  1. Hi guys, Still trying to find the topologies for TS, DIAG, CFG and found them but without initial configs. Could tell me please, is it possible to get initial configs? I saw some posts and links where says its with initial configs but after uploading to UNL there is nothing overthere. May be I do something wrong? Please, advice or share any useful link for that. Good luck for getting numbers to everyone!
  2. Hi All, Is there any document for the order of operation for DMVPN with IPSEC like this document? Inside-to-Outside Outside-to-Inside If IPSec then check input access list decryption – for CET (Cisco Encryption Technology) or IPSec check input access list check input rate limits input accounting policy routing routing redirect to web cache NAT inside to outside (local to global translation) crypto (check map and mark for encryption) check output access list inspect (Context-based Access Control (CBAC)) TCP intercept encryption Queueing If IPSec then check input access list decryption – for CET or IPSec check input access list check input rate limits input accounting NAT outside to inside (global to local translation) policy routing routing redirect to web cache crypto (check map and mark for encryption) check output access list inspect CBAC TCP intercept encryption Queueing
  3. Question: Ping from R3 R3# ping Elaborate your solution step by step. NETMAP ----------- 1:0/0 2:0/0 2:0/1 3:0/1 R1 ---- hostname R1 interface Loopback0 ip address interface Loopback1 ip address secondary ip address secondary ip address interface Ethernet0/0 ip address router ospf 1 network area 0 network area 0 router bgp 13 bgp log-neighbor-changes network network network neighbor remote-as 13 neighbor update-source Loopback0 R2 --- hostname R2 interface Ethernet0/0 ip address no shut interface Ethernet0/1 ip address no shut router ospf 1 network area 0 network area 0 R3 --- interface Loopback0 ip address interface Ethernet0/1 ip address no shut router ospf 1 network area 0 network area 0 router bgp 13 bgp log-neighbor-changes neighbor remote-as 13 neighbor update-source Loopback0
  4. Hi guys, B1-B5 still coming in lab or B6-B10 and Alinux1-6 are enough for preparation?
  5. 24 August 2016 in BeiJing, TS2 has New fault of 70% . 25 August 2016 in Chengdu, TS2 has New fault of 70% . New TS topology=TS2 topology,just has new fault ! 70% new fault !
  6. Hello, guys. Regarding New TS Ticket 10 (Telnet from NAS to Server2, NAT ticket). Previously I wrote in my feedback that in order to match the required ouput, R25 should translate outside source to its local loopback. After numerous requests, I prepared a lab to demonstrate the concept. You can find it attached to post. Here are the details on NAT translations: When NAS (192.168.1.xxx) is telnetting to Server2 (Real IP is, but the ticket requires to telnet to R25's WAN IP) it is going to 10.99.25.xxx (R25's WAN IP), so passing through R70 it is NATted (192.168.1.xxx -> 10.99.25.xxx). After arriving at R25 telnet packet is first NATted via "nat inside" translation (destination 10.99.25.xxx ->, then via "nat outside" translation (source 10.99.70.xxx -> 10.70.25.xxx). Issue, that Minh Khoi pointed out for me, is that in this case R25 will drop the returning traffic. Here are the details of traffic path and NAT translations. (telnet SYN Packet) NAS -> R70 IP.src =, IP.dst = R70 -> ISP2 -> R25 IP.src =, IP.dst = R25 -> SW210 -> Server2 IP.src =, IP.dst = (telnet SYN ACK Packet) Server2 -> SW210 -> R25 IP.src =, IP.dst = R25 -> drop The reason for this is that when going from inside –> outside, routing is always done FIRST, followed by NAT. And because R25 has directly connected loopback with IP, it decides that SYN ACK packet is destined for R25 itself and resets the connection. As I stated in my feedback, I managed to solve the ticket (match the required output) by adding "ip nat outside source" command. So there are two possibilities: If R25 does not have a loopback with IP, then the concept stated above is true. In the attached lab file, you can check this. Maybe, I was wrong and there were no loopbacks on R25 other than L0, and I misled you all because I thought that all this will work only in case R25 has such loopback configured. If R25 does have a loopback with IP, there were other config lines that make such concept possible, but unfortunately I could not find a way to make it work. If anyone would be able to find a solution in this case, please share here your opinion. [Hidden Content]
  7. Hello all, I share an IOU export for training the TS. This work has been done by one of our friends (like Guru said ) The only thing I can say is "that's a really good work for training TSv5". Topology + Workbook included [hide][Hidden Content]] The password is "Kn0wYoUr3n3mY". Have fun ! Thank you ! Gerard111
  8. Hi All Finally I pass CCIE RS v5 yesterday, I'd like to thank to CC forum . From this Forum I can get some resource and a lot of tips and trick to study CCIE here is what I can remember from my exam yesterday TS; 1. Vlan 12 is not allowed on the Trunk 2. Wrong ppp hostname 3. passive interface 4. offset list with wrong acl. and wrong metric eigrp 5. modify the route map with correct metric 6. advertise the wrong network of IPv6 7. wrong DMVPN config, correct some nhrp map, and correct acl on the R19, permit esp 8. a lot correction: ip nat missing in R8, default originate R7, R8, enable mpls on R4 and R6, Correct Ospf config on R7. don't forget to try the back up scenario 9. wrong crypto address and missing the mode of transform set 10. enable ip domain lookup, ip dns DIAG in here you have to manage the time very carefully, because it is only 30 minutes. You will not have enough time to read all the question, email, config, design, log. especially for Question no 3 which take more time. 1. VTP problem : vtp password 2. DMVPN miss config on R16, wrong subnet 3. uRPF: - R1 : loose config to both R2 and R3 - R2 & R3 : Strict uRPF to R1 Q1 : Drag and Drop : not really sure my answer is correct or not Q2 : reason of the problem : I choose strict uRPF Config - MST - DMVPN with VRF - NTP with authentication Good luck for everyone pursuing CCIE Thx BR
  9. Hello Guys, I was making the old TS yesterday and i have some doubts with the ACL. For what I know, in the lab you should avoid the permit any any in the ACL, you're supposed to solve like an "expert". If you have the ACL that is causing the problem in the path that it takes, deny ip, can i solve it just with a permit any any? Can I put just a permit up ? I mean, it is almost the same, but i have some doubts about it. I appreciate your help on this guys.
  10. jchuna

