N

NA (neighbor advertisement) messages, 683

name command, 25, 40, 135

named ACLs

configuration, 472

editing, 473-475

overview, 471-472

named mode (EIGRP configuration), 249

names (MIB variables), 697

National Institute of Standards and Technology (NIST), 739

native VLANs, 20

mismatched on trunks, 118

router configuration, 525-526

NBAR (Network Based Application Recognition), 498

NBIs (Northbound Interfaces), 768-770

NCP (Network Control Protocols), 341

NDA (nondisclosure agreement), 788

NDP (Neighbor Discovery Protocol), 593

filtering messages through IPv6 ACLs, 679-683

implicit filtering messages through IPv6 ACLs, 683-684

SLAAC, 597

ndp –an command, 615

neighbor commands, 322

neighbor shutdown command, 314

neighbors

advertisement (NA) messages, 683

BGP, 303

disabling, 314

states, 313

eBGP

configuring, 312

disabling, 314

using link addresses, configuring, 311

verifying, 312-313

EIGRP for IPv4, 234-235

discovery, 234

requirements, 286

status, 253

topology information, exchanging, 235-236

troubleshooting, 286-290

verifying, 235, 285-286

EIGRP for IPv6, 656-657

requirements, 656

troubleshooting, 656-657

OSPF

area mismatches, finding, 290-291

duplicate RIDs, 291-293

Hello/dead timer mismatches, 293-294

Hello messages, 181-182

LSDB exchange, 183-186

meeting, 181

requirements, 289

RIDs, learning, 181

states, 182-183, 186, 288

troubleshooting, 288-294

OSPFv3, 632

requirements, 633-634

troubleshooting, 633-635

verifying, 632-633

relationships, 284

neighbor requirements, 284

pinging routers, confirming, 285

routing protocol relationships, troubleshooting, 274

solicitation (NS) messages, 683

states, 628

netsh interface ipv6show neighbors command, 615

Network Based Application Recognition (NBAR), 498

network command, 222, 323

BGP table entries, injecting, 314

advertising subnets to ISPs, 318

classful network routes, 315-318

static discard routes, 319-320

EIGRP, 270

enabling, 246

for IPv4, 648

for IPv6 compatibility, 647

wildcard masks, 248

OSPF single-area configuration, 198-200

OSPFv2

interface configuration, 218

multiarea configuration, 209

Network Control Protocols (NCP), 341

network functions virtualization (NFV), 754

network interface cards (NICs), 718, 735

Network Interface Modules (NIMs), 332

Network Layer Reachability Information (NLRI), 303

Network Management Station. See NMS

Network Time Protocol (NTP), 757-758

networks

analyzers, 719

broad access, 739

classful

autosummarization at boundaries, 266-267

routes, injecting, 315-318

contiguous, 267

controllers

centralized control, 766-767

defined, 766

Northbound Interfaces (NBIs), 768-770

Southbound Interfaces (SBIs), 767-768

devices, 762

control, centralizing, 766-767

control plane, 763-764

data plane, 762-763

management plane, 764

security. See authentication, AAA servers

switch internal processing, 765-766

discontiguous, 267

discontiguous classful, 266-268

flow, 493

physical data center, 736

programmability, 760

APIC Enterprise Module (APIC-EM), 774-776

Application Centric Infrastructure (ACI), 773-774

comparisons, 776

public cloud

address assignment services, 756-757

DHCP services, 757

DNS services, 754-756

NTP, 757-758

VNFs, 752-754

redundancy needs, 547-548

traffic

bandwidth, managing, 491

characteristics, 491

delay, 491

jitter, 491

loss, 491

types, 492-494

unsecured, 400-401

virtual, 735-736, 754

VMs, 736

Nexus 1000v vSwitch, 736

NFV (network functions virtualization), 754

NHRP (Next Hop Resolution Protocol), 412-413

dynamic mapping, enabling, 412

spoke-to-spoke communication, 413

NICs (network interface cards), 718, 735

NIMs (Network Interface Modules), 332

NIST (National Institute of Standards and Technology), 739

NLRI (Network Layer Reachability Information), 303

NMS (Network Management Station), 695

notification community strings, 701

SNMP, 696-697

no auto-summary command, 268

no ip access-group command, 476

no ip address command, 539

no ip domain-lookup command, 572

no ip sla schedule 1 command, 715

no neighbor shutdown command, 314

no passive-interface command, 223, 270

no shutdown command, 40, 359

EIGRP for IPv6, 650, 662

Layer 1 leased-line WAN problems, 354

OSPF processes, 294

ROAS subinterfaces, 527

no spanning-tree portfast bpduguard default command, 95

no spanning-tree portfast default command, 95

no switchport command

Layer 3 EtherChannels, 539

Layer 3 switches, 543

routed ports, 535

nondisclosure agreement (NDA), 788

noninteractive data application traffic, 493

nonroot switches (RPs), 101-103

problems, troubleshooting, 103

tiebreakers, 102-103

normal-time questions, 785

Northbound Interfaces (NBIs), 768-770

notification community strings, 701

notifications

SNMP, 696-697

SNMPv3, 710-711

NS (neighbor solicitation) messages, 683

NTP (Network Time Protocol), 757-758

numbered ACLs, configuring, 475-476

numbers

AS numbers. See ASNs

HSRP group, 555

MIB variables, 697

ROAS subinterfaces, 525

sequence, editing ACLs with, 473-475

numeric reference table conversions

binary-to-hexadecimal, 808

decimal-to-binary, 805-807

hexadecimal-to-binary, 808

O

ODL (OpenDaylight), 771-772

Odom, Wendell Twitter/Facebook information, 799

OIDs (object IDs), 697

on-demand self-service (cloud computing), 739

one-way delay, 491

ONF (Open Networking Foundation), 771

Open SDN, 771

Open SDN Controller (OSC), 772

Open Shortest Path First. See OSPF

OpenDaylight (ODL), 771-772

OpenFlow, 768, 771

operations (IP SLAs), 713-715

OpFlex, 768

OSC (Open SDN Controller), 772

OSPF (Open Shortest Path First), 170, 179

