search for ccna answer

Tuesday, May 15, 2012

UCEN 3133 Advanced Computer Networks - Tutorial 3 - Year 2012

Tutorial 3 – MPLS Operation

1. A smaller autonomous system (AS) is defined inside the boundaries of a larger AS, and both of them employ MPLS to forward packets. A label switched path (LSP) has already been established from end-to-end between edge Label Switched Routers (LSRs) from the larger AS. This LSP tunnels through the smaller AS. In this scenario, what mechanism does MPLS provide in order to minimize routing information maintenance in the internal LSRs of the smaller AS ? Describe in detail how this mechanism works as a labelled packet is forwarded through the smaller AS.

MPLS uses a stack of labels.
  1. When a transit packet arrives with its own label corresponding to an external LSP, the ingress LSR of the smaller AS pushes a new label onto the label stack.
  2. This new label corresponds to an internal LSP within the smaller AS
  3. The internal LSRs of the smaller AS switch the packet through to the egress LSR, working only on the topmost label (the new label)
  4. At the egress LSR of the smaller AS, the new label is popped off the stack restoring original label.
  5. The packet resumes its travel using the original external LSP for the larger AS.


2. What is the motivation behind the use of Penultimate Hop Popping in an MPLS network ? Describe briefly how it works.

It provides a form of optimization to minimize the performance penalty incurred when the egress LSR of a MPLS network has to perform two lookup operations when processing a label stack. When a packet with a stack of two labels arrives at the penultimate LSR (the LSR before the egress LSR), it pops the top stack before forwarding it onwards to the last stack.

3. Distinguish between the independent and ordered control approach to exchanging labels in the Label Distribution Protocol (LDP).

Independent control - Each LSR advertises label mappings at will. In an unsolicited mode, LSRs will generally advertise new labels whenever the IP routing information changes.

Ordered control - In this mode,  all path advertisements originate at the egress router, and the label advertisement messages travel upstream to the ingress router. For advertisement on demand, a request from the ingress router triggers a chain of requests downstream to the egress router

4. Explain, with the aid of a diagram, how the liberal approach to label retention works in the LDP ? What advantage does the liberal approach offer over the conservative approach, and what is its corresponding disadvantage ?

It retains all label mappings even if they don’t correspond to an existing LSP.

  • Advantage: If the next hop path changes for the LSP, the given LSR  may already have a new LSP ready, so it can react to the routing change almost immediately. Whereas in conservative approach, the LSR will need to request label mappings first from alternative downstream LSRs in the neighbourhood.
  • Disadvantage: Larger mapping table space required to keep all the labels, as well as network overhead in label exchange when the number of neighbouring LSRs is very large.


5. Explain two approaches that could be employed to address the potential problem of loops in the label distribution protocol (LDP)

·         The hop count field in the label request message is incremented by all LSRs that the message passes through. If the hop count ever reaches a maximum value,  a loop has occurred and the LSR sends a LDP notification message to the originator of the message.
  • Path vectors - Each router inserts its own LSR ID in the path vector field of the message, and if it ever finds its own ID here in a newly received message, it breaks the loop


6. Name the two situations in which a LSR in the middle of a LSP may need to return an Internet Control Message Protocol (ICMP) error message to a datagram’s source. What is the problem with using ICMP in a Virtual Private Network (VPN) deployed using MPLS, and how is this addressed by the LSR that wishes to create the ICMP message ?

Two situations:
  • The datagrams hop limit may run out
  • The packet may encounter a problem in a link between routers (link broken, or datagram too large to be fragmented and sent over link)

In a VPN, only the egress router at the boundary of the VPN is able to access the source IP address. Other intermediate routers cannot access the source IP address (which is encrypted using IPSec), and hence cannot route the appropriate ICMP message back to the source.
This is addressed by creating a ICMP message and adding the original stack label from the packet that caused the error. This ICMP datagram will follow the route of the original packet to the egress router, who can then successfully route it back to its source.


7. How might a session initialization deadlock occur during the LDP of a MPLS ? Explain how this can be overcome using the LDP hello message.

As part of LDP, two LSRs may not be able to agree on parameters during session initialization. The propose / reject cycle could then continue indefinitely, causing a deadlock. This can be overcome by having the network administrator intervene and make the passive LSR accept the proposed session. To make the active LSR propose again, the passive LSR increments the configuration sequence number in its hello messages to the active LSR. 

