Cisco Dumps Feedbacks

CCIE Written And Lab Feedbacks


CCIE RS Lab TS/DIAG++++/ CFG feedback

TS
The interface is not used, it takes 1 hour and 50 minutes.
Q1 the wrong point is the same as the version.
Q2 R3 is fully configured. You only need to modify the configuration of the R17
interface.
Q3 Only need to modify the ACL of R2
Q4 Same as the version.
Q5 Same as the version
Q6 Same as the version
Q7 Same as the version
Q8 the interface has a DHCP ACL and authentication open. My phenomenon cant
come out, and I can only delete the ACL. This question may be deducted.
Q9 Same as the TS version. By the way, Hong Kongs mouse sensitivity is too high, and
in terms of use, it is quite bad for me.
DIAG++++

According to the order of the questions, I checked the 10 minutes and did not find the
wrong point until the fourth question was distinguished, so the most important thing
when testing is “sinking”
CFG

First, check if ISE is connected and can log in.
Before eating, I knocked out NTP, log, 1.1, 1.2, 1.3, and everything went well.
After eating, directly knock out all parts of ISE. Then NGIPS, WSA. Then check the effect,
R1 and R2 can establish a neighbor, but the CTO value is 5000, restarting R1 and R2
does not work. There is an attempt to create a new object during the period. The
troubleshooting took 15 minutes but the result was not enough, then I changed the
rule, restarted to solve!

The next knock on the VPN is to follow the problem, in addition to 3.3 sitevrfb some
problems, R4 and R5 have neighbors, also announced the route of loopback200, but
the other party is not able to learn, check 5 minutes, no results, give up, continue down
knock.

About 1 hour from the exam, I knocked out all the exam questions, and the SW2 mab
and dot1x had no effect.

At 25 minutes from the end of the exam, SW2 still has no effect, restart SW2, this
operation is very dangerous and it is not recommended to try. After rebooting, I tested
the fail state of ASA1 and ASA2, the cluster of ASA3 and ASA4, EtherChannel, MABPC,
dot1xPC, wireless and PC.

After all the tests, there are still 3 minutes left until the end of the exam. Quietly waiting
for the end of the exam, waiting for the fate of the arrangement, but fortunately, this
time, lucky came to me.

Key tips:
Usually practice more, knock more TXT
(Thank you again, Teacher Chen, without your embarrassment more than once, I will
not have the luck of this time. At the same time, thank you, Mr. Zhong, for the phrase
""steady"" before the exam, which completely stabilized my heart.) Also, this time I went
to Shenzhen by train. From Hong Kong to Shenzhen, it took nearly 30 hours to take the
train. During this day, I re-trained the situation and the teacher’s video, summarized
it
again. At the same time, it also reveals my shortcomings that I usually practice fewer,
hope my bro will not make my mistakes.
Finally, I will spit out a sentence. The video of Mr. Zhong’s video is “The Winning
Book”, so be sure to check it over and over again.
Thank you again for your great support from the teachers and the brothers in the
group. Thank you, Mr. Zhong, thank you, Mr. Chen, thank you, Mr. Mi, insist, come on!



Do you know how to solve TS /CFG problems?

There are not many problems with the exam. I will Just write something I think I need to pay
attention to. with the help of SPOTO club, i pass the exam once. If you want to know more details,
you can consult SPOTO club where there are many professionals. I will provide comprehensive
dumps and clear solutions.

TS:
1. User 4 trace 10.4.40.40. Only when I come back to check, I find trace 10.4.40.40 timeout
suddenly. In the beginning, it is good. but It is ping, not trace. R40 trace usser4 also works. Finally,
I reload user4, then the phenomenon is restored. So, if you have a chance, you still have to look
at what you have done.
2.MPLS backup. The backup enterprise is required to go to DMVPN. I take half an hour to try to
do this. I discover that DMVPN will become the primary route if I can’t use some ways. There is
no default route-map on r14. I remember that the teacher advises us not to write route-map. So
give up. Finally, I change the configuration back. only r51 OS has a devolved default route in TS. In
65005, master and standby can be distinguished by setting default-information to originate
metric-type. Do not know how to distinguish between primary and secondary in 65001. There is
no route-map preset on r14.

