0% found this document useful (0 votes)
193 views169 pages

Ltrccie 3401 PDF

Uploaded by

Bruce Xya
Copyright
© © All Rights Reserved
We take content rights seriously. If you suspect this is your content, claim it here.
Available Formats
Download as PDF, TXT or read online on Scribd
0% found this document useful (0 votes)
193 views169 pages

Ltrccie 3401 PDF

Uploaded by

Bruce Xya
Copyright
© © All Rights Reserved
We take content rights seriously. If you suspect this is your content, claim it here.
Available Formats
Download as PDF, TXT or read online on Scribd
You are on page 1/ 169

CCIE SP Practice Lab

Lizabete Cacic – Technical Leader


Vaibhav Agrawal – Network Consulting Engineer
LTRCCIE-3401
Cisco Spark
Questions?
Use Cisco Spark to communicate
with the speaker after the session

How
1. Find this session in the Cisco Live Mobile App
2. Click “Join the Discussion”
3. Install Spark or go directly to the space
4. Enter messages/questions in the space

Cisco Spark spaces will be cs.co/clus17/#TECCCIE-3406


available until July 3, 2017.

LTRCCIE-3401 © 2017 Cisco and/or its affiliates. All rights reserved. Cisco Public 3
“If you know the enemy
and yourself, you need no fear
the result of a hundred battles”

Sun Tzu – The Art of War


Agenda

• CCIE SP Lab Format


• LabTorial Overview
• Hands-on Lab (3 ½ hours)
• Troubleshoot
• Diagnostic
• Configuration
• Lab Review
• Questions & Answers
Disclaimer
• Not all topics discussed today
appear on every exam
• Due to time restraints, we are
unable to discuss every feature and
topic described in the exam
blueprint

LTRCCIE-3401 © 2017 Cisco and/or its affiliates. All rights reserved. Cisco Public 6
CCIE SP Lab Format
CCIE SP v4.1 – Unified Exam Topics
Domains Written Lab
1. Core Routing 25% 30%

2. Service Provider Architecture and Services 21% 22%

3. Access and Aggregation 18% 21%

4. High Availability and Fast Convergence 14% 15%

5. Service Provider Security, Operation, and Management 12% 12%

6. Evolving Technologies 10% n/a

https://learningnetwork.cisco.com/community/certifications/ccie_service_provider/written_exam_v4/exam-topics

LTRCCIE-3401 © 2017 Cisco and/or its affiliates. All rights reserved. Cisco Public 8
Fixed and Mobile Location

Brussels Warsaw Moscow

Vancouver London Kiev


Chicago Toronto Dalian
Milan Bucharest
Beijing Seoul
San Jose Las Vegas RTP Istanbul
Chengdu Tokyo
Amman New Delhi
San Diego Dubai Osaka
Orlando Cairo Doha Shanghai
Wuhan
Miami Riyadh
Guangzhou Taipei
Karachi
Mexico City Hong Kong
Bangalore
Bangkok Ho Chi Minh
Kuala Lumpur
Lagos
Singapore Fixed Locations
Nairobi

Jakarta
Mobile Locations

São Paulo
Johannesburg
Sydney
Buenos Aires

https://learningnetwork.cisco.com/docs/DOC-3224
LTRCCIE-3401 © 2017 Cisco and/or its affiliates. All rights reserved. Cisco Public 9
CCIE Passing Criteria

•  120 min •  60 min •  300 min (5h)


•  Optional +30min •  No Optional time •  Optional -30min (if used in TS)

•  Independent incidents •  Independent tickets •  Dependent items


•  Console access to the devices •  No Console access to the devices •  Console access to the devices
•  Topology speci!c for TS •  Multiple source of information (like •  Topology speci!c for
scenarios diagrams, emails, and logs) con!guration scenario

LTRCCIE-3401 © 2017 Cisco and/or its affiliates. All rights reserved. Cisco Public 10
LabTorial
Overview
CCIE SP Lab Exam Format
Web-based delivery

Optional Optional
(2h) + 30 min (60 min) - 30 min (5h)

about 10 to 12 6 minutes per about 10 to 12


minutes in average question in minutes in average
per question average per question

LTRCCIE-3401 © 2017 Cisco and/or its affiliates. All rights reserved. Cisco Public 12
CCIE SP Practice Lab
Web-based delivery

Optional Optional
(2h) + 30 min (60 min) - 30 min (5h)

