ETExamTower
Q89Security

SIMULATION Guidelines This lab item requires tasks to be completed on virtual devices. - Use the **Tasks** tab to review the tasks for this lab item. - Use the **Topology** tab to access the device console(s) and complete the tasks. - Console access is available for every required device by selecting its device icon or the tab above the console window. - All required preconfigurations are already applied. - Do not modify the enable password or hostname on any device. - Save configurations to NVRAM before proceeding to the next item. - Select **Next** at the bottom of the screen to submit this lab and continue to the next question. - After **Next** is selected, the lab closes and cannot be reopened. Topology Tasks The operations team began configuring network devices for a new site. R10 and R20 are preconfigured with the CORP VRF, and R10 has network connectivity to R20. Complete the configuration to meet these objectives: 1. Extend the CORP VRF between R10 and R20 through Tunnel0. 2. Secure Tunnel0 with the preconfigured profile. <AnswerReveal answer={" "} explanation={"Configure Tunnel0 in VRF CORP on both routers, assign tunnel addresses 10.100.100.1/30 (R10) and 10.100.100.2/30 (R20), and use GRE protected by `myprofile`. R10’s tunnel source is e0/1 and destination is 10.10.2.1; R20’s tunnel source is e0/2 and destination is 10.10.1.1. The VRF assignment must precede tunnel IP addressing so the address remains configured."} />

Question exhibitQuestion exhibitQuestion exhibit
← → navigate · a answer
Discussion · 19
9
the ip vrf forwarding command should be the first command, since this usually removes the IP address, which will need to be added back again.
5
This config also needs static vrf routes, otherwise, traffic will not be routed through t0
4
[Task 1] R10(config)# interface Tunnel 0 R10(config-if)# ip vrf forwarding CORP R10(config-if)# ip address 10.100.100.1 255.255.255.0 R10(config-if)# tunnel source e0/1 R10(config-if)# tunnel destination 10.10.2.20 R10(config-if)# tunnel mode gre ip R20(config)# interface Tunnel 0 R20(config-if)# ip vrf forwarding CORP R20(config-if)# ip address 10.100.100.2 255.255.255.0 R20(config-if)# tunnel source e0/2 R20(config-if)# tunnel destination 10.10.1.10 R20(config-if)# tunnel mode gre ip [Task 2] R10(config-if)# tunnel protection ipsec profile MYPROFILE R20(config-if)# tunnel protection ipsec profile MYPROFILE
3
You don't need it. GRE is the default mode for a tunnel. "The default tunnel mode for a Cisco interface is "GRE" (Generic Routing Encapsulation), meaning that when you configure a tunnel interface, it will automatically be set to use GRE encapsulation unless explicitly specified otherwise"
3
I think the following static routes are missing: R10(config)#ip route vrf CORP 10.101.2.0 255.255.255.0 tunnel 0 R20(config)#ip route vrf CORP 10.100.1.0 255.255.255.0 tunnel 0
3
Correct, and it also needs two static routes: R10(config)#ip route vrf CORP 10.101.2.0 255.255.255.0 10.100.100.2 R20(config)#ip route vrf CORP 10.100.1.0 255.255.255.0 10.100.100.1
3
The exam I took last night had this sim, it has FINANCE vrf, you need to extend the VRF across the GRE, but the task never mentioned configuring VRF on the connected switch, where the VLAN222 is there, so please be careful and you do you need to extend the VRF to the downstream switch as well, which mean reconfig the p2p interface and the VLAN222. Also, out of 54 questions, only about half them were from here, the rest were new but related the topics here. About 15 questions were Wireless, at least 15 of them were Programming, 10 of them were SD-WAN/SD-Access, and finally some networking questions. Good luck all.
2
it does not say configure static route, only 2 task.
2
it not says configure static route, only 2 task
2
Had a similar sim on exams. The vrf was called FINANCE. First task was to extend vrf. The second task was to set static routes.
2
Sims were similar, but most of the questions were new
1
why need "tunnel mode gre ip" doesnt see this from question
1
it doesnt say configure static route on between R10 R20
1
tunnel dest should be 10.10.2.1 for R10 and 10.10.1.1 for R20.
1
disregard, dont know the ips for the interfaces.
1
Without those, the tunnel won't come up, so it stays unusable. I think we can assume that is not how it is supposed to stay.
1
How did the other sim / questions compare with the list here?
1
Just want to let everybody know there's a version of this question that doesn't provide the IPSEC Profile and the question doesn't explicitly say "create an ipsc profile" but when I got the results of the test, the "security" section of the test was only 20% out of 100%. I think there's a version of this question where they expect you to create the IPSEC Profile from scratch to protect the Tunneled Interface.
1
Ultimately, that is the real question... do you get penalized for doing something more than was explicitly asked for? Or do you get penalized for not doing something correctly, just because it wasn't stated in the question?