CCNA: Routing and Switching Essentials
Skills Assessment Assessment – Student Training Training Exam Topology
Assessment O!ecti"es #art $: %nitiali&e 'e"ices (8 points, 5 minutes) #art (: Con)igure 'e"ice *asic Settings (28 points, 30 minutes) #art +: Con)igure Switch Security, -.ANs, and %nter/-.AN Routing (14 points, 15 minutes) #art 0: Con)igure OS#1"( 'ynamic Routing #rotocol (24 points, 25 minutes) #art 2: %mplement '3C# and NAT (13 NAT (13 points, 25 minutes) #art 4: Con)igure and -eri)y Access Control .ists 5AC.s6 (13 points, 25 minutes)
© 2013 2013 Cisco Cisco and/or and/or its affil affiliat iates. es. All All ri! ri!ts ts reser" reser"ed. ed. #!is #!is docu documen mentt is is Cisc Cisco o $u%l $u%lic. ic.
$ae $ae $ of $+
CCNA: Routing and Switching Essentials
SA Exam
Scenario &n t!is 'ills Assessment ('A) ou *ill confiure a small net*or. +ou *ill confiure routers, s*itc!es, and $Cs to support &$"4 connecti"it, s*itc! securit, and inter -A routin. +ou *ill t!en confiure t!e de"ices *it! '$"2, C$, and dnamic and static A#. Access control lists (AC-s) *ill %e applied for added securit. +ou *ill test and document t!e net*or usin common C-& commands t!rou!out t!e assessment.
Re7uired Resources •
3 outers (Cisco 141 *it! Cisco &' elease 15.2(4)3 uni"ersal imae or compara%le)
•
2 '*itc!es (Cisco 260 *it! Cisco &' elease 15.0(2) lan%ase imae or compara%le)
•
3 $Cs (7indo*s , ista, or 9$ *it! terminal emulation proram, suc! as #era #erm)
•
Console ca%le to confiure t!e Cisco &' de"ices "ia t!e console ports
•
:t!ernet and 'erial ca%les as s!o*n in t!e topolo
#art $: %nitiali&e 'e"ices Total points: 8 Time: 2 minutes
Step $: %nitiali&e and reload the routers and switches9 :rase t!e startup confiurations reload t!e de"ices. ;efore proceedin, !a"e our instructor "erif de"ice initiali
%OS Command
#oints
:rase t!e startup=confi file on all routers.
1> points (> point per router)
eload all routers.
1 > points (> point per router)
:rase t!e startup=confi file on all s*itc!es and remo"e t!e old -A data%ase.
2 points (1 point per s*itc!)
eload %ot! s*itc!es.
2 points (1 point per s*itc!)
erif -A data%ase is a%sent from flas! on %ot! s*itc!es.
1 point (> point per s*itc!)
%nstructor Sign/o)) #art $: #oints: o) 8
© 2013 Cisco and/or its affiliates. All ri!ts reser"ed. #!is document is Cisco $u%lic.
$ae ( of $+
CCNA: Routing and Switching Essentials
SA Exam
#art (: Con)igure 'e"ice *asic Settings Total points: (8 Time: +; minutes
Step $: Con)igure the %nternet #C9 Confiuration tass for t!e &nternet $C include t!e follo*in (efer to #opolo for &$ address information)? Con)iguration %tem or Task
Speci)ication
#oints
&$ Address
(1/2 point)
'u%net as
(1/2 point)
efault @ate*a
20.165.200.225
Note? &t ma %e necessar to disa%le t!e $C fire*all for pins to %e successful later in t!is la%.
Step (: Con)igure R$9 Confiuration tass for 1 include t!e follo*in? Con)iguration %tem or Task
Speci)ication
isa%le ' looup
#oints (1/2 point)
outer name
1
(1/2 point)
:ncrpted pri"ileed eec pass*ord
class
(1/2 point)
Console access pass*ord
cisco
(1/2 point)
#elnet access pass*ord
cisco
(1/2 point)
:ncrpt t!e clear tet pass*ords # %anner
(1/2 point) Bnaut!ori
(1/2 point)
'et t!e description &nterface '0/0/0
'et t!e -aer 3 &$"4 address. Bse t!e first a"aila%le address in t!e su%net.
(1/2 point)
'et t!e clocin rate to 128000 Acti"ate &nterface efault route
Confiure a default route out '0/0/0.
Note? o not confiure @0/1 at t!is time.
Step +: Con)igure R(9 Confiuration tass for 2 include t!e follo*in?