CFG:
Layers 1 and 2 do require more attention. There is no SW mo acc, there is also the mouth of the
shutdown. Remember to take the time to check yourself.
2 many kids are missing. Take the time to look it up.
3.HSRP has been partially configured.
I want to give some confidence to many students like me who work full-time and have no time to
knock out the version on weekends. It is really important to watch the discussion in the group
and listen to the teachers teaching videos carefully. Many of the situations I encountered in the
exam room are solved in groups and by teachers. In addition, if there is no time for students, you
can try to take a week off work before the test or take participate in the model test. I always talk
to the teacher after the exam. My teacher has been very helpful to me. They help me understand
the test point. Finally, thank you very much for your help!



CCIE RS Lab solutions:TS2, DIAG2+, CFG 2+

Combination: TS2, DIAG2+, CFG 2+. Test location: BJ
Q1 Deny all by default, add one to release.
Q2 R14: next-version op-self
Q3 Did not solve it, give up decisively, R23 had a neighbor but did not receive the
route of 10.2.100/24, IGP checked no problem and BGP strategy was no problem,
too.
Q4 The demand has indeed changed, not SERVER1, but SERVER2, the solution is
consistent.
Q5 Change the network type of the tunnel to P2M. Note here that the R60
phenomenon map requires a route of 10.100.0.51. I didn’t pay attention to it for the
first time. There is a problem with the tunnel IP address of R51 (/32).
Q6 Do Redis OSPF in R15 ipv6.
Q7 R1 did not announce the IGP; the RT import of R3 had a problem, I checked
R4/R6 and changed it to the correct one.
Q8 D version CP snooping, add a trust, and then remove the lease of D version CP.
Q9 Tunnel key is wrong
Q10 Supplement the R24’s outside configuration and add R25 in parallel. (The
address of telnet is 123.45.67.89).

DIAG2+
Just starting this, it’s really awkward, I don’t know what to do. Because you can’t
easily click “next”, I probably guessed that the answer might be DIAG2. After the
next question, I found that I can take a step forward.
Look at the picture and see the configuration.
Found that R2 has no route, R3 has a route.
After looking at the topology, I found that this topology was the opposite of the
version 2+ topology. I subconsciously thought it was version 2, but later confirmed
that there was a problem with R2, which was DIAG2+; the problem with R3 was
DIAG2. Decisively chose the answer of DIAG2+.
The capture file has a link at the bottom of the test interface. After you click it, it
will come out (the same as the cloud version ark given by the teacher).
Here, I personally analyze where the capture is very embarrassing. Filtering with the
version SRPV6 first does not work. It is filtered out using the version srp later. I have
been looking for a long time, I am very embarrassed, I don’t know which one to
choose. Finally, I stared at the FE80 package. Note that it is the src column. Don’t
find the dst column, confirm it and choose it. (The one of the FE80 that I chose dst
at the beginning).

CFG 2+
When I got the version, I was so happy that it was so simple!
OSPF is basically pre-configured. When configuring DR/BDR, pay attention to “cle ip ospf pro”.
BGP is also full, the router-id can be added up.
All of Corenetwork’s VRFs don’t have RDs.
JacobsCorp’s VRF is also equipped with its own.
————Pick up your sleeves and do it!
Maybe I knocked too fast. When I was typing 2.4 EBGP, I did all of MPLS, VPNV4,
VRF, and RT (version Q, Main office). I admire myself and dare to do this. I suggest
that you don’t do this like me. In the end, you still have to slash all the way and
stabilize! Because it is in this process, I was added to the wrong point by the
teacher, and I will talk about it in detail later!
When I did DMVPN, I didn’t have any “fragile ingredients”. It was just a casual
down, just add IPSEC.
Today, BJ’s Andy teacher is too strict. I will elaborate on my experience with TR (I
remembered it three times at first, then calmly thought about it not only three
times).
The first place: The IGP of R15 is all gone. At this time, when I configured EBGP of
R15, I habitually checked the neighbors and configuration of IGP and found this
problem.

Note: Recovery after reconfiguration.
The second place: the IP address of R52 was changed (not pre-configured, because

I confirmed it is “up” when I configured).
Note: Recovery after reconfiguration.
The third place: the RD of the R52 was changed. Neighbors were all hanging, I
reconfigured them all.