10 minutes per 5 minutes per


question in about 11 minutes per
question in average
average question in average

CCIE SP Practice Lab

LTRCCIE-3401 © 2017 Cisco and/or its affiliates. All rights reserved. Cisco Public 13
Hands-on Lab
Login Page

LTRCCIE-3401 © 2017 Cisco and/or its affiliates. All rights reserved. Cisco Public 15
Troubleshooting
Module
Troubleshooting Module
General Comments
• Have a troubleshooting plan

• Multiple approaches are possible


• Configuration check, feature specific show commands, debugs, ping, traceroute
• Use the approach that you are most comfortable with
• Know the tools and options
• Know the technology and features you are troubleshooting
• Be methodical and thorough
• But do not get stuck on one idea

LTRCCIE-3401 © 2017 Cisco and/or its affiliates. All rights reserved. Cisco Public 17
Topology ASBR7
G0/1 G0/2

G0/2 G4
ASBR11 G0/3 G3 ASBR12
G0/1 G2

G4 G0/2
P10 G0/1 P13
G3
G2 G0/3

G0/1 G2 G0/1 G0/1


G0/3 G5 G0/4 G0/3
PE8 PE9 PE14 PE15
G3 G4 G0/3 G0/2
G0/2 G0/2

G0/1 G0/1 G0/1 G0/1 G0/1 G0/1

CE1 CE2 CE3 CE6 CE5 CE4

LTRCCIE-3401 © 2017 Cisco and/or its affiliates. All rights reserved. Cisco Public 18
L0 = 7.7.7.7

IPv4 Address G0/1


ASBR7
G0/2

1.7.11.0/24 2.7.12.0/24

L0 = 11.11.11.11 G0/2 L0 = 12.12.12.12


1.11.12.0/24 G4
ASBR11 G0/3 G3 ASBR12
G0/1 G2
1.10.11.0/24 2.12.13.0/24

L0 = 10.10.10.10 G4 G0/2 L0 = 13.13.13.13


P10 G0/1 P13
G3 G0/3
G2
1.8.10.0/24 1.9.10.0/24 2.13.14.0/24 2.13.15.0/24

L0 = 8.8.8.8 G0/1 G2 L0 = 14.14.14.14 G0/1 G0/1 L0 = 15.15.15.15


G0/3 G5 G0/4 G0/3
PE8 PE9 PE14 PE15
1.8.9.0/24 G3 G4 G0/3 1.8.9.0/24 G0/2
G0/2 G0/2
L0 = 9.9.9.9

172.1.8.0/24 172.2.9.0/24 172.3.9.0/24 172.4.6.0/24 172.5.14.0/24 172.4.6.0/24

G0/1 G0/1 G0/1 G0/1 G0/1 G0/1

CE1 CE2 CE3 CE6 CE5 CE4


Last octet is router-id
L0 = 1.1.1.1 L0 = 2.2.2.2 L0 = 3.3.3.3 L0 = 6.6.6.6 L0 = 5.5.5.5 L0 = 4.4.4.4

LTRCCIE-3401 © 2017 Cisco and/or its affiliates. All rights reserved. Cisco Public 19
L0 = 7::7

IPv6 Address G0/1


ASBR7
G0/2

1:7:11::/64 2:7:12::/64

L0 = 11::11 G0/2 L0 = 12::12


1:11:12::/64 G4
ASBR11 G0/3 G3 ASBR12
G0/1 G2
1:10:11::/64 2:12:13::/64

L0 = 10::10 G4 G0/2 L0 = 13::13


P10 G0/1 P13
G3
G2 G0/3
1:8:10::/64 1:9:10::/64 2:13:14::/64 2:13:15::/64

L0 = 8::8 G0/1 G2 L0 = 14::14 G0/1 G0/1 L0 = 15::15


G0/3 G5 G0/4 G0/3
PE8 PE9 PE14 PE15
1:8:9::/64 G3 G4 G0/3 1:8:9::/64 G0/2
G0/2 G0/2
L0 = 9::9

172:1:8::/64 172:2:9::/64 172:3:9::/64 172:4:6::/64 172:5:14::/64 172:4:6::/64

G0/1 G0/1 G0/1 G0/1 G0/1 G0/1

CE1 CE2 CE3 CE6 CE5 CE4


Last two characters are router-id characters
L0 = 1::1 L0 = 2::2 L0 = 3::3 L0 = 6::6 L0 = 5::5 L0 = 4::4
Example: PE15 Gig0/1: 2:13:15::15

LTRCCIE-3401 © 2017 Cisco and/or its affiliates. All rights reserved. Cisco Public 20
Routing Information ASBR7
G0/1 G0/2

