tcp, 464

udp, 464

knowledge gaps, finding, 792-793

K-values (EIGRP), 286

KVM (keyboard, video display, or mouse), 733

L

labs, completing, 795-796

LACP (Link Aggregation Control Protocol), 86

LANs, 523

defined, 16

DPs, 54, 104-105

interfaces, 490

redundancy

problems caused without STP, 45-46

STP, 42

security

IEEE 802.1x, 144-146

STP security exposures, 65-66

troubleshooting, 575-576

VLAN support, adding, 122

Layer 1

leased-line WANs

CSU/DSUs, 334

physical components, 332-333

speeds, 333-334

troubleshooting, 354

leased-line WANs with HDLC, 335-336

PPPoE

configuration, 416-417

switches, 21

troubleshooting, 427-428

Layer 2

leased-line WANs, 354-356

leased-lines with HDLC, 336

MLPPP, 349

PPPoE

configuration, 417

troubleshooting, 428-429

Layer 3

GRE tunnel issues, 409

leased-line WANs, troubleshooting, 357-358

MetroE design, 370

E-LAN service, 371-372

E-Line service, 370-371

E-Tree service, 372

MLPPP, 348-349

MPLS, 377

MPLS VPNs, 379-380

EIGRP challenges, 382

OSPF area design, 381-382

PPPoE

configuration, 417-418

status, verifying, 425

troubleshooting, 429

switches, 21

EtherChannels, 537-541

routed ports, 534-537

with SVIs, 529-534

VLAN (virtual LAN) routing, 23-24

LCP (Link Control Protocol), 341-342

learning state (interfaces), 58

leased-line WANs, 330-331

building, 335-336

CSU/DSU, 334

with HDLC, 336

configuring HDLC, 337-340

de-encapsulating/re-encapsulating IP packets, 336

framing, 336

physical components, 332-333

with PPP

authentication, 342-343

configuring PPP, 343-344

configuring PPP CHAP, 344-346

configuring PPP PAP, 346-347

control protocols, 341

framing, 341

multilink. See MLPPP

PPP functions, 340

speeds, 333-334

troubleshooting, 353-354

Layer 1 problems, 354

Layer 2 problems, 354-356

Layer 3 problems, 357-358

mismatched subnets, 358

least-bandwidth, 237

limiting SPAN sources, 725

Link Aggregation Control Protocol (LACP), 86

Link Control Protocol (LCP), 341-342

link-local addresses, 595

link-state advertisements. See LSAs

link-state database. See LSDB

link-state protocols, 175. See also OSPF

Link-State Update (LSU) packets, 183

links

access

MetroE, 365

MPLS, 378

addresses, 311-312

Ethernet, 185-186

RSTP types, 63

serial

bandwidth, 238-239

replacing with IP tunnels, 398

routing IP packets over, 398

list logic (IP ACLs), 444-445

listening state (interfaces), 58

LLQ (Low Latency Queuing), 505-507

load balancing

EIGRP, 263-264, 651-652

HSRP, 553

MLPPP, 349

OSPF, 217

OSPFv3, 627

local SPAN, configuring, 721-724

location (ACLs), 440-441

log keyword, 452, 670

log messages, unsolicited, 283

logging IPv6 ACLs, 670

logical switches, 157-158

logins (AAA), 147, 150

Long-Term Evolution (LTE), 393

loopback interfaces, 203

looping frames, preventing, 44

loss, managing, 491

Low Latency Queuing (LLQ), 505-507

LSAs (link-state advertisements), 183

exchanging with OSPF neighbors, 183-184

DRs on Ethernet links, 185-186

maintenance, 184-185

flooding, 179

LSDB relationship, 179

OSPFv3, 636

router, 636

LSDB (link-state database), 179

area design, 190

best routes, finding, 180

contents, displaying, 201

exchanging between neighbors

DRs on Ethernet links, 185-186

fully exchanging LSAs, 183-184

maintaining neighbors, 184-185

LSAs relationship, 179

OSPFv3, 636

LSU (Link-State Update) packets, 183

LTE (Long-Term Evolution), 393

M

mac-address command, 432

MAC addresses

burned-in, 49

forwarding, 111

learning, 111

tables

EtherChannel impact, predicting, 111-112

instability, 47

STP impact, predicting, 110

maintenance

EIGRP neighbors, 233

OSPF neighbors, 184-185

Managed Extensibility Framework (MEF), 366

Management Information Base. See MIB

management plane (networking devices), 764

managing

bandwidth, 491

delay, 491

IPv6 ACLs, 685

jitter, 491

loss, 491

SNMP, 695

manual EtherChannels configuration, 84-86

marking, 497-499

with classification, 497

DiffServ DSCP values

AF, 502-503

CS, 503

EF, 502

Ethernet 802.1Q headers, 500-501

Ethernet 802.11 headers, 501

IP headers, 499-501

MPLS Label headers, 501

trust boundaries, 501-502

