路由器RTA与RTB之间建立BGP连接并互相学习到了路由。RTA与RTB都使用缺省定时器。如果路由器间链路拥塞,导致RTA收不到RTB发出的Keepalive消息,则会发生()后果。
A.30秒后,RTA认为邻居失效,并删除从RTB学来的路由
B.90秒后,RTA认为邻居失效,并删除从RTB学来的路由
C.120秒后,RTA认为邻居失效,并删除从RTB学来的路由
D.180秒后,RTA认为邻居失效,并删除从RTB学来的路由
A.30秒后,RTA认为邻居失效,并删除从RTB学来的路由
B.90秒后,RTA认为邻居失效,并删除从RTB学来的路由
C.120秒后,RTA认为邻居失效,并删除从RTB学来的路由
D.180秒后,RTA认为邻居失效,并删除从RTB学来的路由
如图所示,RTA、RTB、RTC、RTD在同一个AS内,通过直连链路建立IBGP邻居关系,RTB、RTC为路由反射器,RTA与RTC为RTB的路由反射器客户RTB与RTD为RTC的路由反射器客户端,RTA上将10.1.1.0/24宣告进BGP中,则RTD上收到的BGP路由更新其OriginatorID值为()。
A.1.1.1.1
B.此题为填空题,答案请参考选项A
A.BGP建立邻居前需要建立一条UDP连接
B.BGP建立邻居关系需要先交互链路状态信息
C.BGP路由器支持自动发现邻居
D.BGP建立邻居必须配置MD5认证
A.在任何规模的内部BGP闭合网中都建议使用BGP的路由反射器以减少IBGP连接数量
B.一个Cluster内可以有多个路由反射器以实现冗余
C.非客户机必须与路由反射器以及互相之间组成全连按网
D.反射器功能只在路由反射器上完成,该路由器不处理不需要反射的路由
A.作为一台路由器的管理地址
B.使用该接口地址作为动态路由协议OSPF的RouterID
C.用该地址作为BGP建立TCP连接的源地址
D.用该地址作为BGP的RouterID
RTA:
[RTA]ikepeer123
[RTA-ike-peer-123]pre-shared-kesimple123[RTA-ike-peer-123]remote-addr
ess100.1.1.2
.......<-i
IRTA-ike-peer-123]local-address100.1.1.1[RTA-ike-peer-123]quit
[RTA]ipsecproposal1IRTA-ipsec-proposal-l]quit[RTA]aclnumber3000
[RTA-acl-adv-3000]rule0permitipsource192.168.1.00.0.0.255destination1
92.168.2.00.0.0.255
[RTA]ipsecpolic11isakmp
[RTA-ipsec-polic-isakmp-l-l]securitacl3000[RTA-ipsec-polic-isakmp-l-l]
ike-peer123
[RTA-ipscec-polic-isakmp-l-l]proposal1[RTA-ipsec-polic-isakmp-l-l]qui
t
[RTA]interfaceEthernetO/1/1
[RTA-Ethernet0/1/1]ipaddress10.1.1.1255.255.255.0[RTA]interfaceEthern
etO/l/0
[RTA-Ethernet0/1/0]ipaddress192.168.1.1255.255.255.0[RTA]interfaceLoo
pback0
[RTA-LoopbackO]ipaddress1.1.1.1255.255.255.255[RTA]interfaceTunnel1
[RTA-Tunnel1]source1.1.1.1
[RTA-Tunnel1]destination2.2.2.2
[RTA-Tunnell]ipaddress100.1.1.1255.255.255.0[RTA-Tunnel1]keepalive
[RTA-Tunnell]ipsecpolic1
[RTA]iproute-static2.2.2.2255.255.255.25510.1.1.2
[RTA]iproute-static192.168.2.0255.255.255.0100.1.1.2RTB:
[RTB]ikepeer123
[RTB-ike-peer-123]pre-shared-kesimple123[RTB-ike-peer-123]remote-addr
ess100.1.1.1
[RTB-ike-peer-123]local-address100.1.1.2[RTB-ike-peer-123]quit
[RTB]ipsecproposal1[RTB-ipsec-proposal-l]quit[RTB]aclnumber3000
[RTB-acl-adv-3000]ruleopermitipsource192.168.2.00.0.0.255destination1
92.168.1.00.0.0.255
[RTB]ipsecpolic11isakmp
[RTB-ipsec-polic-isakmp-l-l]securitacl3000[RTB-ipsec-polic-isakmp-l-l]
ike-peer123
[RTB-ipsec-polic-isakmp-l-l]proposal1[RTB-ipsec-polic-isakmp-l-l]quit
[RTB]interfaceEthernet0/1/1
[RTB-Ethernet0/1/1]ipaddress10.1.1.2255.255.255.0[RTB]interfaceEthern
et0/1/0
[RTB-Ethernet0/1/0]ipaddress192.168.2.1255.255.255.0[RTB]interfaceLoo
pback0
[RTB-Loopback0]ipaddress2.2.2.2255.255.255.255[RTB]interfaceTunnell