area design, 189

ABR, 190, 210-211

areas, 189-190

backbone areas, 190

backbone routers, 190

benefits, 191

interarea routes, 190

internal routers, 190

intra-area routes, 190

MPLS VPNs, 381-382

network size, 189

problems, 188, 281

single-area, 188

SPF workload, reducing, 190

three-area, 189

best routes with SPF, calculating, 186-188

configuration

errors, troubleshooting, 282-283

mode, enabling, 198

default routes, 213-215

Dijkstra SPF algorithm, 180

EIGRP, compared, 224

goals, 302

Hello/dead timers, 293-294

history, 619

interarea routes, verifying, 212

interfaces

costs, setting, 216-217

EIGRP interfaces, compared, 281

identifying, 275

passive, 196

troubleshooting, 281-283

load balancing, 217

LSAs, 179

metrics, 215

based on interface bandwidth, 216-217

higher reference bandwidth, 217

setting, 217

MTU mismatched settings, 296

neighbors, 181

area mismatches, finding, 290-291

DRs on Ethernet links, 185-186

duplicate RIDs, 291-293

Hello messages, 181-182

Hello/dead timer mismatches, 293-294

LSAs, exchanging, 183-184

maintaining, 184-185

meeting, 181

requirements, 284, 289

RIDs, learning, 181

states, 182-186, 288

troubleshooting, 288-294

process-ids, 198

processes, shutting down, 294-296

RIDs

configuring, 203-204

duplicate, troubleshooting, 291-293

super backbone, 381

Version 2. See OSPFv2

OSPFv2 (OSPF Version 2), 170

default routes, 213-215

dual stack, 619

history, 619

interface configuration

example, 218

verifying, 219-221

load balancing, 217

metrics, 215

based on interface bandwidth, 216-217

higher reference bandwidth, 217

setting, 217

multiarea configuration, 206-210

network commands, 209

single-area configurations, 207-208

subnets, 206

verifying, 210-212

OSPFv3, compared, 621, 628-629

RIPv2/EIGRP, compared, 233

single-area configuration, 197-198

IPv4 addresses, 197

matching with network command, 198-200

multiarea configurations, 207-208

network command, 198

organization, 196-197

passive interfaces, 204-206

RIDs, 203-204

verifying, 200-202

wildcard masks, 199

OSPFv3 (OSPF Version 3), 616

address families dual stack, 620

configuration, 621

default routes, 627-628

load balancing, 627

multiarea example, 622

multiarea on ABR, 625

route selection metrics, setting, 626

single-area, 623-624

dual stack, 619

interfaces, 630

troubleshooting, 631-632

verifying, 630-631

IPv6

MTU mismatches, 636-638

routes, 638-641

LSAs, 636

LSDBs, 636

neighbors, 632

requirements, 633-634

troubleshooting, 633-635

verifying, 632-633

OSPFv2, compared, 621, 628-629

passive interfaces, 624

RIDs, 624

output queuing, 504

overages (MetroE data usage), 374-375

overlapping routes, troubleshooting, 577-580

overlapping subnets

with VLSM, 583-585

without VLSM, 581-583

P

PaaS (Platform as a Service), 743-744

packets

classification, 495

ACLs, 497

with marking, 497

matching, 496-497

NBAR, 498

router queuing, 496

routers, 497

congestion avoidance, 512

TCP windowing, 512-513

tools, 513-514

congestion management, 504

Low Latency Queuing (LLQ), 505-507

multiple queues, 504

output queuing, 504

prioritization, 505

queuing strategy, 507

round robin scheduling, 505

de-encapsulating/re-encapsulating with HDLC, 336

defined, 495

filtering. See ACLs

ICMPv6, 675

marking, 499

802.1Q headers, 500-501

802.11 headers, 501

with classification, 497

DiffServ DSCP AF values, 502-503

DiffServ DSCP CS values, 503

DiffServ DSCP EF values, 502

IP headers, 499-501

MPLS Label headers, 501

trust boundaries, 501-502

matching, 441-442

policing, 507

discarding excess traffic, 509

edge between networks, 509-510

features, 510

traffic rate versus configured policing rate, 508

router originated, 670

router queuing, 496

routing over serial links, 398

shaping, 507, 510

features, 512

slowing messages, 510

time intervals, 511-512

TCP, 675

UDP, 675

PAgP (Port Aggregation Protocol), 86

PAP (Password Authentication Protocol)

authentication, 343, 356

configuring, 346-347

parameters

ICMPv6, 669

ip_address, 198

wildcard_mask, 198

partial mesh topology (MetroE), 369

partial updates (EIGRP), 232, 235

passive-interface command, 205

defined, 222, 297

EIGRP, 251, 270

OSPF interfaces as passive, configuring, 196

OSPFv3, 624

passive-interface default command, 205, 270

passive interfaces

EIGRP, 251

OSPF, 196, 204-206

OSPFv3, 624

Password Authentication Protocol. See PAP

passwords, 698

path attributes (BGP), 305-306

Path MTU Discovery (PMTUD), 668

paths

forwarding

APIC-EM Path Trace ACL Analysis tool, 778

APIC-EM Path Trace app, 777

selections, 172

PBX (private branch exchange), 34

PCP (Priority Code Point) field (802.1Q header), 500

PE (provider edge), 377

Pearson Network Simulator (the Sim), 796

peers (BGPs), 303

periodic updates, 229

permit command, 471-474, 487

extended IPv6 ACLs, 675

GRE tunnel ACLs, 410

IPv6 ACLs, 672

permit gre command, 432

permit icmp any any router-advertisement command, 684

permit icmp any any router-solicitation command, 684

permit ipv6 commands, 687

permit keyword, 442, 448-449

Per-VLAN Spanning Tree Plus (PVST+), 72-73

physical data center networks, 736

physical design (MetroE), 365-366

physical server model, 734

ping command, 483, 571-574, 615

IPv6

connectivity, testing, 600-602

routes, testing, 614

leased-line WANs, 353

self-ping, 483-485

ping6 command, 615

IPv6 ACLs, 674

IPv6 connectivity, testing, 601

pings (IPv6 hosts)

failure from default router, 606-607

name resolution problems, 607-608

working only in some cases, 605-606

planes (networking devices)

