Exam Code: ccnp 300 101 dumps (Practice Exam Latest Test Questions VCE PDF)
Exam Name: Implementing Cisco IP Routing
Certification Provider: Cisco
Free Today! Guaranteed Training- Pass 9tut ccnp 300 101 Exam.

Q11. What is the default OSPF hello interval on a Frame Relay point-to-point network? 

A. 10 

B. 20 

C. 30 

D. 40 

Answer:

Explanation: 

Explanation: Before you troubleshoot any OSPF neighbor-related issues on an NBMA network, it is

important to remember that an NBMA network can be configured in these modes of operation with the ip

ospf network command: Point-to-Point Point-to-Multipoint Broadcast NBMA The Hello and Dead Intervals

of each mode are described in this table: Hello Interval Dead Interval Network Type (secs) (secs) Point-to-

Point 10 40 Point-to-Multipoint 30 120 Broadcast 10 40 Non-Broadcast 30 120

Reference: http://www.cisco.com/c/en/us/support/docs/ip/open-shortest-path-first-ospf/13693- 22.html


Q12. A network engineer executes the show crypto ipsec sa command. Which three pieces of information are displayed in the output? (Choose three.) 

A. inbound crypto map 

B. remaining key lifetime 

C. path MTU 

D. tagged packets 

E. untagged packets 

F. invalid identity packets 

Answer: A,B,C 

Explanation: 

show crypto ipsec sa This command shows IPsec SAs built between peers. The encrypted

tunnel is built between 12.1.1.1 and 12.1.1.2 for traffic that goes between networks 20.1.1.0 and 10.1.1.0.

You can see the two Encapsulating Security Payload (ESP) SAs built inbound and outbound.

Authentication Header (AH) is not used since there are

no AH SAs.

This output shows an example of the show crypto ipsec sa command (bolded ones found in answers for

this question).

interface: FastEthernet0

Crypto map tag: test, local addr. 12.1.1.1

local ident (addr/mask/prot/port): (20.1.1.0/255.255.255.0/0/0) remote ident (addr/mask/prot/port):

(10.1.1.0/255.255.255.0/0/0) current_peer: 12.1.1.2

PERMIT, flags={origin_is_acl,}

#pkts encaps: 7767918, #pkts encrypt: 7767918, #pkts digest 7767918 #pkts decaps: 7760382, #pkts

decrypt: 7760382, #pkts verify 7760382 #pkts compressed:

0, #pkts decompressed: 0

#pkts not compressed: 0, #pkts compr. failed: 0,

#pkts decompress failed: 0, #send errors 1, #recv errors 0 local crypto endpt.: 12.1.1.1, remote crypto

endpt.: 12.1.1.2 path mtu 1500, media mtu 1500

current outbound spi: 3D3

inbound esp sas:

spi: 0x136A010F(325714191)

transform: esp-3des esp-md5-hmac ,

in use settings ={Tunnel, }

slot: 0, conn id: 3442, flow_id: 1443, crypto map: test sa timing: remaining key lifetime (k/sec):

(4608000/52) IV size: 8 bytes

replay detection support: Y

inbound ah sas:

inbound pcp sas:

inbound pcp sas:

outbound esp sas:

spi: 0x3D3(979)

transform: esp-3des esp-md5-hmac ,

in use settings ={Tunnel, }

slot: 0, conn id: 3443, flow_id: 1444, crypto map: test sa timing: remaining key lifetime (k/sec):

(4608000/52) IV size: 8 bytes

replay detection support: Y

outbound ah sas:

outbound pcp sas:

Reference: http://www.cisco.com/c/en/us/support/docs/security-vpn/ipsec-negotiation-ike- protocols/5409-

ipsec-debug-00.html


Q13. A router with an interface that is configured with ipv6 address autoconfig also has a link-local address assigned. Which message is required to obtain a global unicast address when a router is present? 

