判斷題

Acme is a small shipping company that has an existing enterprise network comprised of 2 
switches;DSW1 and ASW2. The topology diagram indicates their layer 2 mapping. VLAN 40 is a new VLAN that will be used to provide the shipping personnel access to the server. For security reasons, it is necessary to restrict access to VLAN 20 in the following manner: 
- Users connecting to ASW1’s port must be authenticate before they are given access to the network. -Authentication is to be done via a Radius server:
- Radius server host: 172.120.39.46
-Radius key: rad123 
- Authentication should be implemented as close to the host device possible. 
- Devices on VLAN 20 are restricted to in the address range of 172.120.40.0/24. 
- Packets from devices in the address range of 172.120.40.0/24 should be passed on VLAN 20. 
- Packets from devices in any other address range should be dropped on VLAN 20. 
- Filtering should be implemented as close to the server farm as possible. 
The Radius server and application servers will be installed at a future date. You have been tasked with implementing the above access control as a pre-condition to installing the servers. You must use the available IOS switch features.
 


您可能感興趣的試卷

你可能感興趣的試題

2.判斷題

Network topology exhibit: 
 


You work as a network administrator at . You study the network topology exhibit carefully. is a small 
company that has an existing enterprise network consisting of two switches named 1 and 2. The network topology schemata indicates their layer 2 mapping. VLAN 40 is a new VLAN that will be used to provide the shipping personnel access to the server. For security reasons, it is necessary to restrict access to VLAN 20 in the following manner: 
Users connecting to 1’s port must be authenticate before they are given access to the network. Authentication is to be done via a Radius server: 
Radius server host: 172.120.39.46 
Radius key: key 
Authentication should be implemented as close to the host device possible. 
Devices on VLAN 20 are restricted to in the address range of 172.120.40.0/24. 
Packets from devices in the address range of 172.120.40.0/24 should be passed on VLAN 20. 
Packets from devices in any other address range should be dropped on VLAN 20. Filtering should be implemented as close to the server farm as possible. 
The Radius server and application servers will be installed at a future date. You have been tasked with implementing the above access control as a pre-condition to installing the servers. You must use the available IOS switch features.

3.單項(xiàng)選擇題Which bridge ID belongs to switch 1? ()

A.32928 000d bd33 029b
B.24623 000f 34f5 039b
C.32928 000d bd03 029b
D.32768 000d bd33 029b
E.32769 000d 65db 01dd
F.32815 000d bd03 029b
G.None of the other alternatives apply

4.單項(xiàng)選擇題Which port state is interface Fa0/2 of switch 2 in for VLANs 1 and 160? ()

A.Listening
B.Learning
C.Disabled
D.Blocking
E.Forwarding
F.Discarding
G.None of the other alternatives apply

5.單項(xiàng)選擇題Which port role has interface Fa0/2 of switch 1 adopted for VLAN 47?()

A.Root port
B.Nondesigned port
C.Designated port
D.Backup port
E.Alternate port
F.None of the other alternatives apply

6.單項(xiàng)選擇題Which bridge ID belongs to switch 2? ()

A.32928 000d bd33 029b
B.24623 000f 34f5 039b
C.32928 000d bd03 029b
D.32768 000d bd33 029b
E.32769 000d 65db 01dd
F.32815 000d bd03 029b
G.None of the other alternatives apply

7.單項(xiàng)選擇題Which spanning Tree Protocol has been implemented on switch 2? ()

A.STP/IEEE 802.1D
B.MSTP/IEEE 802.1s
C.PVST+
D.PVRST
E.None of the other alternatives apply

9.判斷題

The network is displayed in the diagram below: 
 



You have just been hired by to help their main office expand. The main offices have enhanced their wiring closets with some Layer 3 switches. The new distribution layer switch has been installed and a new access layer switch cabled next to it. Your task is to configure the distribution layer and access layer 
switch with VTP to share VLAN information, then to configure inter-VLAN routing on the distribution layer switch to route traffic between the different VLANs that are configured on the access layer switches. 
VTP Domain Distribution 
VLAN Ids 20 31 
IP Addresses 172.16.71.1/24 172.16.132.1/24 
These are your specific tasks: 
1. Configure the VTP information with the distribution layer switch as the VTP server 
2. Configure the VTP information with the access layer switch as a VTP client 
3. Configure VLANs on the distribution layer switch 
4. Configure inter-VLAN routing on the distribution layer switch 
5. Specific VLAN port assignments will be made as users are added to the access layer switches in the future. 
6. All VLANs and VTP configurations are to completed in the global configuration 
To configure the switch click on the host icon that is connected to the switch be way of a serial console cable.

最新試題

Which two statements are true about BPDU port-guard and BPDU filtering?()

題型:多項(xiàng)選擇題

How are STP timers and state transitions affected when a topology change occurs in an STP environment?()

題型:單項(xiàng)選擇題

Refer to the exhibit. On the basis of the output of the show spanning-tree inconsistentports command, which statement about interfaces FastEthernet 0/1 and FastEthernet 0/2 is true?()

題型:單項(xiàng)選擇題

Which statement is correct about the use of the virtual interface on a WLC ?()

題型:單項(xiàng)選擇題

Refer to the exhibit. What command was issued on the Layer 3 switch Sw1 between Exhibit #1 and Exhibit #2?()

題型:單項(xiàng)選擇題

Refer to the exhibit. Switch 15 is configured as the root switch for VLAN 10 but not for VLAN 20. If the STP configuration is correct, what will be true about Switch 15?()

題型:單項(xiàng)選擇題

Refer to the exhibit. Which Virtual Router Redundancy Protocol (VRRP) statement is true about the roles of the master virtual router and the backup virtual router?()

題型:單項(xiàng)選擇題

Examine the diagram. A network administrator has recently installed the above switched network using 3550s and would like to control the selection of the root bridge.Which switch should theadministrator configure as the root bridge and which configuration command must theadministrator enter to accomplish this?()

題型:單項(xiàng)選擇題

Refer to the exhibit. For what purpose is the command show ip cef used?()

題型:單項(xiàng)選擇題

DS2 has not become the active device for Vlan103’s HSRP group even though all interfaces are active. As related to Vlan103’s HSRP group. What can be done to make the group function properly ? ()

題型:單項(xiàng)選擇題