control, 763-764

data, 762-763

management, 764

planning

EIGRP configuration, 246

VTP configuration, 129

Platform as a Service (PaaS), 743-744

PMTUD (Path MTU Discovery), 668

point-to-point edge ports, 63, 93

point-to-point GRE tunnels, 399

point-to-point lines, 330-331

building, 335-336

CSU/DSU, 334

with HDLC, 336

configuring HDLC, 337-340

de-encapsulating/re-encapsulating IP packets, 336

framing, 336

physical components, 332-333

with PPP

authentication, 342-343

configuring PPP, 343-344

configuring PPP CHAP, 344-346

configuring PPP PAP, 346-347

control protocols, 341

framing, 341

multilink. See MLPPP

PPP functions, 340

speeds, 333-334

troubleshooting, 353-354

Layer 1 problems, 354

Layer 2 problems, 354-356

Layer 3 problems, 357-358

mismatched subnets, 358

Point-to-Point over Ethernet. See PPPoE

point-to-point ports, 63, 93

Point-to-Point Protocol. See PPP

Point-to-Point topology (MetroE), 367-368

points of presence (PoP), 304, 365

policies

ACI, 773

filtering, 668

policing

data overages (MetroE), 374

QoS, 507

discarding excess traffic, 509

edge between networks, 509-510

features, 510

traffic rate versus configured policing rate, 508

rate, 508

pooling resources, 739

PoP (points of presence), 304, 365

Port Aggregation Protocol (PAgP), 86

PortChannels. See EtherChannels

PortFast, 65

configuring, 81

enabling/disabling, 83

global settings, displaying, 83

verifying, 82-83

ports

802.1w RSTP roles, 60

alternate, 60-61, 91-92

backup, 60, 91-92

blocking, choosing, 44

channels, 86

costs

IEEE default, 55

STP, 53, 78-79

designated, 49, 54, 60

disabled, 60

Layer 3 switch routed, 534-537

numbers, matching, 464-467

per-VLAN STP costs, 74

root (RPs), 60

nonroot switches, 101-103

switches, choosing, 52-53

RSTP

backup, 62-63

roles, 60, 91-92

states, 92-93

types, 63, 92

SPAN destination/source, 719

stacking ports, 156

states

RSTP, 92

STP versus RSTP, 62

switch root, choosing, 52-53

trusted/untrusted, 151-153

configuring, 153

DHCP snooping, 154

powers of 2 numeric reference table, 810

PPP (Point-to-Point Protocol), 340, 413

authentication, 342-343

CHAP

authentication, 342, 356

configuring, 344-345

verifying, 345-346

configuring, 343-344

control protocols, 341

dial connections to ISPs, 414

framing, 341

leased-line WANs, 340

multilink (MLPPP), 348

configuring, 349-350

Layer 2 fragmentation balance, 349

Layer 3, 348-349

load balancing, 349

verifying, 351-353

PAP

authentication, 343, 356

configuring, 346-347

PPPoE Layer 2 configuration, 417

status, 344

ppp authentication chap command, 345

ppp authentication command, 349, 359

ppp chap hostname command, 432

ppp chap password command, 432

ppp multilink command, 350, 360

ppp multilink group command, 360

ppp multilink group 1 command, 350

ppp pap sent-username command, 346, 359

PPPoE (Point-to-Point over Ethernet), 413-415

configuring, 415-416

ISP router configuration example, 419

Layer 1, 416-417

Layer 2, 417

Layer 3, 417-418

summary, 418-419

enabling, 417

history, 414

troubleshooting, 425-426

customer router configuration, 426

dialer 2 status, 427

Layer 1, 427-428

Layer 2, 428-429

Layer 3, 429

summary, 430

verification, 420-421

dialers, 421-422

Layer 3 status, 425

session status, 424

virtual-access interfaces, 423

pppoe-client dial-pool number command, 417, 432

pppoe enable command, 417, 432

practice exams

answering questions, 790-791

CCNA R&S, 790

checklist, 790

ICND2, 790

knowledge gaps, finding, 792-793

other, 792

scores, 796-797

taking, 789-790

preemption (HSRP active/standby roles), 557-558

pre-exam suggestions, 786-787

prefixes

BGP, 303

IPv6, 594, 670

preparing for the exam

CLI skills, 794-796

exam-day suggestions, 787

knowledge gaps, finding, 792-793

practice exams

answering questions, 790-791

CCNA R&S, 790

checklist, 790

ICND2, 790

other, 792

scores, 796-797

taking, 789-790

pre-exam suggestions, 786-787

preparing for failure, 788

question types, 784

ready to pass assessment, 797

study tasks, 798

studying after failing to pass, 797-798

tutorial, 784-785

prioritization (congestion management), 505

Priority Code Point (PCP) field (802.1Q header), 500

priority queues, 506

priv keyword (snmp-server group command), 707

private branch exchange (PBX), 34

private cloud computing, 739-741

private WANs

MetroE, 364

access links, 365

data usage, 373-375

E-LAN services, 368-372

E-Line services, 367-371

E-Tree services, 369-372

full mesh topology, 368

hub and spoke topology, 369

IEEE Ethernet standards, 366

Layer 3 design, 370-372

MEF, 366

partial mesh topology, 369

physical design, 365-366

Point-to-Point topology, 367-368

services, 366

MPLS, 375-377

access links, 378

Layer 3 design, 377

MPLS VPNs, 379-382

QoS, 378-379

VPNs, 376

public cloud

accessing, 746-749

branch office connections, 751

types, 362

probes, 713-715

process-ids (OSPF), 198

processes

OSPF, shutting down, 294-296

RSTP, 62

programmability (network), 760

APIC Enterprise Module (APIC-EM), 774-776

Application Centric Infrastructure (ACI), 773-774

comparisons, 776

proprietary routing protocols, 175

protocols, 224

BGP, 174, 300, 303

AS, 304

ASNs, 304

best path selection, 305-306

configuring, 310

external. See eBGP

IGPs, compared, 302

internal (iBGP), 304

ISP default routes, learning, 320-321

neighbors, 303, 313-314

prefixes, 303

reachability, 302

route advertising, 303-304

routing table analysis reports website, 303

table entries, injecting, 314-320

update messages, 303-310

BPDUs (bridge protocol data units), 49

CHAP

authentication, 342, 356

configuring, 344-345

verifying, 345-346

control plane, 764

DHCP

Binding Table, 153

DHCP Relay, 573

public cloud services, 757

snooping, 151-154

Dijkstra SPF algorithm, 180

DTP, 116

DV (distance vector), 175, 228

distance/vector information learned, 228

EIGRP as, 232-233

route poisoning, 231-232

split horizon, 230-231

update messages, 229-230

EAP, 146

EAPoL, 146

eBGP, 304

Internet edge, 306-309

neighbors, 311-314

EGP, 173, 302

EIGRP, 175

FHRP, 544

features, 550

HSRP. See HSRP

need for, 549

options, 550-551

GLBP, 544

HDLC, 331, 336-340, 398

HSRP, 544, 551

active/passive model, 551

active/standby routers, choosing, 555

active/standby rules, 557

configuring, 554

failover, 552

group numbers, 555

load balancing, 553

no preemption, 557

with preemption, 558

troubleshooting, 560-563

verifying, 555-556

versions, 559-560

iBGP, 304

IGPs, 173, 226

BGPs, compared, 302

classless/classful, 177

configuring, 310

goals, 302

metrics, 175-176

routing protocol algorithm, 175

subnets, 303

IGRP, 175

IPv4. See IPv4 routing

IPv6. See IPv6 routing

link-state, 175

management plane, 765

matching, 463-464

MPBGP, 380

NDP, 593

filtering messages through IPv6 ACLs, 679-683

implicit filtering messages through IPv6 ACLs, 683-684

SLAAC, 597

NHRP, 412-413

dynamic mapping, enabling, 412

spoke-to-spoke communication, 413

NTP, 757-758

OSPF. See OSPF

OSPFv2. See OSPFv2

OSPFv3. See OSPFv3

PAgP, 86

PAP

authentication, 343, 356

configuring, 346-347

PPP. See PPP

PPPoE, 413, 415

configuring, 415-419

enabling, 417

history, 414

ISP router configuration example, 419

troubleshooting, 425-430

verification, 420-425

RADIUS, 146-148

RIP, 175-176, 226

RIPv2, 302

EIGRP/OSPFv2, compared, 233

goals, 302

routable, 172

routed, 172

routing

administrative distance, 177-178

algorithms, 175

AS, 174

autosummarization, 266-268

classless/classful, 177, 266

convergence, 173

defined, 172

DV. See DV protocols

EGP (exterior gateway protocol), 173

functions, 172-173

IGP, 173-177

interfaces enabled with, verifying, 274

interior comparison, 233

IPv4, 202

link-state, 175

path selections, 172

proprietary, 175

RIPv1, 226

RIPv2, 226

route redistribution, 177

troubleshooting, 273-274

RSTP

alternate ports, 60-61

backup port role, 62-63

Cisco Catalyst STP modes, 88-90

implementing, 88

link types, 63

port roles, 60, 91-92

port states, 62, 92-93

port types, 63, 92

processes, 62

standards, 58

STP, compared, 59-60

RTP, 235

SNMP. See SNMP

STA (spanning-tree algorithm), 48

STP. See STP

TACACS+, 148

TCP

BGP connections, displaying, 313

packets, 675

port numbers, matching, 464-467

transporting messages between BGP peers, 310

windowing, 512-513

UDP

Jitter probes, 713

packets, IPv6 ACL matching, 675

port numbers, matching, 464-467

VRRP, 544

VTP, 120

automated update powers, 120

configuration, 129-131

domains, 125-127

features, 128

planning configuration, 129

pruning, 127-128

requirements, 126-127

servers, 124

standard range VLANs, 123

storing configuration, 134-135

switches synchronization to VLAN database, verifying, 131-133

synchronization, 125-126

transparent mode, 135

troubleshooting, 135-139

versions, 127

VLAN support, adding, 123

provider edge (PE), 377

pruning (VTP), 127-128

public cloud computing, 741

accessing with

Internet, 745-746

private WANs, 746-749

VPNs, 747

address assignment services, 756-757

branch offices example, 749-752

email services traffic flow, 750-751

Internet connections, 751

private WAN connections, 751

DHCP services, 757

DNS services, 754-756

intercloud exchanges, 748-749

NTP, 757-758

VNFs, 752-754

PVST+ (Per-VLAN Spanning Tree Plus), 72-73

Q

QoE (Quality of Experience), 492

QoS (Quality of Service), 378, 488

bandwidth, 491

classification, 495

ACLs, 497

with marking, 497

matching, 496-497

NBAR, 498

router queuing, 496

routers, 497

congestion avoidance, 512

TCP windowing, 512-513

tools, 513-514

congestion management, 504

Low Latency Queuing (LLQ), 505-507

multiple queues, 504

output queuing, 504

prioritization, 505

queuing strategy, 507

round robin scheduling, 505

defined, 488

delay, 491

jitter, 491

loss, 491

marking, 499

with classification, 497

DiffServ DSCP AF values, 502-503

DiffServ DSCP CS values, 503

DiffServ DSCP EF values, 502

Ethernet 802.1Q headers, 500-501

Ethernet 802.11 headers, 501

IP headers, 499-501

MPLS Label headers, 501

trust boundaries, 501-502

MPLS, 378-379

needs based on traffic types

data applications, 492-493

video applications, 494

voice applications, 493-494

policing, 507

discarding excess traffic, 509

edge between networks, 509-510

features, 510

traffic rate versus configured policing rate, 508

shaping, 507, 510

features, 512

slowing messages, 510

time intervals, 511-512

switches/routers, 495

tools, 496

VoIP, 493-494

query messages (EIGRP), 242

questions (exam)

