Q32Services
Refer to the exhibit. A network engineer is configuring router RB to protect BGP advertisements against route-hijacking activity. RB must validate all prefixes it receives from origin AS 200 before installing them in the BGP routing table. Which configuration fulfills this requirement?
← → navigate · a answer
Community votes
Discussion · 9
3
got this on the exam, 'D' is correct (you can ignore the typo here, it is correctly spelled on the exam)
D - is enabling the feature
A - is using it for best-path calculation
see:
https://www.cisco.com/c/en/us/support/docs/ip/border-gateway-protocol-bgp/217020-bgp-rpki-with-xr7-cisco8000-whitepaper.html
2
According to the link posted, it says:
To enable the router for as-origin validity check, activate this command for the concerned address family.
router bgp 100
address-family ipv4 unicast
bgp origin-as validation enable
!
Then it says:
When you ""activate this command"", it causes the router to scan the prefixes present in its BGP table against the ROA information received from the validator and one of the three states is assigned to prefixes .
RP/0/RP0/CPU0:Cisco8000#show bgp origin-as validity
!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!
In the exhibit you see the following CLI Command:
show bgp origin-as validity
This would mean the feature is already enabled, otherwise you won't be able to check/execute
show bgp origin-as validity
So, I would go for D.
2
https://www.cisco.com/c/en/us/support/docs/ip/border-gateway-protocol-bgp/217020-bgp-rpki-with-xr7-cisco8000-whitepaper.html
By default, the router gets ROAs from the validator but does not start using them until it is configured to do so. As a result, these prefixes are marked as ‘D’ or disabled...
To enable the router for as-origin validity checking, activate this command for the specific address family.
router bgp <#AS>
address-family ipv4 unicast
bgp origin-as validation enable
it makes the router scan the prefixes in its BGP table against the ROA information received from the validator and one of the three states is assigned to prefixes. To enable the router to use prefix validation state information while making the best path calculation, this command is needed.
router bgp <#AS>
address-family ipv4 unicast
bgp bestpath origin-as use validity
I would go for D, since it just needs to scan the prefix
1
i go for A. mismatch in the router name in the prompt
D 1
Selected Answer: D
this is the first command needed to use the requested feature
D 1
Selected Answer: D
This is not part of the Cisco SPCORE e-learning syllabus.
Based on the explanation, I will choose D
D 1
Selected Answer: D
Step-3: To let the router use prefix validation state information when doing the best path calculation, this command is required. It is not enabled by default, since it lets you choose not to use the validity information for best path calculation while still allowing you to use it in route policies, which are discussed later in this document.
router bgp 100
address-family ipv4 unicast
bgp bestpath origin-as use validity
!
RP/0/RP0/CPU0:Cisco8000#show bgp 203.0.113.0/24
Thu Jan 21 05:30:13.858 UTC
BGP routing table entry for 203.0.113.0/24
Versions:
Process bRIB/RIB SendTblVer
Speaker 31 31
Last Modified: Jan 21 00:03:33.344 for 05:26:40
https://www.cisco.com/c/en/us/support/docs/ip/border-gateway-protocol-bgp/217020-bgp-rpki-with-xr7-cisco8000-whitepaper.html
D 1
Selected Answer: D
Step-2: To enable the router for as-origin validity checking, turn on this command for the relevant address family.
router bgp 100
address-family ipv4 unicast
bgp origin-as validation enable
When you turn on this command, it makes the router compare the prefixes in its BGP table with the ROA information received from the validator, and one of the three states is assigned to prefixes .
RP/0/RP0/CPU0:Cisco8000#show bgp origin-as validity
Origin-AS validation codes: V valid, I invalid, N not-found, D disabled
Network Next Hop Metric LocPrf Weight Path
V*> 203.0.113.0/24 10.0.12.2 0 0 8100 ?
I* 203.0.113.1/24 10.0.12.2 0 0 8100 ?
N*> 192.168.122.1/32 10.0.12.2 0 0 8100 ?
D 1
Selected Answer: D
Step-1: By default, the router pulls ROAs (Route Origin Authorization) from the validator but does not start using them until it is set up to do so. Because of that, these prefixes are marked as ‘D’ or disabled.
RP/0/RP0/CPU0:Cisco8000#show bgp origin-as validity
Status codes: s suppressed, d damped, h history, * valid, > best
i - internal, r RIB-failure, S stale, N Nexthop-discard
Origin codes: i - IGP, e - EGP, ? - incomplete
Origin-AS validation codes: V valid, I invalid, N not-found, D disabled
Network Next Hop Metric LocPrf Weight Path
D*> 203.0.113.0/24 10.0.12.2 0 0 8100 ?
D*> 203.0.113.1/24 10.0.12.2 0 0 8100 ?
D*> 192.168.122.1/32 10.0.12.2 0 0 8100 ?