Sunday, May 13, 2012

UCEN 3133 Advanced Computer Networks - Tutorial 2 - Year 2012

Tutorial 2 – MPLS Overview

1. Sketch the diagram of an Edge LSR (Label Switching Router). Identify 3 components that are important with respect to label switching at the periphery of an autonomous MPLS network, and briefly explain how they function.





     (i)            The Forwarding Information Base (FIB) is a standard IP forwarding table extended with labelling information. It allows labelled packets from within the MPLS core network to routed forwards as pure IP packets
   (ii)            Label Information Base (LIB) - holds all labels assigned by this LSR and the  mappings of these labels to labels received from any neighboring LSRs, during the process of label binding exchange.
 (iii)            Label Forwarding Information Base (LFIB) is used during the actual forwarding of labelled packets and holds only labels that are in use currently


2. Explain how labels can be useful as a preliminary measure  towards the enforcement of some form of QOS guarantee in a MPLS, making reference in your answer to Forward Equivalence Class (FEC)

Forwarding Equivalence Class (FECs) is a way of grouping incoming packets in some way so that all packets identified with a particular FEC are treated in the same manner, for example being switched over the same path (LSP). This allows some form of QOS to be enforced on the LSRs of the label switched path (LSP) that the packets flow through. Labels are associated with each particular FEC, and the FEC is established once at the entry of the IP packet into an ingress LSR.

3. Give examples of 3 items that can be used in classifying a Forward Equivalence Class (FEC)

     (i)            A specific source or destination IP network address
   (ii)            A specific class of traffic (e.g. interactive voice, streaming media) data within the packet
 (iii)            The particular interface on a router which the packet arrives on

4. Explain what is meant by label disposition or imposition with respect to an edge LSR.

Label imposition is the act of appending a label, or a stack of labels, to a packet in the ingress point of the MPLS domain. Label disposition is the act of removing the last label from a packet at the egress point before it is forwarded to a neighbor that is outside the MPLS domain.

5. Consider that an egress LSR in autonomous MPLS (AS 1) is communicating with its peer in another autonomous MPLS network (AS 2) using a suitable protocol (BGP for example). The process of negotiation between these peers results in a decision that exiting IP packets with a specific subnet prefix from the egress LSR in AS1 is to be routed along a specific Label Switched Path (LSP) in AS 2. Sketch an outline of how this might be accomplished using labels. What is the advantage of this approach ?

The ingress edge LSR at AS1 negotiates with the egress LSR of AS1, to append a label to all incoming packets into AS1. This label specifies that packets with a specific subnet prefix are meant to be switched immediately onwards to AS2 once they exit  from AS1. The AS1 ingress LSR builds a label stack by pushing another label corresponding to an LSP that terminates at the IP address of the AS1 egress LSR. This packet with two labels is forwarded along a LSP in AS1. All the other LSRs in the LSP in AS1 only perform switching on the top most label in the stack. Finally, at the egress LSR of AS1 this label is popped leaving the bottom label – which is used to forward the packet on to the ingress router of AS2

Monday, April 16, 2012

UCEN 3133 Advanced Computer Networks - Tutorial 1


1. Explain how connection oriented switching (as exemplified by technologies like ATM or MPLS) provides an advantage of speed over connectionless packet switching technologies (such as TCP/IP) ?

Connection oriented switching uses the label on a packet as an index into an internal table to forward the packets onwards. The process of indexing into a table is faster than searching a table (which is the mechanism used in routing), particularly when the indexing can be implemented in hardware
 
2. Describe briefly 4 underlying reasons why ATM was not adopted on a larger scale. What factor makes MPLS more attractive to a broader adoption in comparison to ATM ?

  1. Expense: ATM switches and NIC much more expensive than Ethernet: existing Ethernet equipment in IP networks could not be reused
  2. Connection set up latency: Since ATM is connection oriented, the packet request to set up a PVC has to pass through many switches before acknowledgment
  3. Cell overhead: the large ATM cell header provides a big overhead
  4. Specification of QOS requirements difficult: not all applications know beforehand the QOS that they require during a session.

MPLS was designed to build on top of the existing IP infrastructure (particularly layer 2 – Ethernet), rather than replace it completely – which makes it easier for companies with legacy IP infrastructure to migrate.