answering, 790-791

budgeting time, 785

knowledge gaps, finding, 792-793

types, 784

queuing

congestion management, 504

Low Latency Queuing (LLQ), 505-507

multiple queues, 504

output queuing, 504

prioritization, 505

round robin scheduling, 505

strategy, 507

priority queues, 506

queue starvation, 506

routers, classification for, 496

R

RA (Router Advertisement), 610, 684

RADIUS protocol, 146-148

rapid elasticity (cloud computing), 739

Rapid PVST+, 72

Rapid Spanning Tree Protocol. See RSTP

rate limiting (DHCP snooping), 154

RD (reported distance), 240-241, 257

reachability (BGP), 302

read-only (RO) communities (SNMP), 699

read-write (RW) communities (SNMP), 699

ready to pass assessment (exam), 797

Real-time Transport Protocol (RTP), 235

redistribution

Internet edge ISP routes, learning, 309

routes (MPLS VPNs), 380

redundancy

FHRP

features, 550

HSRP. See HSRP

need for, 549

options, 550-551

LANs

problems caused without STP, 45-46

STP, 42

network needs for, 547-548

single points of failure, 547

reference bandwidth, 216-217

relationships (neighbors), 284

EIGRP for IPv6, 656-657

OSPFv3, troubleshooting, 633-635

pinging routers, confirming, 285

requirements, 284

states, 628

relay agents (DHCPv6), 596

Reliable Transport Protocol (RTP), 235

remark command, 472, 487

Remote SPAN (RSPAN), 721

reply messages (EIGRP), 242

reported distance (RD), 240-241, 257

Representational State Transfer (REST), 769

requirements

cloud computing services, 739

EIGRP for IPv6 neighbors, 656

neighbors, 284

EIGRP, 286

OSPF, 289

OSPFv3, 633-634

SNMPv3 configuration, 704

VTP, 126-127

resource pooling (cloud computing), 739

responders (IP SLAs), 713

REST (Representation State Transfer), 769

RESTful APIs, 769

reverse engineering from ACL to address range, 454-456

reversed source/destination IP address, troubleshooting, 480-481

RFC 1065, 694

RFC 4301 Security Architecture for the Internet Protocol, 395

RIDs (router IDs), 181

defining, 196

EIGRP, configuring, 252

OSPF, 181

configuring, 203-204

duplicate, troubleshooting, 291-293

OSPFv3, 624

RIP (Routing Information Protocol), 175-176, 226

RIPv2 (RIP Version 2), 226

EIGRP/OSPFv2, compared, 233

goals, 302

RO (read-only) communities (SNMP), 699

ROAS (router-on-a-stick), 520, 524

configuration, 524

example, 524

native VLANs, 525-526

subinterface numbers, 525

subinterfaces, creating, 524-525

troubleshooting, 528-529

verifying, 526-527

connected routes, 526

show vlans command, 527

subinterface state, 527

roles

ports

alternate, 60-61

backup, 62-63

root. See RPs

RSTP, 60, 91-92

STP, 57

root bridge IDs, 50

root costs (switches), 48

root ports. See RPs

root switches

electing, 50-52

election influence, configuring, 80-81

ruling out switches, 100-101

STP, verification, 77

troubleshooting, 99-101

round robin scheduling (queuing), 505

round-trip delay, 491

Round Trip Time (RTT), 715

routable protocols, 172

routed ports, 534-537

routed protocols, 172

Router Advertisement (RA) messages, 610, 684

router bgp command, 311

router eigrp command, 246, 270, 647

router-id command, 222, 614

OSPFv3, 624, 643

RIDs, defining, 196

router-on-a-stick. See ROAS

router ospf command, 196, 222

router ospf 1 command, 198

Router Solicitation (RS), 610

routers. See also routes; routing

ABR (Area Border Router), 190

interface OSPF areas, verifying, 210-211

OSPFv2 multiarea configuration, 209-210

advertisement (RA) messages, 610, 684

backbone, 190

best routes, finding, 180

classification, 497

ACLs, 497

NBAR, 498

Cloud Services Routers (CSRs), 747

configuring different VIPs, troubleshooting, 563

data plane processing, 763

designated (DRs), 185

backup (BDRs), 185

discovering, 211-212

Ethernet links, 185-186

DROthers, 186

flooding, 179

GRE tunnels between, 399

HSRP

active/passive model, 551

active/standby routers, choosing, 555

active/standby rules, 557

configuring, 554

failover, 552

group numbers, 555

load balancing, 553

no preemption, 557

with preemption, 558

troubleshooting, 560-563

verifying, 555-556

versions, 559-560

IDs. See RIDs

internal, 190, 623-624

IPv6

addressing configuration, 598-599

connectivity, verifying, 601-603

issues, 604

routing, enabling, 598

static route configuration, 599

troubleshooting, 611-612

ISP, 419

LSAs, 636

multiple serial links between, 347

OSPF interface costs, 216-217

public cloud networks, 754

QoS, 495

queuing

classification for, 496

congestion management, 504-507

strategy, 507

redundant, 549. See also FHRP

ROAS, 23, 524

configuration, 524-526

native VLANs, 525-526

subinterfaces, creating, 524-525

troubleshooting, 528-529

verifying, 526-527

router WAN interface status, 585

routing IP packets over serial links, 398

solicitation (RS) messages, 610, 684

troubleshooting

DHCP issues, 573-574

LAN issues, 575-576

VLAN routing, 21-23

routes. See also routers; routing

BGP

advertising, 303-304

best path selection, 305-306

classful networks, injecting, 315-318

default, 627-628

discard, 319

EIGRP

choosing, 234

load balancing, 263-264

tuning with bandwidth, 259

variance, 263-264

EIGRP for IPv6, 659-660

feasibility conditions, 242

feasible successor, 241-242

convergence, 260-261

identifying, 258-260

host, 357

interarea, 640

IPv6

EIGRP for IPv6 metrics, 650-651

OSFPv3 metrics, 626, 638-640

static, configuring, 599

troubleshooting, 640-641

ISP

default, learning, 320-321

Internet edge, learning, 309

OSPF

default routes, 213-215

interarea, verifying, 212

poisoning, 231-232

redistribution, 177, 380

static discard, 319-320

successor, 257-258

routing. See also routers; routes

EIGRP for IPv6, enabling/disabling, 650

LANs, 523

protocols. See routing protocols

troubleshooting

default router IP address setting, 572

DHCP issues, 573-574

DNS problems, 571-572

incorrect addressing plans, 581-585

IP forwarding issues, 577-580

LAN issues, 575-576

mismatched IPv4 settings, 568-569

mismatched masks, 569-571

router WAN interface status, 585

VLAN. See VLAN routing

Routing Information Protocol (RIP), 175

routing protocols

administrative distance, 177-178

algorithms, 175

AS, 174

autosummarization, 266

classful network boundaries, 266-267

discontiguous classful networks, 267-268

classless/classful, 177, 266

convergence, 173

defined, 172

DV, 175, 228

distance/vector information learned, 228

EIGRP as, 232-233

route poisoning, 231-232

split horizon, 230-231

update messages, 229-230

EGP (exterior gateway protocol), 173

functions, 172-173

IGP, 173

algorithms, 175

classless/classful, 177

metrics, 175-176

interfaces enabled with, verifying, 274

interior comparison, 233

IPv4, 202

link-state, 175

path selections, 172

proprietary, 175

RIPv1, 226

RIPv2, 226

route redistribution, 177

troubleshooting

configuration errors, 274

internetwork, analyzing, 273

neighbor relationships, 274

routing tables, 273

RPs (root ports), 60

nonroot switches, 101-103

problems, troubleshooting, 103

tiebreakers, 102-103

switches, choosing, 52-53

RS (Router Solicitation) messages, 610, 684

RSPAN (Remote SPAN), 721

RSTP (Rapid Spanning Tree Protocol), 58-59

alternate ports, 60-61

backup port role, 62-63

Cisco Catalyst switch RSTP modes, 88-90

implementing, 88

link types, 63

ports

roles, 60, 91-92

states, 62, 92-93

types, 63, 92

processes, 62

standards, 58

STP, compared, 59-60

RTP (Real-time Transport Protocol), 235

RTP (Reliable Transport Protocol), 235

RTT (Round Trip Time), 715

rules

AAA login authentication, 150

HSRP active/standby, 557

implicit IPv6 ACL ICMPv6 message filtering, 683-684

ruling out switches, 100-101

RW (read-write) communities (SNMP), 699

S

SaaS (Software as a Service), 743

SBIs (Southbound Interfaces), 767-768

scoring exams, 796-797

sdm prefer command, 532

sdm prefer lanbase-routing command, 543

SDN (Software Defined Networking), 760

APIC Enterprise Module (APIC-EM), 774-776

Application Centric Infrastructure (ACI), 773-774

architecture, 770

comparisons, 776

controllers

centralized control, 766-767

Northbound Interfaces (NBIs), 768-770

OpenDaylight SDN controller, 771

Southbound Interfaces (SBIs), 767-768

Open SDN, 771

Open SDN Controller (OSC), 772

OpenDaylight (ODL), 771-772

OpenFlow, 771

Secure Shell (SSH), 765

Secure Sockets Layer (SSL), 396-397

security

AAA servers

configuration, 148-150

login authentication rules, 150

login process, 147

TACACS+/RADIUS protocols, 148

access, 145

attacks

DHCP-based, 152

types, 150

authentication

802.1x, 145

AAA servers, 147-150

Internet VPNs, 393

SNMPv3, 699, 707-708

DHCP snooping

configuration settings, 153

DHCP-based attacks, 152

DHCP Binding Table, 153

features, 151

ports as trusted, configuring, 153

rate limiting, 154

rules summary, 153