© 2013 Cisco and/or its affiliates. All ri!ts reser"ed. #!is document is Cisco $u%lic.
$ae + of $+
(1/2 point)
CCNA: Routing and Switching Essentials
SA Exam
Con)iguration %tem or Task
Speci)ication
isa%le ' looup
#oints (1/2 point)
outer name
2
(1/2 point)
:ncrpted pri"ileed eec pass*ord
class
(1/2 point)
Console access pass*ord
cisco
(1/2 point)
#elnet access pass*ord
cisco
(1/2 point)
:ncrpt t!e clear tet pass*ords
(1/2 point)
:na%le ##$ ser"er
(1/2 point)
# %anner
Bnaut!ori
(1/2 point)
'et t!e description &nterface '0/0/0
'et t!e -aer 3 &$"4 address. Bse t!e net a"aila%le address in t!e su%net.
(1 point)
Acti"ate &nterface 'et t!e description &nterface '0/0/1
'et t!e -aer 3 &$"4 address. Bse t!e first a"aila%le address in t!e su%net.
(1 point)
'et clocin rate to 128000 Acti"ate &nterface 'et t!e escription &nterface @0/0 ('imulated &nternet)
'et t!e -aer 3 &$"4 address. Bse t!e first a"aila%le address in t!e su%net.
(1 point)
Acti"ate &nterface &nterface -oop%ac 0 ('imulated 7e% 'er"er)
'et t!e description.
efault route
Confiure a default route out @0/0.
'et t!e -aer 3 &$"4 address.
Step 0: Con)igure R+9 Confiuration tass for 3 include t!e follo*in?
© 2013 Cisco and/or its affiliates. All ri!ts reser"ed. #!is document is Cisco $u%lic.
$ae 0 of $+
(1/2 point) (1/2 point)
CCNA: Routing and Switching Essentials
SA Exam
Con)iguration %tem or Task
Speci)ication
isa%le ' looup
#oints (1/2 point)
outer name
3
(1/2 point)
:ncrpted pri"ileed eec pass*ord
class
(1/2 point)
Console access pass*ord
cisco
(1/2 point)
#elnet access pass*ord
cisco
(1/2 point)
:ncrpt t!e clear tet pass*ords # %anner
(1/2 point) Bnaut!ori
(1/2 point)
'et t!e description &nterface '0/0/1
'et t!e -aer 3 &$"4 address. Bse t!e net a"aila%le address in t!e su%net.
(1/2 point)
Acti"ate &nterface &nterface -oop%ac 4
'et t!e -aer 3 &$"4 address. Bse t!e first a"aila%le address in t!e su%net.
(1/2 point)
&nterface -oop%ac 5
'et t!e -aer 3 &$"4 address. Bse t!e first a"aila%le address in t!e su%net.
(1/2 point)
&nterface -oop%ac 6
'et t!e -aer 3 &$"4 address. Bse t!e first a"aila%le address in t!e su%net.
(1/2 point)
efault route
Confiure a default route out '0/0/1.
(1/2 point)
Step 2: Con)igure S$9 Confiuration tass for '1 include t!e follo*in? Con)iguration %tem or Task
Speci)ication
isa%le ' looup
#oints (1/2 point)
'*itc! name
'1
(1/2 point)
:ncrpted pri"ileed eec pass*ord
class
(1/2 point)
Console access pass*ord
cisco
(1/2 point)
#elnet access pass*ord
cisco
(1/2 point)
:ncrpt t!e clear tet pass*ords # %anner
(1/2 point) Bnaut!ori
Step 4: Con)igure S+ Confiuration tass for '3 include t!e follo*in?
© 2013 Cisco and/or its affiliates. All ri!ts reser"ed. #!is document is Cisco $u%lic.
$ae 2 of $+
(1/2 point)
CCNA: Routing and Switching Essentials
SA Exam
Con)iguration %tem or Task
Speci)ication
isa%le ' looup
#oints (1/2 point)
'*itc! name
'3
(1/2 point)
:ncrpted pri"ileed eec pass*ord
class
(1/2 point)
Console access pass*ord
cisco
(1/2 point)
#elnet access pass*ord
cisco
(1/2 point)
:ncrpt t!e clear tet pass*ords # %anner
(1/2 point) Bnaut!ori
(1/2 point)
Step <: -eri)y network connecti"ity9 Bse t!e ping command to test connecti"it %et*een net*or de"ices. Bse t!e follo*in ta%le to met!odicall "erif connecti"it *it! eac! net*or de"ice. #ae correcti"e action to esta%lis! connecti"it if a test fails? 1rom
To
%# Address
#ing Results
#oints
1
2, '0/0/0
(1/2 point)
2
3, '0/0/1
(1/2 point)
&nternet $C
efault @ate*a
(1/2 point)
Note? &t ma %e necessar to disa%le t!e $C fire*all for pins to %e successful. %nstructor Sign/o)) #art (: #oints: o) (8
#art +: Con)igure Switch Security, -.ANS, and %nter -.AN Routing Total points: $0 Time: $2 minutes
Step $: Con)igure S$9 Confiuration tass for '1 include t!e follo*in?