    No New feedback

    Guys I don't see any feedback on troubleshooting tickets for long time... What happened why passed or failed students are not posting their troubleshooting ticket experience like before???
  11. Hello Everyone, Soon going to appear in for R&S lab exam, need small help related to DHCP snooping in very first TS question. One of TS exercises I found this problem where SW1 connected to SERVER1 is configured with command "ip dhcp snooping vlan 200" due to which SERVER1 is not getting the IP I tried adding ip dhcp snooping trust command on the interface facing R7 and R8 on SW1 but no joy. Also tried number of options by studying about dhcp snooping. I am only able to solve this question by removing the command "ip dhcp snooping vlan 200" from SW1. I don't know if this is the right approach. Please help..
  12. Hi All, While browsing for new dumps, my friend go this new diag in one of the chine forums. It looks like the new diag, but not sure. just attaching it for our benefit to review in this gr8 forum. Updated TS along with this BV new diag-may be.pdf New TS with qus & ans.pdf
  13. I don't mean to break the rules of the forum - but i don't think that post on "what labs will i get" has been updated with the new labs and with the labs that are retired. Now with K9, TSv5 new - are we still seeing MSDP and MPLS TS in the lab? I'm familiarizing myself with TSv5 and TSv5 new (apart from K7+ and K8+ - and of course, K9)... and my lab's next week
  14. Hello, After some observation of threads and reports I concluded that you miss some easy things what shouldn't be done on TS part. Sometimes reporters said everything working fine but I fail. Why? i'll try answer: 1. Avoid to remove config line completely , thing what can be done with change. Only last way is remove away. This always don't like our vendor. 2. DO NOT shut interfaces, think what can be done without it. 3. Wording of question. Read very careful. Because I saw that first impression is, that you can not to do anything on particular place, but in fact YOU CAN. Super answer I saw from Mike81. Post #19 [Hidden Content] MPSv3 ticket MQC. 4. Better use AD for static routes...you can get same result as removing it 5. To leave helper commands like logg con - IS NOT a fault - verified with proctor But main attention - is question WORDING !!!. I got lot of questions - like "does restriction in questions are correct?" " I cant solve with this restriction" - YES YOU CAN, but deep dive in question. Last MPLSv3 is verified by very respectful experts. I as creator, + 2 CCIE's from here. All questions are correct. everything is verified. the best result what I know to solve this TS from first face was 3.5 hours. it is absolutely normal, because there are much more faults than in life. To add more tips here are welcome !!
  15. Dear CCIEian i just need to know how many case with 3 point in the TS and how many point can i lose and still pass also should i have all the faults in the case to get its point
  16. Is it possible to throw some light on where to look for TS questions and topology diagram
  17. Please clarify these TS' terminology? Are there any overlaps? What are the differences? Which ones have + version? If there more, please add it to the list. Thank you. MPLSv1 MPLSv2 MPLSv3 MSDPv1 MSDPv2 MSDPv3 TS3 TS4 TS503 TS504 TS5 301 TS5v1 TS5v2 TS5v3
  18. Hello Everyone - need some help with MSDP question in TS5 v2. MSDP is up, RP mapping info is distributed across every router and I am able to ping from R28. But I am getting two replies per ping however ping output given in question says to have only one reply per ping packet. Please advise what i am missing here - This is what I am getting - two replies per ping - i should only be getting one reply per ping packet R28#ping re 5 Type escape sequence to abort. Sending 10, 100-byte ICMP Echos to, timeout is 2 seconds: . Reply to request 1 from, 36 ms Reply to request 1 from, 40 ms Reply to request 2 from, 28 ms Reply to request 2 from, 28 ms Reply to request 3 from, 28 ms Reply to request 3 from, 32 ms Reply to request 4 from, 28 ms Reply to request 4 from, 28 ms
  19. Could those who attempted the exam help to clear my doubt? I heard that in config section there is a terminal server. But do we also have it in TS section? Can I do something like the following to log into all the 30 devices at the beginning of the TS section? TerminalServer#send * " enable cisco " Ctrl+Z so that I don't have to type password every time I click into a new router/switch?
  20. cc2ccie