trusted/untrusted ports, 151-154

encryption, 699, 707-708

IEEE 802.1x, 144-146

AAA servers, configuring, 145

authentication process, 145

EAP, 146

username/password combinations, verifying, 145

Internet VPNs, 393

IPsec encryption, 395-396

SNMP, 698-699

SNMPv3, 705-707

STP, 65-66

self-ping, 483-485

sender’s bridge IDs, 50

sender’s root cost, 50

sequence numbers, 473-475

serial cables, 332

serial links. See leased-line WANs

servers

AAA

authentication, 147-150

configuring for 802.1x, 145

defining, 149

enabling, 149

username/passwords, verifying, 145

Cisco hardware, 732-733

defined, 732

physical server model, 734

virtualization, 734-735

hosts, 734

hypervisors, 734

multithreading, 734

networking, 736

virtual data centers, 735-738

VMs, 734

VTP, 124

service-level agreements (SLAs), 712

service providers (SPs), 362

services

cloud computing

broad network access, 739

cloud services catalogs, 740

Infrastructure as a Service (IaaS), 742

measured, 739

on-demand self-service, 739

Platform as a Service (PaaS), 743-744

private, 739-741

public, 741

rapid elasticity, 739

requirements, 739

resource pooling, 739

Software as a Service (SaaS), 743

DHCP, 757

DNS, 754-756

Internet as WAN, 389

MetroE, 366

E-LAN, 368-372

E-Line, 367-371

E-Tree, 369-372

public cloud

accessing with Internet, 745-746

accessing with private WANs, 746-749

accessing with VPNs, 747

address assignment, 756-757

branch offices example, 749-752

intercloud exchanges, 748-749

session keys, 395

session status (PPPoE), 424

sessions (SPAN), 720-721, 725

Set messages

RO/RW communities, 699

SNMPv2 support, 699-701

writing variables on agents, 696

shaping (QoS), 507, 510

features, 512

rate, 510

slowing messages, 510

time intervals, 511-512

shaping data overages (MetroE), 375

shared edge ports, 93

shared keys, 395

shared ports, 63, 93

shared session keys, 395

shorter VLAN configuration example, 28-29

Shortest Path First algorithm. See SPF algorithm

show access-list command, 473

show access-lists command, 450, 457, 479, 487, 687

show arp command, 572

show commands

IPv6 ACLs, 673

routing protocol-enabled interfaces, verifying, 275

STP status, 68

show controllers command, 352

show controllers serial command, 360

show etherchannel 1 summary command, 86

show etherchannel command, 96, 543

show etherchannel summary command, 107, 540

show interfaces command, 298, 360, 543, 569

EIGRP neighbor requirements, verifying, 286

MLPPP, 352

OSPF

interfaces, 283

neighbors, 289

OSPFv3 interface bandwidth, 640

PPP CHAP status, 345

PPP PAP, 346

PPP status, 344

routed ports, 536

show interfaces description command, 298, 576

show interfaces dialer command, 421, 433

show interfaces status command

Layer 3 EtherChannels, 539

routed ports, 536

show interfaces switchport command, 31-34, 37, 41, 114-116, 135

show interfaces trunk command, 32-34, 38, 41, 116-117

show interfaces tunnel command, 405, 433

show interfaces virtual-access command, 433

show interfaces virtual-access configuration command, 423

show interfaces vlan command, 543

show ip access-list command, 457, 474-476

show ip access-lists command, 450, 479, 487

show ip bgp command, 323

show ip bgp summary command, 313, 323

show ip eigrp interfaces command, 271, 297

EIGRP-enabled interfaces, 250-251, 275

EIGRP neighbor requirements, verifying, 286

multilink interfaces, 352

show ip eigrp interfaces detail command, 250, 271

show ip eigrp neighbors command, 271, 297

neighbor status, displaying, 253

neighbor verification checks, 285

show ip eigrp topology all-links command, 260

show ip eigrp topology command, 271

feasible successor routes, 259

metrics, 262

successor routes, 258

topology table, 256

show ip interface brief command, 360

GRE tunnels, 404

multilink interfaces, 352

OSPF interfaces, troubleshooting, 283

show ip interface command, 286, 450, 457, 479

show ip ospf command, 223, 298

duplicate OSPF RIDs, 291

OSPF neighbors, troubleshooting, 289

show ip ospf database command, 179, 201, 223

show ip ospf interface brief command, 205, 223, 298

OSPF areas for ABR interfaces, 210

OSPF-enabled interfaces, identifying, 275

OSPF neighbors, troubleshooting, 289

OSPF status on interfaces, 281

OSPFv2 interface configuration, 221

show ip ospf interface command, 223, 298

DRs/BDRs details, displaying, 211

Hello/dead timer mismatches, 293

OSPF areas for ABR interfaces, 210

OSPF neighbors, troubleshooting, 289

OSPFv2 interface configuration, 220

passive interface, 206

show ip ospf neighbor command, 182, 223, 298

DRs/BDRs details, displaying, 211

neighbors, listing, 288

OSPF processes shutdown, 295

show ip ospf neighbor interface brief command, 295

show ip protocols command, 223, 271, 297

EIGRP-enabled interfaces, 251-252, 275

EIGRP neighbors, 253, 286

IPv4 routing protocols, 202

OSPF configuration errors, 282-283

OSPFv2 interface configuration, 219

show ip route command, 223, 271, 323, 577-580

administrative distance, 178

dialer interface Layer 3 orientation, 425

EIGRP-learned routes, displaying, 254

IPv4 routes added by OSPF, 201

routing tables, displaying, 543

show ip route eigrp command, 254, 271, 297

show ip route ospf command, 223, 298, 577-578

show ip route static command, 214

show ip sla enhanced-history distribution-statistics command, 729

show ip sla history command, 717, 729

show ip sla statistics command, 729

show ip sla summary command, 729

show ipv6 access-list command, 677, 687

show ipv6 eigrp interfaces command, 654, 662

show ipv6 eigrp interfaces detail command, 662

show ipv6 eigrp neighbors command, 663

show ipv6 eigrp topology command, 663

show ipv6 eigrp topology | section command, 663

show ipv6 interface command, 614, 687

show ipv6 neighbors command, 614

IPv6 ACL ICMPv6 NDP message filtering, 681

IPv6 IPv4 replacement, 603

show ipv6 ospf command, 640, 643

show ipv6 ospf database command, 636, 643

show ipv6 ospf interface brief command, 630, 640, 643

show ipv6 ospf interface command, 630-631, 643

show ipv6 ospf neighbor command, 635, 643

show ipv6 protocols command, 614, 643

EIGRP for IPv6, 662

EIGRP for IPv6 interfaces, 654

OSPFv3 interfaces, 630

show ipv6 route command, 614, 643

EIGRP for IPv6, 663

IPv6 router connectivity, 603

show ipv6 route eigrp command, 663

show ipv6 route ospf command, 638, 643

show ipv6 route | section command, 663

show ipv6 routers command, 614, 681

show mac address-table command, 114

show mac address-table dynamic command, 111

show monitor detail command, 724, 729

show monitor session all command, 723

show monitor session command, 724, 729

show ppp all command, 346-347, 360

show ppp multilink command, 353, 360

show pppoe session command, 424, 433

show running-config command, 135, 449, 473-475

show snmp command, 703, 729

show snmp community command, 702, 728

show snmp contact command, 728

show snmp group command, 709, 729

show snmp host command, 702, 729

show snmp location command, 728

show snmp user command, 708, 729

show spanning-tree bridge command, 81

show spanning-tree command, 96

show spanning-tree interface command, 96

show spanning-tree interface detail command, 82

show spanning-tree root command, 77, 81

show spanning-tree summary command, 83, 96

show spanning-tree vlan 10 bridge command, 77

show spanning-tree vlan 10 command, 75-77

show spanning-tree vlan 10 interface gigabitethernet0/2 state command, 92

show spanning-tree vlan command, 96

show standby brief command, 555-565

show standby command (HSRP), 565

configuration, 560

status, 556

show tcp brief command, 313

show tcp summary command, 323

show vlan brief command, 26-29, 114

show vlan command, 41, 114, 141

show vlan id command, 27, 114

show vlan status command, 135

show vlans command, 527, 543

show vtp password command, 134, 141

show vtp status command, 29, 41, 131, 134, 141

shutdown command, 40, 359

EIGRP for IPv6, 650, 662

Layer 1 leased-line WAN problems, 354

OSPF processes, 294

ROAS subinterfaces, 527

shutdown vlan command, 135, 140

shutting down OSPF processes, 294-296

signatures, 498

the Sim (Pearson Network Simulator), 796

Simple Network Management Protocol. See SNMP

single-area OSPF, 188

single-area OSPFv2 configuration, 197-198

IPv4 addresses, 197

matching with network command, 198-200

multiarea configurations, 207-208

network command, 198

organization, 196-197

passive interfaces, 204-206

RIDs, 203-204

verifying, 200-202

IPv4 routing protocols, 201-202

LSDB contents, displaying, 201

wildcard masks, 199

single-area OSPFv3 configuration, 623-624

single homed Internet edge design, 306

single points of failure, 547

site-to-site VPNs, 394-396

SLA (service level agreement), 712

SLAAC (stateless address autoconfiguration)