G0/2 G4
ASBR11 G0/3 G3 ASBR12
G0/1 G2

G4 G0/2
P10 G0/1 P13
G3
G2 G0/3

G0/1 G2 G0/1 G0/1


G0/3 G5 G0/4 G0/3
PE8 PE9 PE14 PE15
G3 G4 G0/3 G0/2
G0/2 G0/2

G0/1 G0/1 G0/1 G0/1 G0/1 G0/1

CE1 CE2 CE3 CE6 CE5 CE4


BGP sessions

LTRCCIE-3401 © 2017 Cisco and/or its affiliates. All rights reserved. Cisco Public 21
Trouble Ticket 1: IGP
An AS2 operations engineer notices that the IGP peering between P13 and PE15
is not working. Your task is to fix this issue.
PE15# sh isis neighbors

Tag 2:
System Id Type Interface IP Address State Holdtime Circuit Id
P13 L2 Gi0/1 2.13.15.13 UP 26 P13.03
PE14 L2 Gi0/3 2.14.15.14 UP 25 PE14.02

Score: 4 points

LTRCCIE-3401 © 2017 Cisco and/or its affiliates. All rights reserved. Cisco Public 22
Trouble Ticket 2: L2VPN
A customer is complaining that CE4 site cannot ping CE6 site. Your task is to fix
this issue.
CE4# ping 172.4.6.6
Type escape sequence to abort.
Sending 5, 100-byte ICMP Echos to 172.4.6.6, timeout is 2 seconds:
!!!!!
Success rate is 100 percent (5/5), round-trip min/avg/max = 7/10/16 ms

CE4# telnet 172.4.6.6


Trying 172.4.6.6 ... Open
C
CE6#

Score: 3 points

LTRCCIE-3401 © 2017 Cisco and/or its affiliates. All rights reserved. Cisco Public 23
Trouble Ticket 3: PE-CE Routing
CE3 is not receiving routes from PE9. Your task is to fix this issue.
.
CE3# sh ip route rip
--snip--
1.0.0.0/32 is subnetted, 1 subnets
R 1.1.1.1 [120/4] via 172.3.9.9, 00:00:25, GigabitEthernet0/1
5.0.0.0/32 is subnetted, 1 subnets
R 5.5.5.5 [120/4] via 172.3.9.9, 00:00:25, GigabitEthernet0/1
172.1.0.0/24 is subnetted, 1 subnets
R 172.1.8.0 [120/4] via 172.3.9.9, 00:00:25, GigabitEthernet0/1
172.5.0.0/24 is subnetted, 1 subnets
R 172.5.14.0 [120/4] via 172.3.9.9, 00:00:25, GigabitEthernet0/1

Score: 3 points

LTRCCIE-3401 © 2017 Cisco and/or its affiliates. All rights reserved. Cisco Public 24
Trouble Ticket 4: LDP
CE1 and CE5 are part of a L3VPN. A traceroute from CE1 to CE5 is taking more
hops than expected. Your task is to fix this issue. .
CE1# traceroute 5.5.5.5
--snip—

1 172.1.8.8 5 msec 5 msec 4 msec


2 1.8.10.10 [MPLS: Labels 18/41 Exp 0] 17 msec 19 msec 14 msec
3 1.10.11.11 [MPLS: Label 41 Exp 0] 15 msec 18 msec 42 msec
4 1.11.12.12 [MPLS: Label 38 Exp 0] 39 msec 26 msec 32 msec
5 2.12.13.13 [MPLS: Labels 17/26 Exp 0] 33 msec 15 msec 25 msec
6 172.5.14.14 [AS 1] [MPLS: Label 26 Exp 0] 19 msec 15 msec 19 msec
7 172.5.14.5 [AS 1] 37 msec * 17 msec

Score: 2 points

LTRCCIE-3401 © 2017 Cisco and/or its affiliates. All rights reserved. Cisco Public 25
Trouble Ticket 5: BGP
IPv6 BGP peering between CE1 and PE8 is down. Your task is to fix this issue.
.
CE1# sh ip bgp ipv6 unicast summary
--snip--
Neighbor V AS MsgRcvd MsgSent TblVer InQ OutQ Up/Down State/PfxRcd
172:1:8::8 4 1 0 0 1 0 0 00:33:49 2