A. DHCPv6 request 

B. router-advertisement 

C. neighbor-solicitation 

D. redirect 

Answer:

Explanation: 

Autoconfiguration is performed on multicast-enabled links only and begins when a multicastenabled

interface is enabled (during system startup or manually). Nodes (both, hosts and routers) begin

the process by generating a link-local address for the interface. It is formed by appending the interface

identifier to well-known link-local prefix FE80 :: 0. The interface identifier replaces the right-most zeroes of

the link-local prefix. Before the link-local address can be assigned to the interface, the node performs the

Duplicate Address Detection mechanism to see if any other node is using the same link-local address on

the link. It does this by sending a Neighbor Solicitation message with target address as the "tentative"

address and destination address as the solicited-node multicast address corresponding to this tentative

address. If a node responds with a Neighbor Advertisement message with tentative address as the target

address, the address is a duplicate address and must not be used. Hence, manual configuration is

required. Once the node verifies that its tentative address is unique on the link, it assigns that link-local

address to the interface. At this stage, it has IP-connectivity to other neighbors on this link. The

autoconfiguration on the routers stop at this stage, further tasks are performed only by the hosts. The

routers will need manual configuration (or stateful configuration) to receive site-local or global addresses.

The next phase involves obtaining Router Advertisements from routers if any routers are present on the

link. If no routers are present, a stateful configuration is required. If routers are present, the Router

Advertisements notify what sort of configurations the hosts need to do and the hosts receive a global

unicast IPv6 address. Reference: https://sites.google.com/site/amitsciscozone/home/important-tips/ipv6/

ipv6-stateless- autoconfiguration


Q14. Which statement about the NPTv6 protocol is true? 

A. It is used to translate IPv4 prefixes to IPv6 prefixes. 

B. It is used to translate an IPv6 address prefix to another IPv6 prefix. 

C. It is used to translate IPv6 prefixes to IPv4 subnets with appropriate masks. 

D. It is used to translate IPv4 addresses to IPv6 link-local addresses. 

Answer:

Explanation: 


Q15. Refer to the exhibit. Which statement about the command output is true? 

A. The router exports flow information to 10.10.10.1 on UDP port 5127. 

B. The router receives flow information from 10.10.10.2 on UDP port 5127. 

C. The router exports flow information to 10.10.10.1 on TCP port 5127. 

D. The router receives flow information from 10.10.10.2 on TCP port 5127. 

Answer:

Explanation: 


Q16. Which PPP authentication method sends authentication information in cleartext? 

A. MS CHAP 

B. CDPCP 

C. CHAP 

D. PAP 

Answer:

Explanation: 


Q17. A network administrator is troubleshooting a DMVPN setup between the hub and the spoke. Which action should the administrator take before troubleshooting the IPsec configuration? 

A. Verify the GRE tunnels. 

B. Verify ISAKMP. 

C. Verify NHRP. 

D. Verify crypto maps. 

Answer:

Explanation: 


Q18. A network engineer executes the “ipv6 flowset” command. What is the result? 

A. Flow-label marking in 1280-byte or larger packets is enabled. 

B. Flow-set marking in 1280-byte or larger packets is enabled. 

C. IPv6 PMTU is enabled on the router. 

D. IPv6 flow control is enabled on the router. 

Answer:

Explanation: 

Enabling Flow-Label Marking in Packets that Originate from the Device This feature allows the device to

track destinations to which the device has sent packets that

are 1280 bytes or larger.

SUMMARY STEPS

1.enable

2.configure terminal

3.ipv6 flowset

4.exit

5.clear ipv6 mtu

DETAILED STEPS

Command or Action Purpose

Step 1 enable Enables privileged EXEC mode.

Enter your password if prompted.

Example:

Device> enable

Step 2 configure terminal Enters global configuration mode.

Example:

Device# configure

terminal

Step 3 ipv6 flowset Configures flow-label marking in 1280-byte or larger packets sent by the device.