Note: Recovery after reconfiguration.
The fourth place: R19’s DMVPN IPSEC strategy.
Note: Modify algorithm.
The fifth place: Multicast can’t come up. When I fix the configuration, I just added
the configuration, he removed it in the next second. (Change the global configuration of R17).
Note: Reconfigured, “shut” “no shut”, still does not work. In the end, I was
courageous and reloaded R17 directly. Restart the card for nearly 4 minutes,
fortunately, dmvpn is fine. Be sure to confirm the various configurations: Is the track
of IGP, NAT, SW3/SW4 recovered?
The sixth place: the EBGP status of R16 became idle.
Note: Recovery after reconfiguration.
Before the volume was handed over, I saved the windows one by one. I confirmed
the phenomena of the main and standby paths and the maps given by all the test
sites. But before the results came out, my heart was hung.
Finally, express my feelings, “Calmly take care of everything that happens, and have
a good mentality.” You have to understand the biscuit teacher’s problem-solving ideas.
Matters needing attention (personal position):
First, put the key equipment on the display, when all the configuration is checked,
put the key equipment in the lower part of the display and do a check in five
minutes! Avoid being TR and don’t know.
Second, the seat has two displays, it is recommended that you prepare for the split
screen operation during the preparation period. (Clicking on the device defaults to
the left screen, pulling all the questions to the right screen, making it a lot smoother)
Third, do not easily restart some important equipment, this is not recommended.
Because there are likely to be some unexpected situations!
Fourth, the night before the test, do not eat spicy food.
finally, I especially recommend the cert collection ccie rs dumps and very useful
for the exam.



Pass My CCIE Exam in first attempt. Exam combo: TS1, DIAG2, H3

Q1 The HSRP status is normal on SW400, ""port security"" is not enabled on SW410,
and ""IP address dhcp"" is provided on the port of User4.
Q2 The test does not increase the cost value of the SW111 to R14 ports, but reduces the
values of the SW111 to R15 ports.
Q3 Probably on R22, there is no ""originate"" attribute in ""route-map TE"". Fill in ""originate""
and keep in harmony with R23. When the SW210 ""ping 10.1.201.254""
has a route of ""10.1.113.X"", the phenomenon that I am out does
not seem to be this. Adding ""ip ospf cost 1"" on the R13 connection SW101
interface has an effect. Q4 R20, R21 ""route-map"" are written, the name is ""local-pref"", just hang up.
Q5 Change the ip address of R60 tunnel 0
Q6 Declare ""vlan2001"" on SW111, habitually plus ""ipv6 unicast-routing""
Q7 The announcement of lo0 was changed on R5, ""distance ospf external 210"" on R10
Q8 Add ""ip arp inspec trust"" to the port-channel port on SW311. Check that dhcp on R30
has ""lease 0 2"",no change.
Q9 Change tunnel 0 on R71, ""ip ospf net point-to-m""
Q10 Add an ""IP nat outside source static 201.99.70.2 201.99.25.70"" to the R25. First delete
an obvious error.
D2+ :(Same as SPOTO)