Score: 1 point

LTRCCIE-3401 © 2017 Cisco and/or its affiliates. All rights reserved. Cisco Public 26
Diagnostics
Module
Diagnostic Module
General Comments
• Task topic is specified at the top of each page
• You can start with topics you are more familiar with
• You have all information needed to answer the questions
• Provided information has redundancy
• Select resources that help you to answer the questions quickly
• Focus on answering the questions
• Some information could be distracting
• You do not need to think how to fix the issue
• Do not overthink, start with simpler explanations
• Do not get stuck
• You can go back and forth between tasks
LTRCCIE-3401 © 2017 Cisco and/or its affiliates. All rights reserved. Cisco Public 28
L0: 10.1.255.1/32

Topology 2001:DB8:1:1/128
ISP_1_PE1
L0: 192.168.255.1/32
2001:DB8:255::1/128 L0: 10.1.255.2/32
L11: 192.168.11.1/24 A_BURNABY 2001:DB8:1:2/128 L0: 10.1.255.4/32
2001:DB8:11::1/128 2001:DB8:1:4/128
L12: 192.168.12.1/24 ISP_1_P ISP_1_ASBR
2001:DB8:12::1/128
L0: 10.1.255.3/32
L13: 192.168.13.1/24
2001:DB8:1:3/128
2001:DB8:13::1/128
ISP_1_PE2
L0: 192.168.255.2/32
2001:DB8:255::1/128
L11: 192.168.21.1/24
2001:DB8:21::1/128 A_DELTA L0: 172.1.1.1/32
L12: 192.168.22.1/24 2001:DB8:172::1/128
2001:DB8:22::1/128 L11: 172.2.2.2/32
L13: 192.168.23.1/24 L0: 10.2.255.1/32 2001:DB8:172::2/128
2001:DB8:2:255::1/128 L0: 10.2.255.2/32 L12: 172.3.3.3/32
2001:DB8:23::1/128 2001:DB8:2:255::2/128 2001:DB8:172::3/128
ISP_2_PE1 L13: 172.4.4.4/32
ISP_2_ASBR1 2001:DB8:172::4/128
L0: 192.168.255.3/32
2001:DB8:255::3/128 A_CALGARY
L31: 192.168.31.1/24
2001:DB8:31::1/128

INTERNET

L0: 10.2.255.3/32
2001:DB8:2:255::3/128

ISP_2_PE2
ISP_2_ASBR2
L0: 10.2.255.4/32
2001:DB8:2:255::4/128
LTRCCIE-3401 © 2017 Cisco and/or its affiliates. All rights reserved. Cisco Public 29
Task 1: Interior Gateway Protocol
ISP_2 recently deployed OSPFv3 in their backbone. Last weekend an operations engineer
noticed that there isn’t an OSPFv3 adjacency between ISP_2_PE1 and ISP_2_PE2. .t
Your task is to diagnose this issue and to answer the question. What is the root cause of this
issue:

Select an answer:

ISP_2_PE1 and ISP_2_PE2 use the same IPv6 link local address on this link.
There is an area-ID mismatch on the link between ISP_2_PE1 and ISP_2_PE2.
IPv6 is not enabled on the GigabitEthernet0/1 interface of the ISP_2_PE2.
There is a duplicate router-id; both routers, ISP_2_PE1 and ISP_2_PE2, use the same router-id.
There is a network type mismatch on the link between ISP_2_PE1 and ISP_2_PE2.

LTRCCIE-3401 © 2017 Cisco and/or its affiliates. All rights reserved. Cisco Public 30
Task 1:
E-mail Thread

LTRCCIE-3401 © 2017 Cisco and/or its affiliates. All rights reserved. Cisco Public 31
Task 1:
Outputs

LTRCCIE-3401 © 2017 Cisco and/or its affiliates. All rights reserved. Cisco Public 32
Task 1:
Outputs

LTRCCIE-3401 © 2017 Cisco and/or its affiliates. All rights reserved. Cisco Public 33
Task 2: MPLS Traffic Engineering
ISP_1 uses MPLS Traffic Engineering solution in their core network. ISP_1_PE1 device has
a 45 Mbps MPLS TE tunnel configured, where ISP_1_PE2 is the tail-end of this tunnel. The
status of this MPLS TE tunnel is down.
Indicate what is the root cause of this issue?

Select an answer:

ISP_1_PE1 is missing a static route for the MPLS TE tunnel to be activated.


ISP_1_P does not have RSVP enabled on the interface facing ISP_1_PE2.
ISP_1_PE2 does not have mpls traffic-eng enabled globally.
There is not enough bandwidth resource available for the MPLS TE tunnel in the path between
ISP_1_P and ISP_1_PE2.