3. Explain how a Switched Virtual Circuit (SVC) established in an ATM network ?

  1. The host requiring a connection sends a  connection request to first ATM switch
  2. This ATM switch then finds path to destination and forwards request to all switches along path
  3. Each pair communicates with the next in sequence on path to choose matching VPI/VCI and store in respective tables.
  4. Only if all switches agree to establishing the SVC, is successful acknowledgement provided, otherwise request denied.
  5. The request setup SVC is done through signalling control and request messages, sent across reserved connections for control traffic


4. Briefly describe 3 advantages offered by switching across an IP infrastructure

  1. Faster forwarding because of indexing in place of routing table lookup
  2. Aggregated route information.  IP routing table look up once when packet arrives at edge router in ISP, and packet is assigned a label for further forwarding.
  3. Manage aggregate flows through a Service Level Agreement (SLA) easier with labels. Each label is equivalent to the Forward Equivalence Class (FEC)

5. Consider 2 hosts, X and Y,  in an ATM network with 3 intermediating ATM switches, A, B and C between them. The order of connection in a newly formed PVC is X -> A -> B-> C-> Y. Given below are the switching tables for all 3 switches:

Switch C

Old
VPI/VCI
Interface
New
VPI/VCI
0
0
5
1
0
3
2
1
2
3
1
4
4
2
1
5
0
0

Switch B

Old
VPI/VCI
Interface
New
VPI/VCI
0
1
0
1
0
5
2
0
4
3
0
1
4
2
2
5
0
3

Switch A

Old
VPI/VCI
Interface
New
VPI/VCI
0
0
5
1
0
1
2
1
3
3
2
2
4
0
4
5
1
0

Given that the VPI/VCI leading into Y has the value of 4, what is the value of the VPI/VCI at the initial end of X ?

Answer:

From Switch C table, the old VPI/VCI resulting in 4 going into Y is 3
From Switch B table, the old VPI/VCI resulting in 3 going into Switch C is 5
From Switch A table, the original VPI/VCI resulting in 5 going into Switch B is 0
Therefore, initial end of X has VPI/VCI of 0

Wednesday, August 10, 2011

CCNA Challenge iPhone and iPad App FREE DOWNLOAD

NetworkEquipment.net just went live with an iTunes application that is targeted to all Cisco network hardware users and is especially helpful to current and future Network Administrators, Systems Analysts, CIO's, etc.



The app, CCNA Challenge, is a fun brain teaser game that keeps the player's CCNA skill level sharp and can be used to prepare anyone for taking the CCNA exam. It was developed by a CCNA as an educational game for current CCNA's and aspiring CCNA's. CCNA Challenge can be played with no time limit to allow for beginners and those needing additional time to thoughtfully consider appropriate responses. It also has three speeds to add an additional challenge.



It has 10 different levels of 20 questions per level with all questions drawn randomly from a pool of over 2000 possible questions so the player will never get bored. This also prevents the player from memorizing the questions at any level and removing the challenge. CCNA Challenge rates the player so that an 80% successful completion rate is necessary to progress to the next level.


Those who use the timed challenge are rated at each successive level based on a combination of efficiency, quality, speed and attention. This allows any player to maximize the amount of knowledge and skill while progressing through the various levels. CCNA Challenge is available for free in the Lite version which consists of two levels of play, or in the Pro version for $1.99 which allows for an additional eight levels of play. The CCNA Challenge app also has a link to the NetworkEquipment.net website which contains a blog with valuable information about various networking issues.

There is also a surprise gift for those who successfully complete all 10 levels. NetworkEquipment.net, is a privately held company, that both buys and sells, out of channel, new and used network hardware, from Cisco Systems, Juniper Networks, Extreme Networks, Brocade Communications Systems, Redback Networks, Force10 Networks, F5 Networks and phone equipment, from Avaya and others. To find out more, please visit http://www.NetworkEquipment.net

DOWNLOAD AT http://itunes.apple.com/us/app/ccna-challenge-pro/id447047756?mt=8

Thursday, June 16, 2011

Many Malaysian Government Sites Hacked

Malaysia's Communications and Multimedia Commission said that 51 websites in the .gov.my domain were attacked beginning late Wednesday, and that 41 of the sites suffered various levels of disruption.



Shutdown Means Darkness For Most Government Websites
The MCMC, the country's Internet and telecommunications regulator, did not however provide information on the nature of the attacks, or the people behind it, describing them only as "unknown hackers".

However, it made references to some of the websites recovering quickly, suggesting that these sites faced a DDoS or distributed denial-of-service attack rather than a hack.