© 2013 Cisco and/or its affiliates. All ri!ts reser"ed. #!is document is Cisco $u%lic.
$ae 4 of $+
CCNA: Routing and Switching Essentials
Con)iguration %tem or Task
SA Exam
Speci)ication
#oints
Create t!e -A data%ase
Bse #opolo -A De ta%le to create and name eac! of t!e listed -A'.
(1 point)
Assin t!e manaement &$ address.
Assin t!e -aer 3 &$"4 address to t!e anaement -A. Bse t!e &$ address assined to '1 in t!e #opolo diaram.
(1/2 point)
Assin t!e default=ate*a
Assin t!e first &$ address in t!e su%net as t!e default=ate*a.
(1/2 point)
orce trunin on &nterface 0/3
Bse -A 1 as t!e nati"e -A.
(1/2 point)
orce trunin on &nterface 0/5
Bse -A 1 as t!e nati"e -A.
(1/2 point)
Confiure all ot!er ports as access ports
Bse t!e interface rane command.
(1/2 point)
Assin 0/6 to -A 31
(1/2 point)
'!utdo*n all unused ports.
(1/2 point)
Step (: Con)igure S+9 Confiuration tass for '3 include t!e follo*in? Con)iguration %tem or Task
Speci)ication
#oints
Create t!e -A data%ase
Bse #opolo -A De #a%le to create eac! of t!e listed -A'. ame eac! -A.
(1 point)
Assin t!e manaement &$ address.
Assin t!e -aer 3 &$"4 address to t!e anaement -A. Bse t!e &$ address assined to '3 in t!e #opolo diaram.
(1/2 point)
Assin t!e default=ate*a
Assin t!e first &$ address in t!e su%net as t!e default=ate*a
(1/2 point)
orce trunin on &nterface 0/3
Bse -A 1 as t!e nati"e -A.
Confiure all ot!er ports as access ports
Bse t!e interface rane command.
(1/2 point) (1/2 point)
Assin 0/18 to -A 33
(1/2 point)
'!utdo*n all unused ports.
(1/2 point)
Step +: Con)igure R$9 Confiuration tass for 1 include t!e follo*in?
© 2013 Cisco and/or its affiliates. All ri!ts reser"ed. #!is document is Cisco $u%lic.
$ae < of $+
CCNA: Routing and Switching Essentials
SA Exam
Con)iguration %tem or Task Confiure 802.1E su%interface .31 on @0/1
Confiure 802.1E su%interface .33 on @0/1
Confiure 802.1E su%interface . on @0/1
Speci)ication
#oints
escription Accountin -A Assin -A 31.
(1 point)
Assin t!e first a"aila%le address to t!is interface. escription :nineerin -A Assin -A 33.
(1 point)
Assin t!e first a"aila%le address to t!is interface. escription anaement -A Assin -A .
(1 point)
Assin t!e first a"aila%le address to t!is interface.
Acti"ate &nterface @0/1
(1/2 point)
Step 0: -eri)y network connecti"ity9 Bse t!e ping command to test connecti"it %et*een t!e s*itc!es and 1. Bse t!e follo*in ta%le to met!odicall "erif connecti"it *it! eac! net*or de"ice. #ae correcti"e action to esta%lis! connecti"it if a test fails? 1rom
To
%# Address
#ing Results
#oints
'1
1, -A address
(1/2 point)
'3
1, -A address
(1/2 point)
'1
1, -A 31 address
(1/2 point)
'3
1, -A 33 address
(1/2 point)
%nstructor Sign/o)) #art (: #oints: o) $0
#art 0: Con)igure OS#1"( 'ynamic Routing #rotocol Total points: (0 Time: (2 minutes
Step $: Con)igure OS#1"( on R$9 Confiuration tass for 1 include t!e follo*in?
© 2013 Cisco and/or its affiliates. All ri!ts reser"ed. #!is document is Cisco $u%lic.