LTRCCIE-3401 © 2017 Cisco and/or its affiliates. All rights reserved. Cisco Public 34
Task 2:
E-mail Thread

LTRCCIE-3401 © 2017 Cisco and/or its affiliates. All rights reserved. Cisco Public 35
Task 2:
Outputs

LTRCCIE-3401 © 2017 Cisco and/or its affiliates. All rights reserved. Cisco Public 36
Task 2:
Outputs

LTRCCIE-3401 © 2017 Cisco and/or its affiliates. All rights reserved. Cisco Public 37
Task 3: L3VPN
ISP_1 and ISP_2 use an MPLS Inter-AS solutions to provide connectivity between sites of
their common customers. Customer_A opened a case with ISP_1 reporting that the Burnaby
and Delta sites lost connectivity with the Calgary site. Indicate which device is causing this
issue: ISP_1_PE1

A_BURNABY
ISP_1_P ISP_1_ASBR

ISP_1_PE2

A_DELTA

ISP_2_PE1
ISP_2_ASBR1
A_CALGARY INTERNET

ISP_2_PE2
ISP_2_ASBR2

LTRCCIE-3401 © 2017 Cisco and/or its affiliates. All rights reserved. Cisco Public 38
Task 3:
E-mail Thread

LTRCCIE-3401 © 2017 Cisco and/or its affiliates. All rights reserved. Cisco Public 39
Task 3:
Outputs

LTRCCIE-3401 © 2017 Cisco and/or its affiliates. All rights reserved. Cisco Public 40
Task 3:
Outputs

LTRCCIE-3401 © 2017 Cisco and/or its affiliates. All rights reserved. Cisco Public 41
Task 3:
Outputs

LTRCCIE-3401 © 2017 Cisco and/or its affiliates. All rights reserved. Cisco Public 42
Task 3:
Outputs

LTRCCIE-3401 © 2017 Cisco and/or its affiliates. All rights reserved. Cisco Public 43
Task 4: PE-CE Connectivity
Customer_A is asking for help with investigating an issue related to a BGP filtering applied
between CE and PE link. Drag and drop the reason why the PE-CE filtering is not working
on the left onto the issue rectangle on the right. Also, drag and drop the device responsible
for this issue on the left onto the device rectangle on the right.
Options Answer Sequence

A_BURNABY This kind of filter are not


supported
an prefix orf must be configured device
A_DELTA
on pE side for the filter to work

ISP_1_PE1 software bug


issue
route-map does not work with
ISP_1_PE2
ACL, it must use prefix-list
route-map applied uses an access-
ASBR7
list that does not exist

LTRCCIE-3401 © 2017 Cisco and/or its affiliates. All rights reserved. Cisco Public 44
Task 4:
E-mail Thread

LTRCCIE-3401 © 2017 Cisco and/or its affiliates. All rights reserved. Cisco Public 45
Task 4:
Outputs

LTRCCIE-3401 © 2017 Cisco and/or its affiliates. All rights reserved. Cisco Public 46
Task 5: Routing/Fast Convergence
ISP_2 uses two ASBRs for Internet connectivity. The design engineer has a requirement to
increase fast convergence on the network. For that, the BGP router reflector must have a
second path in the BGP database. Right now, it only learns the path from one of the ASBR
devices. Select one of the option
Apply the bandwidth community attribute to enable ICMP requirement.

Enable BGP multipath on BGP router reflector device.

Apply advertise external path feature on the 2nd ASBR device.

Enable BGP PIC on the core.

Configure IP FRR.

Enable MPLS TE/FRR.

Configure LDP session protection.

LTRCCIE-3401 © 2017 Cisco and/or its affiliates. All rights reserved. Cisco Public 47
Task 5:
E-mail Thread

LTRCCIE-3401 © 2017 Cisco and/or its affiliates. All rights reserved. Cisco Public 48
Task 5:
Outputs

LTRCCIE-3401 © 2017 Cisco and/or its affiliates. All rights reserved. Cisco Public 49
Task 5:
Outputs

LTRCCIE-3401 © 2017 Cisco and/or its affiliates. All rights reserved. Cisco Public 50
Task 5:
Outputs

LTRCCIE-3401 © 2017 Cisco and/or its affiliates. All rights reserved. Cisco Public 51
Task 5:
Outputs

LTRCCIE-3401 © 2017 Cisco and/or its affiliates. All rights reserved. Cisco Public 52
Task 5:
Outputs