DDoS attacks can make a website inaccessible to users by swamping the website with traffic from hundreds or thousands of computers.

Such attacks are a known tactic of Anonymous, a hacker group that had threatened to attack Malaysia.

The MCMC had noticed a reduction in the levels of attack by 4 a.m. local time Thursday, it said. The attacks had little effect on Malaysian users, and most of the websites have already recovered, it said.

"We do not expect the overall recovery to these websites to take long," it said.

"The public is advised to report any information they may have regarding the identity of these hackers as the act to disrupt network services is a serious offence," it said.

Anonymous has used various online forums to threaten Malaysia with an attack in protest against the government's decision to block 10 websites that reportedly allowed the download of pirated content. Earlier this week, Anonymous invited people to join Operation Malaysia, targeting a government website from 7.30 p.m. GMT on Wednesday (3.30 a.m. Thursday, local time).


List of hacked Malaysia government website (16 June 2011, 11:26am):
http://moha.gov.my/-still cannot view
http://www.malaysia.gov.my/-still cannot view
http://www.kpdnkk.gov.my/-still cannot view
http://www.sabahtourism.com/-still cannot view
http://www.eghrmis.gov.my/-still cannot view (not sure if this because of attack)
http://penang.uitm.edu.my/-OK already
http://www.tourism.gov.my/-OK already
http://www.spr.gov.my/-OK already
http://www.bomba.gov.my/-OK already
http://www.jbiotech.gov.my/-OK already
https://ezi2care.jkm.gov.my/-Can only see Hello world from WordPress.
http://www.moe.gov.my/-OK already
http://www.cidb.gov.my/-OK already
http://www.treasury.gov.my/-OK already
http://www.kkr.gov.my/-OK already
http://www.penerangan.gov.my/-slow response (maybe because of DoS attack).
http://www.1malaysia.com.my/-slow response
http://www.parlimen.gov.my/-OK already.
http://www.rmp.gov.my/-OK already.
http://jpm.gov.my/-still cannot view
http://www.mocat.gov.my/-still cannot view.
http://www.nsc.gov.my/-OK already.
http://www.mohr.gov.my/-OK already.
http://www.kjc.gov.my/-still cannot view.
They’re also exposing 392 account details in Sabah Tourism site from over 3400 users. The data that posted online were email, addresses and passwords. It was defaced with words that include “Deface by Kambeng Merah: Credit to DarkJawa”.