[RTB-Tunnell]source2.2.2.2[RTB-Tunnell]destinationl.1.1.1
[RTB-Tunnell]ipaddress100.1.1.2255.255.255.0[RTB-Tunnell]keepalive
[RTA-Tunnell]ipsecpolic1
[RTB]iproute-staticl.1.1.1255.255.255.25510.1.1.1
[RTB]iproute-static192.168.1.0255.255.255.0100.1.1.1
A.IPSecoverGRE
B.GREoverIPsec
C.L2TPoverIPsec
D.IPSecoverL2TP
RTA
[RTA]ikepeer123
[RTA-ike-peer-123]pre-shared-kesimple123[RTA-ike-peer-123]remote-addr
ess10.2.1.2
[RTA-ike-peer-123]local-address10.2.1.1[RTA-ike-peer-123]quit
[RTA]ipsecproposal1[RTA-ipsec-proposal-1]quit[RTA]aclnumber3000
[RTA-acl-adv-3000]rule0permitipsource10.1.1.00.255.255.255
[RTA]ipsecpolic11isakmp
[RTA-ipsec-polic-isakmp-1-1]securitacl3000[RTA-ipsec-polic-isakmp-1-1]
ike-peer123
[RTA-ipsec-polic-isakmp-1-1]proposal1[RTA-ipsec-polic-isakmp-1-1]quit
[RTA]interfaceEthernet0/1/0
[RTA-Serial0/2/1]ipaddress10.2.1.1255.255.255.0[RTA]interfaceSerial0/
2/1
[RTA-Serial0/2/1]ipaddress10.2.1.1255.255.255.0[RTA-Serial0/2/1]]ipse
cpolic1
RTB:
[RTB]ikepeer123
[RTB-ike-peer-123]pre-shared-kesimple123[RTB-ike-peer-123]remote-addr
ess10.2.1.1
[RTB-ike-peer-123]local-address10.2.1.2[RTB-ike-peer-123]quit
[RTB]ipsecproposal1[RTB-ipsec-proposal-1]quit[RTB]aclnumber3000
[RTB-acl-adv-3000]rule0permitipsource10.3.1.00.255.255.255
[RTB]ipsecpolic11isakmp
[RTB-ipsec-polic-isakmp-1-1]securitacl3000[RTB-ipsec-polic-isakmp-1-1]
ike-peer123
[RTB-ipsec-polic-isakmp-1-1]proposal1[RTB-ipsec-polic-isakmp-1-1]quit
[RTA]interfaceEthernet0/1/0
[RTA-Serial0/2/1]ipaddress10.3.1.1255.255.255.0[RTB]interfaceSerial0/
2/1
[RTB-Serial0/2/1]ipaddress10.2.1.2255.255.255.0[RTB-Serial0/2/1]ipsec
polic1
由此可知()。
A.任何一方发起的SA协商都可以成功
B.任何一方发起的SA协商都不能成功
C.只有从RTA向RTB发起的SA协商才可以成功
D.只有从RTB向RTA发起的SA协商才可以成功
RTA:
[RTA]ikepeer123
[RTA-ike-peer-123]pre-shared-kesimple123[RTA-ike-peer-123]remote-addr
ess10.1.1.2
[RTA-ike-peer-123]local-address10.1.1.1[RTA-ike-peer-123]quit
[RTA]ipsecproposall[RTA-ipsec-proposal-l]quit[RTA]aclnumber3000
[RTA-acl-adv-3000]ruleOpermitipsource1.1.1.10.0.0.0destination2.2.2.2
0.0.0.0
[RTA]ipsecpolic11isakmp
[RTA-ipsec-polic-isakmp-l-l]securitacl3000[RTA-ipsec-polic-isakmp-l-l]
ike-peer123[RTA-ipsec-polic-isakmp-l-l]proposall[RTA-ipsec-polic-isak
mp-l-l]quit
[RTA]interfaceEthernetO/1/1
[RTAEthernet0/1/1]ipaddress10.1.1.1255.255.255.0[RTAEthernet0/1/1]ips
ecpolicl
[RTA]interfaceEthernet0/1/0
[RTAEthernet0/1/0]ipaddress192.168.1.1255.255.255.0
[RTA]interfaceloopback0
[RTA-LoopbackO]ipaddress1.1.1.1255.255.255.255
[RTA]interfaceTunnel1
[RTA-Tunnel1]source1.1.1.1
[RTA-Tunnel1]destination2.2.2.2
[RTA-Tunnell]ipaddress100.1.1.1255.255.255.0