LTRCCIE-3401 © 2017 Cisco and/or its affiliates. All rights reserved. Cisco Public 53
Task 5:
Outputs

LTRCCIE-3401 © 2017 Cisco and/or its affiliates. All rights reserved. Cisco Public 54
Configuration
Section

© 2017 Cisco and/or its affiliates. All rights reserved. Cisco Public 55
Configuration Module
General Comments
• Understand all tasks that you will need to complete
• Check all configuration tasks before you start
• Time is limited
• It is important to develop a correct solution before you start implementing it
• Carefully read all requirements
• Your solution must meet all of them
• Parts of configuration may be repeatable
• Use a text editor to prepare device configurations to save time

LTRCCIE-3401 © 2017 Cisco and/or its affiliates. All rights reserved. Cisco Public
G0/0/0/1 G0/1
A-PE8 Z-CE1
G0/0/0/0

Topology
G0/0/0/2

A-ASBR11 G2 G5
G3 G2 G3 G0/1
G4
G2 G4 G5 G6 G4
Z-CE2

G3
A-P10 A-PE9

G2
C-ASBR7 G0/1 Y-CE3
G3

B-P13 B-PE15

G3
G2 G0/3 G0/1
G4 G0/2 G0/1 X-CE4
G0/2
G0/1 G0/3
B-ASBR12

G0/4
G0/1
G0/3 G0/1
B-PE14 Z-CE5
G0/2

G0/1
X-CE6
LTRCCIE-3401 © 2017 Cisco and/or its affiliates. All rights reserved. Cisco Public 57
G0/0/0/1 G0/1
A-PE8 172.1.8.0/24 Z-CE1
G0/0/0/0

IPv4 and IPv6


G0/0/0/2 172:1:8::/64

1.8.9.0/24

1.9.10.0/24
1.10.11.0/24

172.2.9.0/24
172:2:9::/64
Addressing
A-ASBR11 G2 G5
G3 G2 G3
G4
G2 G4 G5 G6 G4 G0/1
Z-CE2

G3
A-P10 A-PE9

G2
1.11.12.0/24
C-ASBR7 1:11:12::/64 G0/1 Y-CE3
G3

172.4.6.0/24
172:4:6::/64
2.12.13.0/24
2:12:13::/64

2.13.15.0/24
2:13:15::/64
B-P13 B-PE15

G3
G2 G0/3 G0/1
G4 G0/2 G0/1 X-CE4
G0/2
G0/1 G0/3
B-ASBR12

172.5.14.0/24
172:5:14::/64
2.14.15.0/24
2:14:15::/64

G0/4
G0/1
G0/3
B-PE14 Z-CE5
G0/1
G0/2

172.4.6.0/24
172:4:6::/64
G0/1
X-CE6
LTRCCIE-3401 © 2017 Cisco and/or its affiliates. All rights reserved. Cisco Public 58
G0/0/0/1 G0/1
A-PE8 Z-CE1
G0/0/0/0

Routing
G0/0/0/2

Information
A-ASBR11 G2 G5
G3 G2 G3 G0/1
G4
G2 G4 G5 G6 G4
Z-CE2

G3
A-P10 A-PE9

G2
C-ASBR7 G0/1 Y-CE3
G3

B-P13 B-PE15

G3
G2 G0/3 G0/1
G4 G0/2 G0/1 X-CE4
G0/2
G0/1 G0/3
B-ASBR12

G0/4
G0/1
G0/3 G0/1
B-PE14 Z-CE5
G0/2

G0/1
X-CE6
LTRCCIE-3401 © 2017 Cisco and/or its affiliates. All rights reserved. Cisco Public 59
Task I.1: MPLS Traffic Engineering
Configure a MPLS Traffic Engineering Tunnel on A-PE8 router to send traffic over
this tunnel considering the following requirements:
• The Loopback 0 address of A-ASBR11 router is the MPLS TE tail-end.
• It must request 50 Mbps of bandwidth.
• It must use a dynamic path.

Note: You are not allowed to use a static route.