    Active Labs, TS

    can anyone please confirm how many labs & Tshoots are in market for V5...!!! and how many DG Questions are there (approx).
  21. Hi Guys! Need your views/comments on the following three questions. I was able to solve all of them but want to make sure that I am not breaking any requirements or want to find out if there is a better way to solve these.... ----------------------------------------------------------------------------------------------------------------------------------- MPLSv2 - Question 9 - I was able to solve this question but am not sure if I am breaking a requirement. Here is the part of the question that I am concerned about - DO NOT REMOVE OR ADD ANY ACL LINE IN THIS CONFIGURATION My doubt - I found on R19, an acl which only permitted ospf, udp and tcp port 23. This acl was causing DHCP to fail. Since requirement was to not to remove or add acl lines, I simply removed that acl group from the interface config. Am i breaking a rule by configuring this, is there a better way to get it working?? I know that people have failed in the past because they removed entire configs that were breaking stuff when actually they were supposed to edit the configuration to get it working... ----------------------------------------------------------------------------------------------------------------------------------- MPLSV3 - Question 2 - Again, was able to solve this but not sure if I am breaking this requirement - While you are resolving this issue, you are not allowed to change any existing configuration on SW1 In this case, SW1's port facing R10 was assigned vlan 114 but the vlan did not exist on the swithc. So, I added the vlan to the configuration. Since this is ADDING configuration but I am NOT CHANGING any existing config. Is this breaking the requirement? Any better way to solve this? ----------------------------------------------------------------------------------------------------------------------------------- MPLSV3 - Question 6 - Not sure whether or not I am breaking this requirement - YOU ARE NOT ALLOWED TO CHANGE ANY EXISTING IPV6 ACL OR ADD NEW LINES TO IT. ALSO DO NOT REMOVE COMPLETELY TRAFFIC FILTERS FROM ANY INTERFACE. Found this ACL on R5 - ipv6 access-list CCIE permit ipv6 any host 2001:CC1E:100::100 This was applied to interfaces facing R1, R2 and R8 preventing ospf neighborship from coming up. My workaround was to create a new acl with permit ipv6 any any and applied a filter with this ACL to the same interfaces facing R1, R2 and R8. Technically, I am not editing any existing acl, not adding any new lines and not removing COMPLETELY the filters from any interfaces either. But, is this solution acceptable? ----------------------------------------------------------------------------------------------------------------------------------- Thanks!!!
  22. Hello Everyone, I was preparing for CCIE R&S but since all seats were booked, hence the dropped the idea for appearing Lab this time, but I see many seats have been opened by Cisco now. The time I have stopped studying, the new Labs were not there. Can someone provide the Questionnaire and Solutions for the new K Labs and TS ? Kapss
  23. Dear All members I am going to take my first attempt and have a concern about exam question in TS part. When I am doing TS labs provided on WEB-IOU from this great forum , each ticket has a name such as "MST Ticket" , "PPP Ticket" and so on. My question is that in real LAB exam in TS part does the tickets have a title and help to concentrate on a specific feature ? Or the question is like "ping from R20 should be successful" ? Thanks in advance
  24. glasgow

    Cisco IOU

    Cisco IOU is great. But, how to make use of it? I tried many guides like [Hidden Content] Some recommend -Asasel IOU- Still I cannot get Putty telnet to IOU via VMWare. When googled to seek for a solution to this problem, I found the same problems everyware, but no direct answers. Could you please discuss the baby steps to get IOU working? It will be helpful for us to simulate many devices with less resource utilization, and to practice the TS section. Workable solution please.... --Cisco IOU, VMWare, PuTTY, Telnet, GNS3, TS4, TS3++, Guide-- IOU.txt