[RTA]iproute-static2.2.2.2255.255.255.25510.1.1.2
[RTA]iproute-static192.168.2.0255.255.255.0100.1.1.2RTB:
[RTB]ikepeer123
[RTB-ike-peer-123]pre-shared-kesimple123[RTB-ike-peer-123]remote-addr
ess10.1.1.1
[RTB-ike-peer-123]local-address10.1.1.2[RTB-ike-peer-123]quit
[RTB]ipsecproposal1[RTB-ipsec-proposal-l]quit
[RTB]aclnumber3000
[RTB-acl-adv-3000]ruleopermitipsource2.2.2.20.0.0.0destinationl.1.1.1
0.0.0.0[RTB]ipsecpolic11isakmp
[RTB-ipsec-polic-isakmp-l-l]securitacl3000[RTB-ipsec-polic-isakmp-l-l]
ike-peer123
[RTB-ipsec-polic-isakmp-l-l]proposal1[RTB]interfaceEthernet0/1/1
[RTB-Ethernet0/1/1]ipaddress10.1.1.2255.255.255.0[RTB-Ethernet0/1/1]i
psecpolic1
[RTB]interfaceEthernet0/1/0
[RTB-Ethernet0/1/0]ipaddress192.168.2.1255.255.255.0[RTB]interfaceLoo
pback0
[RTB-Loopback0]ipaddress2.2.2.2255.255.255.255[RTB]interfaceTunnell
[RTB-Tunnell]source2.2.2.2[RTB-Tunnell]destinationl.1.1.1
[RTB-Tunnell]ipaddress100,1.1.2255.255.255.0[RTB-Tunnell]keepalive
[RTB]iproute-staticl.1.1.1255.255.255.25510.1.1.1
[RTB]iproute-static192.168.1.0255.255.255.0100.1.1.1
A.IPsecoverGRE
B.GREoverIPsec
C.L2TPoverIPsec
D.IPSecoverL2TP
RTA
[RTA]ikepeer123
[RTA-ike-peer-123]pre-shared-kesimple123[RTA-ike-peer-123]remote-addr
ess10.2.1.2
[RTA-ike-peer-123]local-address10.2.1.1[RTA-ike-peer-123]quit
[RTA]ipsecproposal1[RTA-ipsec-proposal-1]quit[RTA]aclnumber3000
[RTA-acl-adv-3000]rule0permitipsource10.1.1.00.0.0.255destination10.3.
1.00.0.0.255
[RTA]ipsecpolic11isakmp
[RTA-ipsec-polic-isakmp-1-1]securitacl3000[RTA-ipsec-polic-isakmp-1-1]
ike-peer123
[RTA-ipsec-polic-isakmp-1-1]proposal1[RTA-ipsec-polic-isakmp-1-1]quit
[RTA]interfaceSerial0/2/1
[RTA-Serial0/2/1]ipaddress10.2.1.1255.255.255.0[RTA-Serial0/2/1]ipsec
polic1
[RTA]interfaceEthernet0/1/0
[RTA-Serial0/2/1]ipaddress10.1.1.2255.255.255.0
RTB:
[RTB]ikepeer123
[RTB-ike-peer-123]pre-shared-kesimple123[RTB-ike-peer-123]remote-addr
ess10.2.1.1
[RTB-ike-peer-123]local-address10.2.1.2[RTB-ike-peer-123]quit
[RTB]ipsecproposal1[RTB-ipsec-proposal-1]quit[RTB]aclnumber3000
[RTB-acl-adv-3000]rule0permitipsource10.1.1.00.0.0.255destination10.3.
1.0.0.0.0.255
[RTB]ipsecpolic11isakmp
[RTB-ipsec-polic-isakmp-1-1]securitacl3000[RTB-ipsec-polic-isakmp-1-1]
ike-peer123
[RTB-ipsec-polic-isakmp-1-1]proposal1[RTB-ipsec-polic-isakmp-1-1]quit
RTB]interfaceSerial0/2/1
[RTB-Serial0/2/1]ipaddress10.2.1.2255.255.255.0
[RTB-Serial0/2/1]]ipsecpolic1[RTA]interfaceEthernet0/1/0
[RTA-Serial0/2/1]ipaddress10.1.3.1255.255.255.0
由此可知()。
A.任何一方发起的SA协商都可以成功
B.任何一方发起的SA协商都不能成功
C.只有从RTA向RTB发起的SA协商才可以成功
D.只有从RTB向RTA发起的SA协商才可以成功