$ae 8 of $+
CCNA: Routing and Switching Essentials
SA Exam
Con)iguration %tem or Task
Speci)ication
#oints
'$ $rocess &
1
(1/2 point)
outer &
1.1.1.1
(1/2 point)
Bse classless net*or addresses Ad"ertise directl connected et*ors
Assin all directl connected net*ors to Area 0
'et all -A interfaces as passi"e
(1 point) (1 point)
C!ane t!e default cost reference %and*idt! to support @ia%it interface calculations
1000
'et t!e serial interface %and*idt!
128 D%/s
(1 point)
AdFust t!e metric cost of '0/0/0
Cost? 500
(1 point)
(1 point)
Step (: Con)igure OS#1"( on R(9 Confiuration tass for 2 include t!e follo*in? Con)iguration %tem or Task
Speci)ication
#oints
'$ $rocess &
1
(1 point)
outer &
2.2.2.2
(1 point)
Bse classless net*or addresses Ad"ertise directl connected et*ors
Note: mit t!e @0/0 net*or.
'et t!e -A (-oop%ac) interface as passi"e
(1 point) (1 point)
C!ane t!e default cost reference %and*idt! to allo* for @ia%it interfaces
1000
'et t!e %and*idt! on all serial interfaces
128 D%/s
(1 point)
AdFust t!e metric cost of '0/0/0
Cost? 500
(1 point)
(1 point)
Step +: Con)igure OS#1"( on R+9 Confiuration tass for 3 include t!e follo*in?
© 2013 Cisco and/or its affiliates. All ri!ts reser"ed. #!is document is Cisco $u%lic.
$ae = of $+
CCNA: Routing and Switching Essentials
SA Exam
Con)iguration %tem or Task
Speci)ication
#oints
'$ $rocess &
1
(1/2 point)
outer &
3.3.3.3
(1/2 point)
Bse classless net*or addresses Assin interfaces to Area 0 Ad"ertise directl connected et*ors
Bse a sinle summar address for t!e -A (loop%ac) interfaces.
'et all -A (-oop%ac) interfaces as passi"e
(1 point)
(1 point)
C!ane t!e default cost reference %and*idt! to support @ia%it interface calculations
1000
'et t!e serial interface %and*idt!
128 D%/s
(1 point) (1 point)
Step 0: -eri)y OS#1 in)ormation9 erif t!at '$ is functionin as epected. :nter t!e appropriate C-& command to disco"er t!e follo*in information? >uestion
Response
#oints
7!at command *ill displa all connected '$"2 routersG
(1 point)
7!at command displas a summar list of '$ interfaces t!at includes a column for t!e cost of eac! interfaceG
(1 point)
7!at command displas t!e '$ $rocess &, outer &, Address summari
(1 point)
7!at command displas onl '$ routesG
(1 point)
7!at command displas detail information a%out t!e '$ interfaces, includin t!e aut!entication met!odG
(1 point)
7!at command displas t!e '$ section of t!e runnin= confiurationG
(1 point)
%nstructor Sign/o)) #art +: #oints: o) (0
#art 2: %mplement '3C# and NAT )or %#"0 Total points: $+ Time: (2 minutes
Step $: Con)igure R$ as the '3C# ser"er )or -.ANs +$ and ++9 Confiuration tass for 1 include t!e follo*in?
© 2013 Cisco and/or its affiliates. All ri!ts reser"ed. #!is document is Cisco $u%lic.
$ae $; of $+
CCNA: Routing and Switching Essentials
SA Exam
Con)iguration %tem or Task
Speci)ication
#oints
eser"e t!e first 20 &$ addresses in -A 31 for static confiurations
(1 point)
eser"e t!e first 20 &$ addresses in -A 33 for static confiurations
(1 point) ame? ACC#
Create a C$ pool for -A 31
'='er"er? 10.10.10.11 omain=ame? ccna=s%a.com
(1 point)
'et t!e default ate*a. ame? :@ Create a C$ pool for -A 33
'='er"er? 10.10.10.11 omain=ame? ccna=s%a.com
(1 point)
'et t!e default ate*a.