Score: 3 points

LTRCCIE-3401 © 2017 Cisco and/or its affiliates. All rights reserved. Cisco Public 60
Task I.2: Multicast
ISP-A must implement the Next Generation MVPN, as defined in RFC 6388.
Configure ISP-A devices to provision the multicast for Customer Z with the
following specifications:
• MPLS encapsulation must be used for both unicast and multicast traffic
• PIM must be used to assign flows to the LSPs, but it should not be used inside
of the ISP-A network core
• BGP based auto-discovery is not required to discover the PEs members within
the same MVPN
• The Root of the Default MDT must be the Loopback address of the PE9
• The VPN-ID is 200:1
• Supports is required for IPv4 multicast traffic only Score: 4 points
• Use a static RP 172.2.9.9

LTRCCIE-3401 © 2017 Cisco and/or its affiliates. All rights reserved. Cisco Public 61
Task I.3: Quality of Service
Z-CE1 marks all its traffic with IP Precedence 3. Configure A-P10 to ensure that
traffic originated from Z-CE1 have guaranteed bandwidth of 5Mbps awhile
sending out to A-ASBR11.

Score: 3 points

LTRCCIE-3401 © 2017 Cisco and/or its affiliates. All rights reserved. Cisco Public 62
Task II.1: L3VPN
The Inter-AS link between ISP-A and ISP-B fails frequently. This causes network
outage for the Layer-3 VPN services that both offers. Configure ISP-A and ISP-B
to use ISP-C when the direct link between ISP-A and ISP-B fails.
After you complete this task, for verification only, shutdown the link between ISP-A
and ISP-B, Z-CE1 must be able to ping the Loopback 0 address of the Z-CE5 and
vice versa.

Note: Make sure after the verification to unshut the link between ISP-A and ISP-B.

Score: 4 points

LTRCCIE-3401 © 2017 Cisco and/or its affiliates. All rights reserved. Cisco Public 63
Task II.2: Internet Service
Y-CE3 network is an IPv6 enabled only and ISP-A is an IPv4 enabled only. Y-CE3
must reach the Loopback 0 IPv6 address of C-ASBR7. Configure ISP-A transport
this traffic leveraging the MPLS core network.

Note: You are not allowed to enable IPv6 routing in the core of the ISP-A.

Score: 3 points

LTRCCIE-3401 © 2017 Cisco and/or its affiliates. All rights reserved. Cisco Public 64
Task III.1: Transport and Encapsulation Technologies
ISP-A must provision an extra link between A-PE9 and A-P10. Configure the two
links between A-PE9 and A-P10 to functioning as a single Layer 3 link increasing
redundancy and bandwidth.

Note: You are allowed to remove or modify the configuration applied on interface.

Score: 3 points

LTRCCIE-3401 © 2017 Cisco and/or its affiliates. All rights reserved. Cisco Public 65
Task III.2: PE-CE Connectivity
Configure BGP as the PE-CE routing protocol between A-PE9 and CE2 for both
IPv4 and IPv6 address-family. After you complete this task Z-CE2 must be able to
reach Loopback 0 IPv4 and IPv6 addresses of the Z-CE1.

Note: Use the information described in the diagrams provided.

Score: 4 points

LTRCCIE-3401 © 2017 Cisco and/or its affiliates. All rights reserved. Cisco Public 66
Task IV.1: System Level High Availability
ISP-B must avoid black-holed labelled traffic when a core failed link comes back
up again. Configure all routers in the ISP-B network that meets this requirement.

Score: 2 points

LTRCCIE-3401 © 2017 Cisco and/or its affiliates. All rights reserved. Cisco Public 67
Task IV.2: Routing/Fast Convergence
Enable a link protection for the MPLS TE tunnel configured on A-PE8.

Score: 2 points

LTRCCIE-3401 © 2017 Cisco and/or its affiliates. All rights reserved. Cisco Public 68
Task V.1: Control Plane Security
ISP-B must increase control plane security in their backbone. Enable MD5 for
LDP message exchange in all routers of the ISP-B network.

Score: 2 points

LTRCCIE-3401 © 2017 Cisco and/or its affiliates. All rights reserved. Cisco Public 69
Task V.2: Management Plane Security
Increase the management plane security on A-PE8 by allowing in-band TELNET
and SSH via GigabitEthernet 0/0/0/0 interface. None of any other management
protocol should be allowed.

Note: You are not allowed to use access-list.

