19.07.2013 Views

CCNP TSHOOT 6.0 - The Cisco Learning Network

CCNP TSHOOT 6.0 - The Cisco Learning Network

CCNP TSHOOT 6.0 - The Cisco Learning Network

SHOW MORE
SHOW LESS

You also want an ePaper? Increase the reach of your titles

YUMPU automatically turns print PDFs into web optimized ePapers that Google loves.

<strong>CCNP</strong>v6 <strong>TSHOOT</strong><br />

Section 1—Trouble Tickets and Troubleshooting Logs<br />

Task 1: Trouble Ticket Lab 9-3 TT-A<br />

Step 1: Review trouble ticket Lab 9-3 TT-A.<br />

As a security measure, your company has decided to implement stateful packet inspection using a <strong>Cisco</strong> IOS<br />

firewall on edge router R1. <strong>The</strong> firewall will allow traffic from external hosts only if it is a response to a<br />

legitimate request from an internal host. <strong>The</strong> only exception is that Internet access to the internal SRV1 webbased<br />

application will be allowed. Internal users should be able to access the Internet (simulated by Lo1 on<br />

R2) using various protocols, such as ICMP, FTP, Telnet, DNS, and HTTP. <strong>The</strong> firewall implementation must<br />

work in conjunction with the dynamic NAT currently being employed on R1. In addition, internal network<br />

devices must be able to obtain the correct time from the ISP (R2).<br />

You colleague has configured the firewall and the necessary access lists on R1. However, users on the office<br />

VLAN cannot access Internet websites, and remote users on the Internet cannot access the web-based<br />

application on SRV1. Your colleague has asked for your help in diagnosing and solving the problem.<br />

Step 2: Load the device trouble ticket configuration files for TT-A.<br />

Using the procedure described in Lab 3-1, verify that the lab configuration files are present in flash. Load the<br />

proper configuration files as indicated in the Device Configuration File table.<br />

Note: <strong>The</strong> following device access methods are in effect after loading the configuration files:<br />

• Console access requires no username or password.<br />

• Telnet and SSH require username admin and password adminpa55.<br />

• <strong>The</strong> enable password is ciscoenpa55.<br />

Device Configuration File Table<br />

Device Name File to Load Notes<br />

ALS1 Lab93-ALS1-TT-A-Cfg.txt<br />

DLS1 Lab93-DLS1-TT-A-Cfg.txt<br />

DLS2 Lab93-DLS2-TT-A-Cfg.txt<br />

R1 Lab93-R1-TT-A-Cfg.txt<br />

R2 Lab93-R2-TT-A-Cfg.txt<br />

R3 Lab93-R3-TT-A-Cfg.txt<br />

SRV1 N/A Static IP: 10.1.50.1<br />

Default gateway: 10.1.50.254<br />

PC-B N/A DHCP<br />

PC-C N/A DHCP<br />

Step 3: Configure SRV1.<br />

Configure SRV1 with static IP address 10.1.50.1/24 and default gateway 10.1.50.254.<br />

Step 4: Release and renew the DHCP lease on PC-B.<br />

a. Ensure that PC-B is configured as a DHCP client in the OFFICE VLAN.<br />

b. After loading all TT-A device configuration files, issue the ipconfig /release and ipconfig<br />

/renew commands on PC-B.<br />

All contents are Copyright © 1992–2010 <strong>Cisco</strong> Systems, Inc. All rights reserved. This document is <strong>Cisco</strong> Public Information. Page 4 of 16

Hooray! Your file is uploaded and ready to be published.

Saved successfully!

Ooh no, something went wrong!