EUI-64, 597

IPv6 settings, 597

NDP, 597

troubleshooting, 609-610

SLBaaS (SLB as a service), 753

SNMP (Simple Network Management Protocol), 692

agents, 695-696

clear-text passwords, 698

communities, 698-699

Get messages

agent information, 696

RO/RW communities, 699

SNMPv2 configuration, 699-701

history, 695

Inform messages, 696-697, 701-702

managers, 695

MIB, 696-697

notifications, 696-697

read-only (RO) communities, 699

read-write (RW) communities, 699

security, 698-699

Set messages

RO/RW communities, 699

SNMPv2 configuration, 699-701

writing variables on agents, 696

Trap messages, 696-697, 701-702

snmp-server command, 700

snmp-server community command, 727

snmp-server contact command, 727

snmp-server enable traps command, 727

snmp-server group command, 705

snmp-server host command, 701, 710, 727

snmp-server location command, 727

snmp-server user command, 707

SNMPv2

configuring

Get/Set messages, 699-701

Trap/Inform messages, 701-702

verifying, 702-704

security, 699

SNMPv2c (Community-based SNMP Version 2), 699

SNMPv3

configuring, 704

authentication, 707-708

encryption, 707-708

groups, 705-707

notifications, 710-711

requirements, 704

summary, 711-712

users, 707

verifying, 708-709

groups

MIB views, 705

security levels, 705

write views, 706

Inform messages, 710-711

MIB views, 705

security, 699

Trap messages, 710-711

Software as a Service (SaaS), 743

Software Defined Networking. See SDN

solution apps, 777

sources

addresses, 406

IPs, matching, 463-464

IP SLAs, 713

ports (SPAN), 719

SPAN, limiting, 725

Southbound Interfaces (SBIs), 767-768

SPAN (Switched Port Analyzer), 718

dependencies, 722

destination ports, 719

Encapsulated RSPAN (ERSPAN), 721

local, 721-724

network analyzer needs for, 719

Remote (RSPAN), 721

sessions, 720-721

source ports, 719

sources, limiting, 725

traffic direction, 725

VLANs, monitoring, 721

spanning-tree algorithm (STA), 48

spanning-tree bpduguard disable command, 95

spanning-tree bpduguard enable command, 81, 95

spanning-tree bpguard enable command, 75

spanning-tree commands, 95

spanning-tree mode command, 88, 95

spanning-tree mode mst command, 72

spanning-tree mode pvst command, 72

spanning-tree mode rapid-pvst command, 72, 90

spanning-tree pathcost method long command, 55

spanning-tree portfast bpduguard default command, 95

spanning-tree portfast command, 75, 81, 95

spanning-tree portfast default command, 83, 95

spanning-tree portfast disable command, 83, 95

Spanning Tree Protocol. See STP

spanning-tree vlan 10 port priority 112 command, 103

spanning-tree vlan command, 74

speed command, 576

speeds

LAN/WAN interfaces, 490

leased-line WANs, 333-334

SPF (Shortest Path First) algorithm, 180

Dijkstra SPF, 180

OSPF best routes, calculating, 186-188

spinning up VMs, 742

split horizon (DV routing protocols), 230-231

spoofing, 422

SPs (service providers), 362

SSH (Secure Shell), 765

SSL (Secure Sockets Layer), 396-397

STA (spanning-tree algorithm), 48

stack masters, 157

stacking cables, 156

stacking modules, 156

stacking ports, 156

stacking switches

access layer switches, 156-157

benefits, 155

chassis aggregation, 159-161

FlexStack/FlexStack-Plus, 158

operating as single logical switch, 157-158

stack masters, 157

standard ACLs, configuring, 671-674

standard numbered IPv4 ACLs, 443

access-list command, 454

command syntax, 445

configuration examples, 448-452

list logic, 444-445

matching any/all addresses, 448

matching exact IP address, 445-446

matching subset of address, 446-447

overview, 443

reverse engineering from ACL to address range, 454-456

troubleshooting, 452-453

verification, 452-453

wildcard masks

binary wildcard masks, 447-448

decimal wildcard masks, 446-447

standard range VLANs, 123

standby 1 preempt command, 558

standby command, 554, 564

standby HSRP routers, 557

standby version 1 | 2 command, 564

standby version command, 559

stateful DHCP, troubleshooting, 608-609

stateful DHCPv6, 596

stateless address autoconfiguration. See SLAAC

states

change reactions (STP topology), 55-56

discarding, 61

interfaces

changing with STP, 57-58

criteria, 48-49

forwarding/blocking, 47

learning, 58

listening, 58

neighbors

BGP, 313

OSPF, 182-183, 186, 288

OSPFv3, 632

relationships, 628

ports

RSTP, 92-93

STP versus RSTP, 62

ROAS subinterfaces, 527

STP, 57

tunnel interfaces, 407

VLAN mismatched trunking operational, 116

static discard routes, 319-320

static routes (IPv6), configuring, 599

status

BPDU Guard global settings, 83

EIGRP neighbors, 233, 253

HSRP, 555

interface codes, 353

PortFast global settings, 83

PPP, 344

PPP CHAP, 345

PPP PAP, 346

PPPoE

Layer 3, 425

sessions, verifying, 424

STP verification, 75-77

steady-state operation (STP), 56

STP (Spanning Tree Protocol), 42

802.1D standard, 58

behind the scenes summary, 72

BIDs

defined, 49

root switch election, 50-52

system ID extensions, 73-74

BPDUs (bridge protocol data units), 49

BPDU Guard

configuring, 81

enabling/disabling, 83

global settings, displaying, 83

verifying, 82-83

Cisco Catalyst switch STP modes, 88-89

configuration, 71

modes, 72

options, 74-75

per-VLAN port costs, 74

PVST+, 72-73

system ID extensions, 73-74

convergence, 48, 105-106

EtherChannels, 64-65

configuring, 84-87

MAC tables impact, predicting, 111-112

troubleshooting, 106-109

forwarding or blocking criteria, 48-49

interface states, changing, 57-58

LAN redundancy, 42-46

LAN segment DPs, choosing, 54

looping frames, preventing, 44

MAC tables impact, predicting, 110

PortFast, 65

configuring, 81

enabling/disabling, 83

global settings, displaying, 83

verifying, 82-83

ports

blocking, choosing, 44

costs, 53, 78-79

states, 62

purpose, 47-49

roles, 57

root election influence, configuring, 80-81

root switch election, 50-52, 100-101

RSTP (Rapid STP), 58-59

alternate ports, 60-61

backup port role, 62-63

Cisco Catalyst switch RSTP modes, 88-90

implementing, 88

link types, 63

port roles, 91-92

port states, 92-93

port types, 63, 92

processes, 62

standards, 58

STP, compared, 59-60

security, 65-66

STA (spanning-tree algorithm), 48

states, 56-57

switch reactions to changes, 56-57

switch RPs, choosing, 52-53

tiebreakers, 102-103

timers, 56-57

topology influences, 55-56

troubleshooting

convergence, 105-106

DPs on LAN segments, 104-105

root switch election, 99-101

RPs on nonroot switches, 101-103

verification, 75-77

studying after failing the exam, 797-798

studying for exam, 798

subinterfaces

defined, 524

ROAS

creating, 524-525

numbers, 525

state, verifying, 527

subnet masks

mismatched masks, troubleshooting, 569-571

VLSM (variable length subnet masking)

overlapping subnets, 583-585

recognizing when VLSM is used, 581

subnets

advertising to ISPs, 318

IGPs, 303

IPv6, 593-594

mismatched

EIGRP neighbors, 286

leased-line WANs, 358

OSPFv2 multiarea configuration, 206

overlapping subnets

with VLSM, 583-585

without VLSM, 581-583

subset of IP address, matching, 446-447

successors

EIGRP

identifying, 257-258

for IPv4, 241-242

for IPv6, 646

feasible

convergence, 260-261

identifying, 258-260

super backbone (OSPF), 381

superior Hello, 50

supplicants, 145

SVIs (switched virtual interfaces), 520, 529

configuring, 529-531

troubleshooting, 532-534

verifying, 531

Switched Port Analyzer. See SPAN

switches

as 802.1x authenticators, 145

access layer, 156-157

adding, 137-139

chassis aggregation, 159

benefits, 161

design, improving, 160

distribution/core switches high availability, 159-160

switch stacking, 159-161

Cisco Catalyst

RSTP modes, 88-90

STP modes, 88-89

core, 159-160

distribution

design, improving, 160

high availability with chassis aggregation, 159-160

internal processing, 765-766

Layer 2, 21

Layer 3, 21

with routed ports, 534-537

VLAN routing, 23-24

Layer 3 EtherChannels

configuring, 537-539

troubleshooting, 541

verifying, 539-540

Layer 3 with SVIs

configuring, 529-531

troubleshooting, 532-534

verifying, 531

links, 63

logical, 157-158

nonroot, 101-103

PortFast, 65

QoS, 495

root

costs, 48

electing, 50-52

election influence, configuring, 80-81

ruling out switches, 100-101

STP verification, 77

troubleshooting, 99-101

RPs (root ports), choosing, 52-53

SPAN, 718

dependencies, 722

destination ports, 719

Encapsulated RSPAN (ERSPAN), 721

limiting sources, 725

local, 721-724

network analyzer needs, 719

Remote (RSPAN), 721

sessions, 720-721

source ports, 719

traffic direction, 725

VLANs, monitoring, 721

stacking

access layer switches, 156-157

benefits, 155

chassis aggregation, 159-161

FlexStack/FlexStack-Plus, 158

operating as single logical switch, 157-158

stack masters, 157

synchronization to VLAN database, verifying, 131-133

ToR (Top of Rack), 736

traditional access switching, 155

virtual (vSwitches), 735

voice switches, 34

as VTP servers, 124

switchport access vlan command, 25, 28-29, 37-40, 113, 135

switchport command

Layer 3 switches, 543

routed ports, 535

switchport mode access command, 25, 28, 37-38, 139

switchport mode command, 30, 40

switchport mode dynamic auto command, 116

switchport mode dynamic desirable command, 32

switchport mode trunk command, 30, 116, 524

switchport nonegotiate command, 34, 40, 116, 139

switchport trunk allowed vlan command, 41, 117

switchport trunk encapsulation command, 30, 40

switchport trunk native vlan command, 40, 118

switchport voice vlan command, 36-38, 41, 135

synchronizing

switches, 131-133

VTP, 125-126, 136-137

system ID extensions (BIDs), 73-74

T

T1. See leased-line WANs

T3, 334

TACACS+, 148

tagging (VLAN), 18-20

tail drops, 513

TCAM (ternary content-addressable memory), 766

T-carrier systems, 333

TCP (Transmission Control Protocol)