H2+

1.1 access ports
1.2 trunk
1.3 link bundling
1.4 Jamesons’s branch offices
Jameson’s IGP: DATA center does not allow LSA 2 to appear, requires ""passive vlan 101,
vlan100, vlan911"", with ""ospf id 1"", ""router-id lo0"". The ospf of the AS65001 area
seems to be all configured. Only R9 and R10 are not configured. After checking the Router
id and other related information, the next step is taken.
Other AS65002 areas are also configured, but the ""network"" method is used.
R11-R14 is equipped with ""default-information originate"", but the requirement is
""must always advertise"", so all changes to ""default-information originate"" Always"".
I did not see the DR/BDR requirements. Know that you are used to configuring mpls in
this step. All related ports are configured with ""mpls ip"", including the ""AS65006"" area,
but you must use lo0 to establish neighbor relationships. I have looked at all devices,
""show run | se mpls"" I didnt find ""mpls label pro ldp"" and ""mpls ldp router lo0"", so I
brushed it all over.
Jacobs’ IGP: I did not see the mandatory requirement of the name JACOBS, nor did I
view the phenomenon diagram of ""52.52.52.52/32"" on the R50, but there is a
phenomenon diagram on R9 and R10, ""show ip route 52.52.52.52"". Upgrade eigrp
protocol to naming mode, redistribute lo52 on R52. Other operations as usual.
Redistribution requirements on R9/R10: The above said that in order to reduce the
""operational cost"", do not use ""access-list, ip prefix, route-map"". So as usual.
R57: BGP has been configured on R57, there is ""redistribute eigrp 10"", I deleted it.
BGP: All routers in the AS65001 area have made protocols, but none of them have been
configured with ""router id"". I did ""address ipv4"" on R1, so it is more obvious to see the
ipv4 route reflector. In fact, it is more convenient to see all the phenomena on R1. You
can see all the vpnv4 routing entries returned by PE devices. It is much more convenient
to see on R11-R14. You can also check if RD is mismatched. All RDs are Need to make
up for yourself, the port is also.
AS65006 needs to delete ""router bgp 65006"" and use ""router bgp 65001"". It is required
that the configuration on the CE device cannot be changed. What else is there for NLRI?
If you cant change the configuration of the CE device, you wont be entangled. All delete
""router bgp 65006"", there is no requirement for R50, R51, R52 to establish igp relationship.
The configuration of my R50-R52 is consistent with that of R3-R8, all equipped with ""ipv4
next-hop-se"".
The address on R52 is wrong.
IPv6: SW3, SW4 and Lo0 have no ipv6 address, vlan 173 and R17 e0/1 have ipv6 address,
but the requirement is to use ospfv3 only on SW3-4, R15-16, so you know.
It’s a tough experience to prepare CCIE, but it’s my lucky to choose SPOTO to pass
my exam at first time.



My exam combo: TS2 DIAG2+ H2+TS2

Q1 The HSRP status is normal on SW400, ""port security"" is not
enabled on SW410, and ""IP address dhcp"" is provided on the port of User4.
Q2 The test does not increase the cost value of the SW111 to R14 ports but reduces the values of the SW111 to R15 ports.
Q3 Probably on R22, there is no ""originate"" attribute in ""route-map TE"".
Fill in ""originate"" and keep in harmony with R23. When the SW210 ""ping 10.1.201.254"" has a
route of ""10.1. 113.X"", the phenomenon that I am out does not seem to be this. Adding ""ip
ospf cost 1"" on the R13 connection SW101 interface has an effect.
Q4 R20, R21 ""route-map"" are written, the name is ""local-pref"", just hang up.
Q5 Change the ip address of R60 tunnel 0
Q6 Declare ""vlan2001"" on SW111, habitually plus ""ipv6 unicast-routing""
Q7 The announcement of lo0 was changed on R5, ""distance ospf external 210"" on R10
Q8 Add ""ip arp inspec trust"" to the port-channel port on SW311. Check that dhcp on R30 has
""lease 0 2”, no change.
Q9 Change tunnel 0 on R71, ""ip ospf net point-to-m""
Q10 Add an ""IP nat outside source static 201.99.70.2 201.99.25.70"" to the R25. First delete an
obvious error.

D2+ :(Same as SPOTO)

H2+
1.1 access ports
1.2 trunk
1.3 link bundling
1.4 Jamesons’s branch offices
Jameson’s IGP: DATA center does not allow LSA 2 to appear, requires ""passive vlan 101,
vlan100, vlan911"", with ""ospf id 1"", ""router-id lo0"". The ospf of the AS65001 area seems to
be all configured. Only R9 and R10 are not configured. After checking the Router id and other
related information, the next step is taken. Other AS65002 areas are also configured, but the
""network"" method is used. R11-R14 is equipped with ""default-information originate"", but
the requirement is ""must always advertise"", so all changes to ""default-information originate"" Always"".
I did not see the DR/BDR requirements. Know that you are used to configuring mpls in this
step. All related ports are configured with ""mpls ip"", including the ""AS65006"" area, but you
must use lo0 to establish neighbor relationships. I have looked at all devices, ""show run | se
mpls"" I didnt find ""mpls label pro ldp"" and ""mpls ldp router lo0"", so I brushed it all over.
Jacobs’ IGP: I did not see the mandatory requirement of the name JACOBS, nor did I view
the phenomenon diagram of ""52.52.52.52/32"" on the R50, but there is a phenomenon
diagram on R9 and R10, ""show ip route 52.52.52.52"". Upgrade eigrp protocol to naming mode, redistribute lo52 on R52. Other operations as usual.
Redistribution requirements on R9/R10: The above said that in order to reduce the ""operational cost"", do not use ""access-list, ip prefix, route-map"". So as usual.
R57: BGP has been configured on R57, there is ""redistribute eigrp 10"", I deleted it.
BGP: All routers in the AS65001 area have made protocols, but none of them have been
configured with ""router id"". I did ""address ipv4"" on R1, so it is more obvious to see the ipv4
route reflector. In fact, it is more convenient to see all the phenomena on R1. You can see
all the vpnv4 routing entries returned by PE devices. It is much more convenient to see on
R11-R14. You can also check if RD is mismatched. All RDs are Need to make up for yourself,
the port is also.
AS65006 needs to delete ""router bgp 65006"" and use ""router bgp 65001"". It is required that
the configuration on the CE device cannot be changed. What else is there for NLRI? If you
cant change the configuration of the CE device, you wont be entangled. All delete ""router
bgp 65006"", there is no requirement for R50, R51, R52 to establish igp relationship. The
configuration of my R50-R52 is consistent with that of R3-R8, all equipped with ""ipv4 next-
hop-se"".
The address on R52 is wrong.
IPv6: SW3, SW4 and Lo0 have no ipv6 address, vlan 173 and R17 e0/1 have ipv6 address, but
the requirement is to use ospfv3 only on SW3-4, R15-16, so you know.
It’s a tough experience to prepare CCIE, but it’s my lucky to choose SPOTO to pass my
exam at first time.