Saturday, June 11, 2011

CCNA Exploration 1: Network Fundamentals – Chapter 11 Exam

01. Immediately after a router completes its boot sequence, the network administrator wants to check the routers configuration. From privileged EXEC mode, which of the following commands can the administrator use for this purpose? (Choose two.)
  • show flash
  • show NVRAM
  • show startup-config
  • show running-config
  • show version
02. Users in the network are experiencing slow response time when doing file transfers to a remote server. What command could be issued to determine if the router has experienced any input or output errors?
  • show running-config
  • show startup-config
  • show interfaces
  • show ip route
  • show version
  • show memory
03.Refer to the exhibit. A technician applies the configuration in the exhibit to a clean router. To verify the configuration, the technician issues the show running-config command in the CLI session with the router. What lines should the technician expect to see in the router output from the show running-config command?
* enable password class
  line console 0
  password ccna
* enable secret cisco
   enable password class
   line console 0
   password ccna
* enable secret 5 $1$v0/3$QyQWmJyT7zCa/yaBRasJm0
  enable password class
  line console 0
  password ccna
* enable secret cisco
  enable password 7 14141E0A1F17
  line console 0
  password 7 020507550A
* enable secret 5 $1$v0/3$QyQWmJyT7zCa/yaBRasJm0
  enable password 7 14141E0A1F17
  line console 0
04.Refer to the exhibit. A network administrator on HostA has problems accessing the FTP server. Layer three connectivity testing was successful from HostA to the S1 interface of RouterB. Which set of commands will allow the network administrator to telnet to RouterB and run debug commands?
* RouterB(config)# enable secret class
  RouterB(config)# line vty 0 4
  RouterB(config-if)# login
* RouterB(config)# enable secret class
  RouterB(config)# line vty 0 2
  RouterB(config-vty)# password cisco
  RouterB(config-vty)# login
* RouterB(config)# enable secret class
  RouterB(config)# line vty 0
  RouterB(config-line)# password cisco
  RouterB(config-line)# login
* RouterB(config)# enable secret class
  RouterB(config)# line aux 0
  RouterB(config-line)# password cisco
  RouterB(config-line)# login
* RouterB(config)# enable secret class
  RouterB(config)# line aux 0
  RouterB(config-vty)# password cisco
  RouterB(config-vty)# login
05.The connection between routers B and C has been successfully tested. However, after rebooting router C, the administrator noticed the response time between networks 10.10.3.0 and 10.10.4.0 is slower. Ping between the two routers is successful. A trace route indicates three hops from router B to router C. What else can be done to troubleshoot the problem?
  • Ping router B S0/1 connection from router C.
  • Trace the connection between router B to router C S0/1.
  • Issue a show ip route command in router B to verify routing is enabled.
  • Issue a show ip interface brief command on router C.
06. What command is used to change the default router name to Fontana?
  • Router# name Fontana
  • Router# hostname Fontana
  • Router(config)# name Fontana
  • Router(config)# hostname Fontana
07.The serial connection shown in the graphic needs to be configured. Which configuration commands must be made on the Sydney router to establish connectivity with the Melbourne site? (Choose three.)
  • Sydney(config-if)# ip address 201.100.53.2 255.255.255.0
  • Sydney(config-if)# no shutdown
  • Sydney(config-if)# ip address 201.100.53.1 255.255.255.224
  • Sydney(config-if)# clock rate 56000
  • Sydney(config-if)# ip host Melbourne 201.100.53.2
08.Refer to the exhibit. The output is shown for the show ip route command executed on Router A. What does the IP address 192.168.2.2 represent?
  • Gateway for the 192.168.1.0 network
  • Gateway for the 192.168.3.0 network
  • IP assigned to the serial port on Router A
  • IP assigned to the serial port on Router B
09.Refer to the exhibit. What additional command is required to allow remote access to this switch from hosts outside the local network?
  • NA-SW1(config-if)# no shutdown
  • NA-SW1(config)# enable password password
  • NA-SW1(config)# ip default-gateway address
  • NA-SW1(config-if)# description description
10. In a Cisco device, where is the IOS file stored prior to system startup?
  • RAM
  • ROM
  • Flash
  • NVRAM
11. When network services fail, which port is most often used to access a router for management purposes?
  • AUX
  • Ethernet

  • Console

  • Telnet

  • SSH

12. A network administrator needs to keep the user ID, password, and session contents private when establishing remote CLI connectivity with a router to manage it. Which access method should be chosen?
  • Telnet
  • Console
  • AUX
  • SSH
13. In a Cisco router, when do changes made to the running-configuration take effect?
  • after a system restart
  • as the commands are entered
  • when logging off the system
  • when the configuration is saved to the startup-configuration
14.Refer to the exhibit. Which names correctly identify the CLI mode represented by the prompt for Switch-East4#? (Choose two.)
  • line configuration mode
  • user executive mode
  • global configuration mode
  • privileged executive mode
  • interface configuration mode
  • enable mode
15. Which three terms correctly define the forms of help available within the Cisco IOS? (Choose three.)
  • hot keys
  • context-check
  • context-sensitive
  • structured check
  • command override
  • command syntax check
16. Which combination of keys would be used at the CLI prompt to interrupt a ping or traceroute process?
  • Ctrl-C
  • Ctrl-P
  • Ctrl-R
  • Ctrl-Shift-6
  • Ctrl-Z
17.Refer to the exhibit. What command will place the router into the correct mode to configure an appropriate interface to connect to a LAN?
  • UBAMA# configure terminal
  • UBAMA(config)# line vty 0 4
  • UBAMA(config)# line console 0
  • UBAMA(config)# interface Serial 0/0/0
  • UBAMA(config)# interface FastEthernet 0/1
18. On a Cisco router, which interface would be used to make the initial configuration?
Console

19.Refer to the exhibit. A student is responsible for the IP addressing, configuration and connectivity testing of the network shown in the graphic. A ping from host B to host C results in a destination unreachable but a ping from host B to host A was successful. What two reasons could account for this failure based on the graphic and partial router output for the Dallas router? (Choose two.)
  • The host A is turned off.
  • The Fa0/0 interface on Dallas is shutdown.
  • The LAN cable is disconnected from host B.
  • The S0/0/1 IP address of Dallas is improperly configured.
  • The Fa0/0 interface on Dallas is in a different subnet than host B.
  • The clock rate is missing on the serial link between Dallas and NYC.