ETExamTower
Q16Services

Refer to the exhibit. An ISP offers shared VoIP Extranet services to a customer in VRF-100 with these settings: - The VoIP services are hosted in the 198.19.100.0/24 address space. - The customer is assigned the 198.18.1.0/29 IP address block. - VRF-100 has import and export route target 65010:100. Which configuration must the engineer apply on PE-1 to provision VRF-100 and enable access to the shared services?

Question exhibit
← → navigate · a answer
Community votes
D
60% (6)
B
40% (4)
A
0% (0)
C
0% (0)
Discussion · 19
7
[Option D] export and import reversed from PE3 vrf definition VRF-100 rd 172.17.255.1:100 ! address-family ipv4 route-target export 65010:100 route-target export 65010:1999 route-target import 65010:100 route-target import 65010:2999 exit-address-family
5
B also looks fine, vrf definition VRF-100 rd 172.17.255.1:100 address-family ipv4 export map VRF-100-EXPORT route-target import 65010:100 route-target import 65010:2999 exit-address-family route-map VRF-100-EXPORT permit 10 match ip address prefix-list VRF-100-ALLOWED-EXPORT set extcommunity rt 65010:100 65010:1999 route-map RF-100-EXPORT permit 20 set extcommunity rt 65010:100 ip prefix-list VRF-100-ALLOWED-EXPORT seq 5 permit 198.18.1.0/29 and it adds the shared community only on the 198.18.1.0/29 prefix:
B 4
Selected Answer: B B and D both will provide access, but D will also provide access to other customer prefixes that are not in the prefix range assigned to the customer
D 3
Selected Answer: D import/export map does not work without route-target import/export. It only further narrows what gets imported from route-target. https://www.cisco.com/c/en/us/td/docs/ios-xml/ios/mpls/command/mp-cr-book/mp-e1.html#wp2441555563 The import map command associates a route map with the specified VRF. You can use a route map to filter routes that are eligible for import into a VRF, based on the route target extended community attributes of the route. The route map might deny access to selected routes from a community that is on the import list. The import map command does not replace the need for a route-target import in the VRF configuration. You use the import map command to further filter prefixes that match a route-target import statement in that VRF.
D 2
Selected Answer: D D is CORRECT ccie_race explains it well, we need export and import opposite to PE3. Also, the question tells us: "VRF-100 is assigned import and export route target 65010:100." which is only configured on D
2
B. vrf definition VRF-100 rd 172.17.255.1:100 ! address-family ipv4 export map VRF-100-EXPORT route-target import 65010:100 route-target import 65010:2999 exit-address-family ! route-map VRF-100-EXPORT permit 10 match ip address prefix-list VRF-100-ALLOWED-EXPORT set extcommunity rt 65010:100 65010:1999 route-map VRF-100-EXPORT permit 20 set extcommunity rt 65010:100 ! ip prefix-list VRF-100-ALLOWED-EXPORT seq 5 permit 198.18.1.0/29
D 2
Selected Answer: D D. Acho que está certo.
2
And I would like to point out that the prefix list in Answer B does not account for longer prefixes. ip prefix-list VRF-100-ALLOWED-EXPORT seq 5 permit 198.18.1.0/29 What if the customer published 198.18.1.4/30 into BGP? 198.18.1.1/32?. The prefix would not match and would NOT export RT 65010:1999 The prefix list is missing "ge 29" attribute to allow longer matches. ip prefix-list VRF-100-ALLOWED-EXPORT seq 5 permit 198.18.1.0/29 ge 29 for that reason I vote D and not B
B 1
Selected Answer: B B is more accurate and takes the mentioned subnet 198.18.1.0/29 into account
1
I am stuck here: B - looks correct according to the Export Maps configuration and just for 198.18.1.0/29. D - looks correct according to the rt export and import policy. Any opinion ? :)
1
A. vrf definition VRF-100 rd 172.17.255.1:100 ! address-family ipv4 export map VRF-100-EXPORT import map VRF-100-IMPORT exit-address-family ! route-map VRF-100-EXPORT permit 10 match ip address prefix-list VRF-100-ALLOWED-EXPORT set extcommunity rt 65010:100 65010:2999 route-map VRF-100-EXPORT permit 20 set extcommunity rt 65010:100 ! route-map VRF-100-IMPORT permit 10 match extcommunity VRF-100-RT SHARED-SERVICES ! ip extcommunity-list standard SHARED-SERVICES permit rt 65010:1999 ip extcommunity-list standard VRF-100-RT permit rt 65010:100 ip prefix-list VRF-100-ALLOWED-EXPORT seq 5 permit 198.18.1.0/29
1
C. vrf definition VRF-100 rd 172.17.255.1:100 ! address-family ipv4 export map VRF-100-EXPORT route-target import 65010:100 route-target import 65010:1999 exit address-family ! route-map VRF-100-EXPORT permit 10 match ip address prefix-list VRF-100-ALLOWED-EXPORT set extcommunity rt 65010:100 65010:2999 route-map VRF-100-EXPORT permit 20 set extcommunity r 65010:100 ! ip prefix-list VRF-100-ALLOWED-EXPORT seq 5 permit 198.18.1.0/29 D. vrf definition VRF-100 rd 172.17.255.1:100 ! address-family ipv4 route-target export 65010:100 route-target export 65010:1999 route-target import 65010:100 route-target import 65010:2999 exit-address-family
B 1
Selected Answer: B Even though it does not explicitly ask us to send only the 198.18.1.0/29 route to the VoIP Shared Services VRF, it makes sense to do that, which is what we see in B. I changed my choice to B from D. D will make connectivity work, but it will also add other routes into the Shared Services VRF, which would not be advised.
1
While everything you said is correct, answer B doesn't use an import map. Your link shows that export map CAN be used by itself, so B still works.
B 1
Selected Answer: B Both B and D work. B is more complete, as it specifies the host network trying to reach shared services, so... i will go with B.
1
I noticed the import map in B does not account for longer prefixes. It should have had the ge 29 keyword like so: ip prefix-list VRF-100-ALLOWED-EXPORT seq 5 permit 198.18.1.0/29 ge 29. For that reason, I upvote D
1
Only the import-map does not work unless route-target import is present
D 1
Selected Answer: D We do have access to the shared services from VRF100, and nothing says anything about specific access from 198.18.1.0/29, so it should be D, not B.
D 1
Selected Answer: D D is the best fit for this need.