TS2 DIAG H3++ CFG H1+

Q1
No 10
No 30
Ospf: no passive interface
Dhcp: change to infinite because lease is short

Q2
SW 111: ospf cost is 100
It deleted

Q3

This problem did not go well.
TE will succeed by changing origin.
However, the displayed AS-path was not displayed
My result was that the AS number of the third hop was 19999.
But the question was AS number 65002.

Q4
the content of BGP was that it did not touch.
I changed the route by setting the OSPF cost of R20 Lo 0  is 0 to   100.

Q5
R60 subnet is different. / 32 / 24

Q6
VLAN 111 was not advertised to OSPFv 3 by SW 111.

Q7
The process ID of OSPF was different for R1 Lo 0.
In R 10 ospf  external was 19.
It changed to 201.

 There were things
I was wasted in in ignoring.
There was a router with mpls ldp router-id lo 0 and mpls label  protocol ldp set in R1 - R6, and a router not configured.

The route-target imports its own export
I was worried about  changing.
However, it was described as separete 2 faults in the problem
sentence, and traceroute was the result that was requested and I
ignored it.

Q8
SW 300/301: vlan 2000 & 2001 ip dhcp relay information trust
SW 310: ip arp inspection
Dhcp: change to infinite because lease is short

Q9
Ospf network type is change

Q 10
Nat pool was set up.
I set up the ip nat outside source static 201.99.70.2 . . .  
Command on R24 and R25 and it was able to telnet.

DIAG H3++ same   as spoto solutions

CFG H1+ same


TS1 DIAG H2++ CFG H1+

TS1
1 - ACL on SW1

2- ppp and chap config on R17

3- R22 interface was not in OSPF,
some problem on R5

4- very simple, just R12 with a shut interface

5- always takes me forever.
I changed many things.
R22 had bad RID for Ospf,
R3 had no ospf Nei towards R21

6- Simple fix to next hop

7- R18 had ACL on serial interface and was missing some nhrp commands. All routers needed shortcut, R15 needed redirect

8- Fixed LDP between R1/2,
bad nat on R8, added cost for interface E2/0 on R4/6,
fixed dhcp problem on R104

9- R21 had ACL that needed fixing,
R24 had bad encryption for tunnel,
R23 had bad NAT

10- fixed dhcp config on NAS
Diag  H2++ - same as spoto

CFG H1+ - looked like spoto .
I couldn't solve ssh  R20, did everything as per solution but ssh  was denied

Couldn't remember encryption commands for DMVPN tunnel on VRF Trace  
routes worked beautifully Really ran out of time but happy I made it


CCIE DUMPS TAGS:

ccie sp written vce cisco certification ccie security ccie service provider books pdf ccie service provider average salary how to get cisco ccie ccie wireless version 3 lab last date cisco ccie qos book ccie r&s written dumps certcollection ccie security v5 advanced technologies ine ccie routing & switching written v5