BGP connections, displaying, 313

packets, 675

port numbers, matching, 464-467

transporting messages between BGP peers, 310

windowing, 512-513

tcp keyword, 464

TCP/IP networks, 694

TDM (time-division multiplexing), 334

telcos (telephone companies), 331, 390

Telnet, 765

ternary content-addressable memory (TCAM), 766

testing IPv6

ACLs, 677

connectivity

hosts, 600-601

routers, 601-603

three-area OSPF, 189

TID fields (QoS marking), 501

tiebreakers (STP), 102-103

time burners, 785

time-division multiplexing (TDM), 334

time (exam)

budget versus number of questions, 785

checking, 786

time intervals (QoS shaping), 511-512

timers

EIGRP for IPv6, 652

EIGRP neighbors, 233

Hello messages, 184

Hello/dead mismatches, troubleshooting, 293-294

STP, 56-57

tools

APIC-EM ACL Analysis, 777

APIC-EM Path Trace ACL Analysis tool, 777-778

APIC-EM Path Trace app, 777

QoS

ACLs, compared, 496

classification, 495-498

congestion avoidance, 512-514

congestion management, 504-507

marking, 499-503

policing, 507-510

queuing strategy, 507

shaping, 507-512

Top of Rack (ToR) switches, 736

topologies

EIGRP

displaying, 255-257

feasible successor routes, 258-261

metrics, 262

successor routes, identifying, 257-258

EIGRP for IPv6, 657-658

MetroE, 366

full mesh, 368

hub and spoke, 369

partial mesh, 369

Point-to-Point, 367-368

OSPF area design, 188

STP, influences, 55-56

ToR (Top of Rack) switches, 736

ToS (Type of Service) field (IPv4), 499

traceroute command, 574

GRE tunnels, 406

IPv6

connectivity, testing, 600-602

network router problems, troubleshooting, 611

routes, testing, 614

traceroute6 command, 615

tracert command, 615

traditional access switching, 155

traffic

bandwidth, managing, 491

characteristics, 491

congestion avoidance, 512

TCP windowing, 512-513

tools, 513-514

congestion management, 504

Low Latency Queuing (LLQ), 505-507

multiple queues, 504

output queuing, 504

prioritization, 505

round robin scheduling, 505

strategy, 507

delay, managing, 491

end-user, measuring, 713

IPv6 ACLs, 670

jitter, 491

loss, 491

policing, 507

discarding excess traffic, 509

edge between networks, 509-510

features, 510

traffic rate versus configured policing rate, 508

public cloud branch office email services, 750-751

shaping, 507, 510

features, 512

slowing messages, 510

time intervals, 511-512

SPAN sessions, 725

types

data, 492-493

video, 494

voice, 378, 493-494

Traffic Class field (IPv6), 500

Transmission Control Protocol. See TCP

transparent mode (VTP), 135

Trap messages, 696-697

SNMPv2, 701-702

SNMPv3, 710-711

troubleshooting

CHAP authentication failures, 356

DPs on LAN segments, 105

EIGRP for IPv6

interfaces, 655

neighbors, 656-657

routes, 660

EIGRP interfaces, 275

configuration problems, 278-281

working details, 276-278

EIGRP neighbors

authentication failures, 286

example, 286-288

incorrect ASNs, 288

mismatched subnets, 286

verification checks, 285-286

EtherChannels, 106

channel-group command incorrect options, 106-108

configuration checks before adding interfaces, 108-109

GRE tunnels, 406

ACLs, 409-410

interface state, 407

Layer 3 issues, 409

source/destination addresses, 406

tunnel destination, 408

HSRP, 560

ACL blocks HSRP packets, 563

configuration, 560-561

group number mismatches, 563

misconfiguration symptoms, 561

routers configuring different VIPs, 563

version mismatches, 562

with IP SLA

counters, 715-716

history data, 717

IPv4 ACLs, 477

ACL behavior in network, 477-479

ACL interactions with router-generated packets, 483-485

common syntax mistakes, 481

inbound ACL filters routing protocol packets, 481-482

reversed source/destination IP address, 480-481

troubleshooting commands, 479-480

IPv4 routing

default router IP address setting, 572

DHCP issues, 573-574

DNS problems, 571-572

incorrect addressing plans, 581-585

IP forwarding issues, 577-580

LAN issues, 575-576

mismatched IPv4 settings, 568-569

mismatched masks, 569-571

packet filtering with access lists, 586

router WAN interface status, 585

IPv6 routing, 604

ACLs, 612

filtering issues, 604

host issues, 604

host pings fail from default router, 606-607

host pings only working in some cases, 605-606

missing IPv6 settings in host, 608-610

name resolution problems, 607-608

router issues, 604

routes, 640-641

routing, 611-612

Layer 3 EtherChannels, 541

leased-line WANs, 353-354

Layer 1 problems, 354

Layer 2 problems, 354-356

Layer 3 problems, 357-358

mismatched subnets, 358

neighbors, 285

OSPF

MTU mismatched settings, 296

processes, shutting down, 294-296

OSPF interfaces, 281-283

area design, 281

configuration errors, 282-283

details, checking, 283

unsolicited log messages, 283

OSPF neighbors, 288-294

area mismatches, finding, 290-291

duplicate RIDs, 291-293

Hello timer/dead timer mismatches, 293-294

LAN problems, 289

neighbor states, 288

OSPFv3

interfaces, 631-632

neighbors, 633-635

PAP authentication failures, 356

PPPoE, 425-426

customer router configuration, 426

dialer 2 status, 427

Layer 1, 427-428

Layer 2, 428-429

Layer 3, 429

summary, 430

ROAS, 528-529

routing protocols

configuration errors, 274

internetwork, analyzing, 273

neighbor relationships, 274

routing tables, 273

routing with SVIs, 532-534

RP problems, 103

SPAN sessions, 725

standard numbered ACLs, 452-453

STP

convergence, 105-106

DPs on LAN segments, 104-105

root switch election, 99-101

RPs on nonroot switches, 101-103

switch data plane forwarding

EtherChannel impact on MAC tables, 111-112

STP impact on MAC tables, 110

VLAN of incoming frames, 112-113

VLANs

access interfaces, 113-114

frame switching problems, 113

undefined/disabled VLANs, 114-115

VLAN trunking

frame switching problems, 113

mismatched native VLANs, 118

mismatched operational states, 116

mismatched supported VLAN lists, 117-118

VTP, 135

adding switches, 137-139

common configuration rejections, 137

synchronization, 136-137

trunking (VLANs)

802.1Q, 20-21

configuration, 30-34

disabling, 139

ISL (Inter-Switch Link), 20-21

overview, 18

protocol. See VTP

troubleshooting, 113-118

VLAN tagging, 18-20

trust boundaries (QoS marking), 501-502

trusted ports, 151

configuring, 153

DHCP snooping, 154

tunnel destination command, 406-408, 432

tunnel mode gre ip command, 404, 432

tunnel mode gre multipoint command, 404

tunnel source command, 406-407, 432

tunnels

destinations, 408

GRE, 398

between routers, 399

configuring, 402-404

details, displaying, 404

functionality, testing, 406

large scale environments, 411

multipoint with DMVPN, 411

point-to-point, 399

routes, 405

troubleshooting, 406-410

tunnel interfaces, 398

unsecured networks, 400-401

verifying, 404-406

interfaces

ACLs, 409-410

creating, 400

destinations, 408

Layer 3 issues, 409

replacing serial links, 398

state, 407

VPN, 394-395

tutorial (exam), 784-785

Twitter (Wendell Odom), 799

Type of Service (ToS) field (IPv4), 499

U

UCS (Unified Computing System), 733

UDP (User Datagram Protocol)