Example:

Device# configure

terminal

Step 3 ipv6 flowset Configures flow-label marking in 1280-byte or larger packets sent by the device.

Example:

Device(config)# ipv6

flowset

Reference: http://www.cisco.com/c/en/us/td/docs/ios-xml/ios/ipv6_basic/configuration/15- mt/ip6b-15-mtbook/ip6-mtu-path-disc.html


Q19. A network engineer has set up VRF-Lite on two routers where all the interfaces are in the same VRF. At a later time, a new loopback is added to Router 1, but it cannot ping any of the existing interfaces. Which two configurations enable the local or remote router to ping the loopback from any existing interface? (Choose two.) 

A. adding a static route for the VRF that points to the global route table 

B. adding the loopback to the VRF 

C. adding dynamic routing between the two routers and advertising the loopback 

D. adding the IP address of the loopback to the export route targets for the VRF 

E. adding a static route for the VRF that points to the loopback interface 

F. adding all interfaces to the global and VRF routing tables 

Answer: A,B 

Explanation: 


Q20. An organization decides to implement NetFlow on its network to monitor the fluctuation of traffic that is disrupting core services. After reviewing the output of NetFlow, the network engineer is unable to see OUT traffic on the interfaces. What can you determine based on this information? 

A. Cisco Express Forwarding has not been configured globally. 

B. NetFlow output has been filtered by default. 

C. Flow Export version 9 is in use. 

D. The command ip flow-capture fragment-offset has been enabled. 

Answer:

Explanation: 

We came across a recent issue where a user setup a router for NetFlow export but was unable to see the

OUT traffic for the interfaces in NetFlow Analyzer. Every NetFlow configuration aspect was checked and

nothing incorrect was found. That is when we noticed the `no ip cef' command on the router. CEF was

enabled at the global level and within seconds, NetFlow Analyzer started showing OUT traffic for the

interfaces. This is why this topic is about Cisco Express Forwarding.

What is switching?

A Router must make decisions about where to forward the packets passing through. This decision-making

process is called "switching". Switching is what a router does when it makes the following decisions:

1.Whether to forward or not forward the packets after checking that the destination for the packet is

reachable.

2.If the destination is reachable, what is the next hop of the router and which interface will the router use to

get to that destination.

What is CEF?

CEF is one of the available switching options for Cisco routers. Based on the routing table, CEF creates its

own table, called the Forwarding Information Base (FIB). The FIB is organized differently than the routing

table and CEF uses the FIB to decide which interface to send traffic from. CEF offers the following

benefits:

1.Better performance than fast-switching (the default) and takes less CPU to perform the same task.

2.When enabled, allows for advanced features like NBAR

3.Overall, CEF can switch traffic faster than route-caching using fast-switching

How to enable CEF?

CEF is disabled by default on all routers except the 7xxx series routers. Enabling and Disabling CEF is

easy. To enable CEF, go into global configuration mode and

enter the CEF command.

Router# config t

Router(config)# ip cef

Router(config)#

To disable CEF, simply use the `no' form of the command, ie. `no ip cef`.

Why CEF Needed when enabling NetFlow ?

CEF is a prerequisite to enable NetFlow on the router interfaces. CEF decides through which interface

traffic is exiting the router. Any NetFlow analyzer product will calculate the OUT traffic for an interface

based on the Destination Interface value present in the NetFlow packets exported from the router. If the

CEF is disabled on the router, the NetFlow packets exported from the router will have "Destination

interface" as "null" and this leads NetFlow Analyzer to show no OUT traffic for the interfaces. Without

enabling the CEF on the router, the NetFlow packets did not mark the destination interfaces and so

NetFlow Analyzer was not able to show the OUT traffic for the interfaces. Reference: https://

blogs.manageengine.com/network-2/netflowanalyzer/2010/05/19/need-for-cef- in-netflow-data-export.html