matching packets, 441-442

matching parameters

extended numbered ACLs

protocol, source IP, and destination IP, 463-464

TCP and UDP port numbers, 464-467

standard numbered ACLs

any/all addresses, 448

command syntax, 445

exact IP address, 445-446

subset of address, 446-447

wildcard masks, 446-448

MaxAge timer (STP), 56

maximum-paths command, 218, 222, 270

EIGRP

for IPv4, 247, 647

for IPv6, 651, 662

load balancing, 263

OSPFv3, 627, 643

maximum transmission unit. See MTU

measuring

cloud computing services, 739

end-user traffic, 713

MEC (Multichassis EtherChannel), 161

MEF (Managed Extensibility Framework), 366

memory (TCAM), 766

messages

challenge, 342

debug, 261

EIGRP, 242

Get

agent information, 696

RO/RW communities, 699

SNMPv2 support, 699-701

ICMPv6

Echo request, 674

filtering, 668-669

NDP, filtering, 679-684

Inform, 696-697

SNMPv2, 701-702

SNMPv3, 710-711

NA (neighbor advertisement), 683

NS (neighbor solicitation), 683

OSPF Hello, 181-182

partial update, 232

RA (router advertisement), 610, 684

RS (router solicitation), 610, 684

RSTP, 62

Set

RO/RW communities, 699

SNMPv2 support, 699-701

writing variables on agents, 696

SNMP variables, monitoring, 696

STP Hello BPDU, 49

Trap, 696-697

SNMPv2, 701-702

SNMPv3, 710-711

unsolicited log, 283

update

BGP, 303, 310

DV routing protocols, 229-230

EIGRP, 235-236

metrics

BGP best path selection, 305-306

EIGRP, 236

bandwidth, 265

calculation, 236-237

components, 262

delay settings, 265

EIGRP topology database, 262

example, 237-238

FD (feasible distance), 240-241

RD (reported distance), 240-241

route load balancing, 264

serial link bandwidth, 238-239

IGP, 175-176

infinity, 231

IPv6 routes

EIGRP for IPv6, 650-651

OSPFv3 interface costs, 626

OSPF, 215

based on interface bandwidth, 216-217

higher reference bandwidth, 217

setting, 217

OSPFv3, 638-640

per-VLAN STP, 74

port, 78-79

root, 48

STP port, 53

MetroE (Metro Ethernet), 362-364

access links, 365

data usage, 373

bandwidth used, charging for, 373-374

overages, controlling, 374-375

IEEE Ethernet standards, 366

Layer 3 design, 370

E-LAN service, 371-372

E-Line service, 370-371

E-Tree service, 372

MEF, 366

physical design, 365-366

services, 366

E-LAN, 368-372

E-Line, 367-371

E-Tree, 369-372

topologies

full mesh, 368

hub and spoke, 369

partial mesh, 369

Point-to-Point, 367-368

MIB (Management Information Base), 695-697

OIDs, 697

variables

monitoring, 696

numbering/names, 697

views, 705

mind maps, reviewing, 795

mismatched IPv4 settings, troubleshooting, 568-569

mismatched masks, troubleshooting, 569-571

mismatched subnets, 286

MLPPP (multilink PPP), 348

configuring, 349-350

Layer 2 fragmentation balance, 349

Layer 3, 348-349

load balancing, 349

verifying, 351-353

monitor session command, 721, 728

monitoring MIB variables, 696

MPBGP (Multiprotocol BGP), 380

MPLS (Multiprotocol Label Switching), 362, 375-377

access links, 378

Label headers, 501

Layer 3 design, 377

public cloud connections, 747

QoS, 378-379

virtual private networks. See MPLS VPNs

MPLS VPNs (MPLS Virtual Private Networks), 376

EIGRP challenges, 382

Layer 3, 379-382

OSPF area design, 381-382

MST (Multiple Spanning Tree), 72

MTU (maximum transmission unit), 236

IPv6 mismatches, 636-638

OSPF mismatched settings, 296

mtu command, 432

multiarea on ABR OSPFv3 configuration, 625

multiarea OSPFv2 configuration, 206-210

network commands, 209

single-area configurations, 207-208

subnets, 206

verifying, 210-212

multiarea OSPFv3 configuration, 622

multicast addresses, 682

Multichassis EtherChannel (MEC), 161

multihomed Internet edge design, 306

multilayer switches. See Layer 3, switches

multilink interfaces, 349

multiple frame transmissions, 47

multiple queues (queuing systems), 504

multiple serial links between routers, 347

Multiple Spanning Tree (MST), 72

Multiprotocol BGP (MPBGP), 380

Multiprotocol Label Switching. See MPLS

multithreading, 734

..................Content has been hidden....................

You can't read the all page of ebook, please click here login for view all page.
Reset