Step (: Con)igure Static and 'ynamic NAT on R(9 Confiuration tass for 2 include t!e follo*in? Con)iguration %tem or Task Create a local data%ase *it! 1 user account
Speci)ication
#oints
Bsername? weuser $ass*ord? cisco$(+02
(1 point)
$ri"ilee le"el? $2
:na%le ##$ ser"er ser"ice
(1/2 point)
Confiure t!e ##$ ser"er to use t!e local data%ase for aut!entication
(1/2 point)
Create a static A# to t!e 7e% 'er"er
&nside @lo%al Address? (;=9$429(;;9((=
Assin t!e inside and outside interface for t!e static A#
(1 point) (1 point)
Access -ist? 1 Confiure t!e dnamic A# inside pri"ate AC-
efine t!e pool of usa%le pu%lic &$ addresses
Allo* t!e Accountin and :nineerin net*ors on 1 to %e translated.
(1 point)
Allo* a summar of t!e -As (loop%ac) net*ors on 3 to %e translated. $ool ame? %NTERNET $ool of addresses include?
(1 point)
(;=9$429(;;9((2 – (;=9$429(;;9((8
efine t!e dnamic A# translation
(1 point)
Step +: -eri)y '3C# and Static NAT9 Bse t!e follo*in tass to "erif t!at C$ and 'tatic A# settins are functionin correctl. &t ma %e necessar to disa%le t!e $C fire*all for pins to %e successful?
© 2013 Cisco and/or its affiliates. All ri!ts reser"ed. #!is document is Cisco $u%lic.
$ae $$ of $+
CCNA: Routing and Switching Essentials
Test
SA Exam
Results
#oints
erif t!at $C=A acHuired &$ information from t!e C$ ser"er
(1/2 point)
erif t!at $C=C acHuired &$ information from t!e C$ ser"er
(1/2 point)
erif t!at $C=A can pin $C=C. (1/2 point)
Note? &t ma %e necessar to disa%le t!e $C fire*all Bse a 7e% %ro*ser on t!e &nternet $C to access t!e 7 e% ser"er (20.165.200.22). -oin *it! Bsername? weuser , $ass*ord? cisco$(+02
(1/2 point)
Note? erification of dnamic A# *ill %e performed in $art 6. %nstructor Sign/o)) #art (: #oints: o) $+
#art 4: Con)igure and -eri)y Access Control .ists 5AC.s6 Total points: $+ Time: (2 minutes
Step $: Restrict access to -T? lines on R(9 Con)iguration %tem or Task Confiure a named access list to onl allo* 1 to telnet to 2.
Speci)ication AC- ame? A'@%N/@T
#oints (2 points)
Appl t!e named AC- to t!e #+ lines
(1 point)
erif AC- is *orin as epected,
(1 point)
Step (: Secure the network )rom %nternet tra))ic9
© 2013 Cisco and/or its affiliates. All ri!ts reser"ed. #!is document is Cisco $u%lic.
$ae $( of $+
CCNA: Routing and Switching Essentials
SA Exam
Con)iguration %tem or Task
Speci)ication
Confiure an :tended AC- to? •
•
AC- o.? $;$
Allo* &nternet !osts 777 access to t!e simulated *e% ser"er on 2 % accessin t!e static A# address (20.165.200.22) t!at ou confiured in $art 3.
#oints (2 points)
$re"ent traffic from t!e &nternet from pinin internal net*ors, *!ile continuin to allo* -A interfaces to pin t!e &nternet $C.
Appl AC- to t!e appropriate interface(s)
(1 point)
erif AC- is *orin as epected
rom t!e &nternet $C? •
•
(1 point)
$in $C=A ($ins s!ould %e unreac!a%le.) $in $C=C ($ins s!ould %e unreac!a%le.)
rom 1, $in t!e &nternet $C ($ins s!ould %e successful.) Note? &t ma %e necessar to disa%le t!e $C fire*all for pins to %e successful.
Step +: Enter the appropriate C.% command needed to display the )ollowing: Command 'escription
Student %nput 5command6
#oints
ispla t!e matc!es an access=list !as recei"ed since t!e last reset.
(1 point)
eset access=list counters.
(1 point)
7!at command is used to displa *!at AC- is applied to an interface and t!e direction t!at it is applied
(1 point)
7!at command displas t!e A# translationsG
Note? #!e translations for $C=A and $C=C *ere added to t!e ta%le *!en t!e &nternet $C attempted to pin t!ese $Cs in 'tep 2. $inin t!e &nternet $C from $C=A or $C= C *ill not add t!e translations to t!e ta%le %ecause of t!e *a t!e &nternet is %ein simulated on t!e net*or.
7!at command is used to clear dnamic A# translationsG
(1 point)
%nstructor Sign/o)) #art 0: #oints: o) $+
© 2013 Cisco and/or its affiliates. All ri!ts reser"ed. #!is document is Cisco $u%lic.
(1 point)
$ae $+ of $+