Jitter probes, 713

packets, IPv6 ACL matching, 675

port numbers, matching, 464-467

undebug all command, 298

undefined VLANs, troubleshooting, 114-115

unequal-cost load balancing, 263

UNI (user network interface), 365

unicast IPv6 addresses, 593-595

Unified Computing System (UCS), 733

unique local unicast addresses, 593

unsecured networks (GRE tunnels), 400-401

unsolicited log messages, 283

untrusted ports, 151-154

upd keyword, 464

updates

BGP, 303, 310

DV protocols, 229-230

EIGRP, 235-236

full, 229

partial, 232

periodic, 229

User Datagram Protocol. See UDP

user network interface (UNI), 365

username command, 345, 359

U.S. National Institute of Standards and Technology (NIST), 739

V

v1default MIB view, 706

variable length subnet masking. See VLSM

variables (MIB)

monitoring, 696

numbering/names, 697

variance (EIGRP), 263-264

variance command, 270

EIGRP for IPv4, 247, 263, 647

EIGRP for IPv6, 651, 662

vCPU (virtual CPU), 734

vector (DV protocols), 228

verification command, 75

verifying

BPDU Guard, 82-83

data and voice VLANs, 36-38

eBGP neighbors, 312-313

EIGRP configuration, 249

EIGRP enabled interfaces, finding, 250-252

IPv4 routing table, displaying, 253-254

neighbor status, displaying, 253

EIGRP for IPv6

interfaces, 654

routes, 659-660

EIGRP neighbors, 235, 285-286

EtherChannel configuration before adding interfaces, 108-109

GRE tunnels, 404-406

HDLC, 339

HSRP, 555-556

interarea OSPF routes, 212

IPv6 connectivity, 600

hosts, 600-601

routers, 601-603

Layer 3 EtherChannels, 539-540

MLPPP, 351-353

OSPFv2 configurations

interfaces, 219-221

multiarea, 210-212

single-area, 200-202

OSPFv3

interfaces, 630-631, 638-640

neighbors, 632-633

PortFast, 82-83

PPP

CHAP, 345-346

PAP, 347

PPPoE, 420-421

dialers, 421-422

Layer 3 status, 425

session status, 424

virtual-access interfaces, 423

ROAS, 526-527

routing protocol-enabled interfaces, 274

routing with SVIs, 531

SNMPv2 configuration, 702-704

SNMPv3 configuration, 708-709

standard numbered ACLs, 452-453

STP, 75-77

switches synchronization to VLAN database, 131-133

username/passwords on AAA servers, 145

versions

HSRP, 559-560

OSPF, 619

VTP, 127

video traffic

QoS requirements, 494

shaping time intervals, 512

views (MIB), 705

virtual-access interfaces, 423

virtual LANs. See VLANs

virtual machines. See VMs

virtual network functions (VNFs), 752-754

Virtual Private LAN Service (VPLS), 367

Virtual Private Networks. See VPNs

Virtual Private Wire Service (VPWS), 367

Virtual Router Redundancy Protocol (VRRP), 544

virtualization

ASA firewall (ASAv), 754

CPU (vCPU), 734

data centers

networking, 735

physical networks, 736

vendors, 735

workflow, 737-738

firewalls, 754

machines. See VMs

network functions virtualization (NFV), 754

networks, 735-736, 754

NICs (vNICS), 735

routers (public cloud networks), 754

servers, 734-735

hosts, 734

hypervisors, 734

multithreading, 734

networking, 736

virtual data center vendors, 735

VMs, 734

switches (vSwitches), 735

VLANs (virtual LANs)

configuration

data and voice VLANs, 36-38

database, VTP synchronization, 125-126

full VLAN configuration example, 25-28

overview, 24-25

shorter VLAN configuration example, 28-29

trunking, 30-34

database, switches synchronization, 131-133

default, 25

enabling/disabling, 115

IDs, 18

incoming frames, choosing, 112-113

interfaces. See SVIs

IP telephony, 34

data and voice VLAN concepts, 34-36

data and voice VLAN configuration and verification, 36-38

summary, 38-39

LAN support, adding, 122

mismatched native on trunks, 118

mismatched supported trunk lists, 117-118

native, 20, 525-526

overview, 16-18

routing. See VLAN routing

SPAN monitoring, 721

standard range, 123

tagging, 18-20

troubleshooting

access interfaces, 113-114

frame switching process problems, 113

undefined/disabled VLANs, 114-115

trunking

802.1Q, 20-21

configuration, 30-34

disabling, 139

ISL (Inter-Switch Link), 20-21

overview, 18

protocol. See VTP

troubleshooting, 113-118

VLAN tagging, 18-20

vlan 10 command, 122

vlan 200 command, 137

vlan command, 25, 37, 40, 135

VLAN routing, 21

Layer 3 EtherChannels

configuring, 537-539

troubleshooting, 541

verifying, 539-540

Layer 3 switch routed ports, 23-24, 534-537

Layer 3 switching with SVIs

configuring, 529-531

troubleshooting, 532-534

verifying, 531

ROAS, 524

configuration, 524-526

troubleshooting, 528-529

verifying, 526-527

routers, 21-23

VLAN Trunking Protocol. See VTP

VLSM (variable length subnet masking)

overlapping subnets, 583-585

recognizing when VLSM is used, 581

VMs (virtual machines), 734

ACI, 773

IaaS, 742

networking, 736

PaaS, 743-744

SaaS, 743

spinning up, 742

virtual NICs (vNICs), 735

VNFs (virtual network functions), 752-754

vNICs (virtual NICs), 735

voice switches, 34

voice traffic, 493

QoS requirements, 494

shaping time intervals, 512

VoIP, 378

VoIP (Voice over IP), 378, 493-494

VPLS (Virtual Private LAN Service), 367

VPNs (Virtual Private Networks)

client, 396-397

dynamic multipoint (DMVPN), 411

multipoint GRE tunnels, 411

NHRP (Next Hop Resolution Protocol), 412-413

Internet, 389

benefits, 394

security, 393

MPLS VPNs, 376

EIGRP challenges, 382

Layer 3, 379-382

OSPF area design, 381-382

public cloud, accessing, 747

site-to-site, 394-396

tunnels, 394-395

VPWS (Virtual Private Wire Service), 367

VRRP (Virtual Router Redundancy Protocol), 544

vSwitches (virtual switches), 735

VTP (VLAN Trunking Protocol), 29, 120

automated update powers, 120

configuration

common rejections, troubleshooting, 137

default VTP settings, 129

example, 130-131

new VTP configuration settings, 130

planning, 129

steps, 129

storing, 134-135

domains, 125-127

features, 128

pruning, 127-128

requirements, 126-127

servers, 124

standard range VLANs, 123

switches synchronization to VLAN database, verifying, 131-133

synchronization, 125

transparent mode, 135

troubleshooting, 135

adding switches, 137-139

common configuration rejections, 137

synchronization, 136-137

versions, 127

VLAN support, adding, 123

vtp commands, 134

vtp domain command, 134, 140

vtp mode command, 40, 134, 140

vtp mode off command, 29, 135

vtp mode transparent command, 29, 135

vtp password command, 134, 140

vtp pruning command, 134, 140

vtp version command, 140

W – Z

WANs

Ethernet, 747

Frame Relay, 362

interface speeds, 490

Internet access, 389

Internet as WAN service, 389

leased-line, 330-331

building, 335-336

CSU/DSUs, 334

mismatched subnets, 358

physical components, 332-333

speeds, 333-334

troubleshooting, 353-358

leased-line with HDLC, 336

configuring HDLC, 337-340

de-encapsulating/re-encapsulating IP packets, 336

framing, 336

leased-line with PPP

authentication, 342-343

configuring PPP, 343-344

configuring PPP CHAP, 344-346

configuring PPP PAP, 346-347

control protocols, 341

framing, 341

multilink. See MLPPP

PPP functions, 340

MetroE, 364

access links, 365

data usage, 373-375

E-LAN service, 368-372

E-Line service, 367-371

E-Tree service, 369-372

full mesh topology, 368

hub and spoke topology, 369

IEEE Ethernet standards, 366

Layer 3 design, 370-372

MEF, 366

partial mesh topology, 369

physical design, 365-366

Point-to-Point topology, 367-368

services, 366

MPLS, 375-377

access links, 378

Layer 3 design, 377

MPLS VPNs, 379-382

QoS, 378-379

VPNs, 376

private

public cloud access, 746-749

public cloud branch office connections, 751

types, 362

public cloud connections

Internet as, 745-746

private WANs, 746-749

service providers (SPs), 362

wireless, 392-393

WAN interface cards (WICs), 332

WC masks. See wildcard masks

websites

APIC-EM Analysis tool released code, 777

APIC-EM labs, 777

ARIN, 174

BGP routing table analysis reports, 303

CCNA (ICND2) Config Labs, 796

CCNA Routing and Switching ICND2 Official Cert Guide, 777

Cisco

ACI, 774

APIC-EM pages, 777

DevNet, 777

Feature Navigator, 531

Prime management products, 695

Eclipse IDE, 744

ETSI, 754

Google App Engine PaaS, 744

IANA, 174

ICMPv6 parameters, 669

IPv6 multicast address space registry, 682

ICMPv6 packets, 669

Jenkins continuous integration and automation tool, 744

MEF, 366

OpenDaylight SDN controller, 771

OpenFlow, 768

Pearson Network Simulator (the Sim), 796

Wendell Odom’s SDN Skills, 777

Wireshark network analyzer, 718

weighting, 505

Wendell Odom’s SDN Skills blog, 777

WICs (WAN interface cards), 332

wildcard_mask parameter (network command), 198

wildcard masks

binary, 447

decimal, 446-447

EIGRP configuration, 248-249

finding, 448

OSPF single-area configuration, 199

wireless Internet, 393

wireless WANs, 392-393

Wireshark network analyzer, 718

workflow (virtualized data center), 737-738

working interfaces, 49

write views (SNMPv3 groups), 706

..................Content has been hidden....................

You can't read the all page of ebook, please click here login for view all page.
Reset