Score: 2 points

LTRCCIE-3401 © 2017 Cisco and/or its affiliates. All rights reserved. Cisco Public 70
Troubleshooting
Module
Answers Key
Ticket 1: IS-IS Circuit Type Mismatch
P13# sh clns interface gigabitethernet 0/3
--snip— Circuit type must
GigabitEthernet0/3 is up, line protocol is up
--snip— match for IS-IS LAN
Routing Protocol: IS-IS network type
Circuit Type: level-1
Interface number 0x3, local circuit ID 0x3
BFD enabled: (MTID:0, ipv4)
PE15# sh clns interface gigabitethernet 0/1
--snip—
GigabitEthernet0/1 is up, line protocol is up
--snip—
Routing Protocol: IS-IS (2)
Circuit Type: level-1-2
Interface number 0x1, local circuit ID 0x1
Level-2 Metric: 10, Priority: 64, Circuit ID: PE15.01
DR ID: 0000.0000.0000.00
Level-2 IPv6 Metric: 10
Number of active level-2 adjacencies: 0
Next IS-IS LAN Level-2 Hello in 7 seconds
BFD enabled: (MTID:0, ipv4)

LTRCCIE-3401 © 2017 Cisco and/or its affiliates. All rights reserved. Cisco Public 72
Ticket 1: Solution
P13#

interface gigabitethernet 0/3


isis circuit-type level-2-only

LTRCCIE-3401 © 2017 Cisco and/or its affiliates. All rights reserved. Cisco Public 73
Ticket 1: Verification
P13# sh isis neighbors
--snip—
Tag 2:
System Id Type Interface IP Address State Holdtime Circuit Id
ASBR12 L2 Gi0/2 2.12.13.12 UP 9 ASBR12.01
PE14 L2 Gi0/1 2.13.14.14 UP 29 P13.01
PE15 L2 Gi0/3 2.13.15.15 UP 29 P13.03

PE15# sh isis neigh


--snip—
Tag 2:
System Id Type Interface IP Address State Holdtime Circuit Id
P13 L2 Gi0/1 2.13.15.13 UP 8 P13.03
PE14 L2 Gi0/3 2.14.15.14 UP 7 PE14.02

LTRCCIE-3401 © 2017 Cisco and/or its affiliates. All rights reserved. Cisco Public 74
L2VPN the MTU
interface must
Ticket 2: MTU Mismatch match
PE14# sh mpls l2transport vc detail
Local interface: Gi0/2 up, line protocol up, Ethernet up
Destination address: 15.15.15.15, VC ID: 46, VC status: down
Last error: Pseudowire MTU mismatch with peer
Output interface: none, imposed label stack {}
Preferred path: not configured
Default path: no route
No adjacency
Create time: 00:17:47, last status change time: 00:17:47
Last label FSM state change time: 00:17:47
Signaling protocol: LDP, peer 15.15.15.15:0 up
Targeted Hello: 14.14.14.14(LDP Id) -> 15.15.15.15, LDP is UP
--snip—
MPLS VC labels: local 22, remote 26
Group ID: local n/a, remote 0
MTU: local 1400, remote 1500
Remote interface description:
Sequencing: receive disabled, send disabled
Control Word: On (configured: autosense)
Dataplane:
SSM segment/switch IDs: 0/0 (used), PWID: 1
--snip--

LTRCCIE-3401 © 2017 Cisco and/or its affiliates. All rights reserved. Cisco Public 75
Ticket 2: Solution
PE14#

interface GigabitEthernet0/2
mtu 1500

LTRCCIE-3401 © 2017 Cisco and/or its affiliates. All rights reserved. Cisco Public 76
Ticket 2: Verification
PE14# sh xconnect all
--snip—
XC ST Segment 1 S1 Segment 2 S2
------+------------------------------+--+---------------------------------+--
UP pri ac Gi0/2:4(Ethernet) UP mpls 15.15.15.15:46 UP

CE4# ping 172.4.6.6


Type escape sequence to abort.
Sending 5, 100-byte ICMP Echos to 172.4.6.6, timeout is 2 seconds:
!!!!!
Success rate is 100 percent (5/5), round-trip min/avg/max = 3/6/8 ms

LTRCCIE-3401 © 2017 Cisco and/or its affiliates. All rights reserved. Cisco Public 77
Ticket 3: RIP Metric is Higher Than 15
CE3# sh ip route
--snip—
Gateway of last resort is not set
3.0.0.0/32 is subnetted, 1 subnets
C 3.3.3.3 is directly connected, Loopback0
172.3.0.0/16 is variably subnetted, 2 subnets, 2 masks
C 172.3.9.0/24 is directly connected, GigabitEthernet0/1
L 172.3.9.3/32 is directly connected, GigabitEthernet0/1
PE9# sh ip route vrf A bgp when redistributing
--snip— VPNv4 learnt via
Gateway of last resort is not set another protocol in
1.0.0.0/32 is subnetted, 1 subnets the remote PE-CE
B 1.1.1.1 [200/0] via 8.8.8.8, 22:04:29 site, you must add
5.0.0.0/32 is subnetted, 1 subnets
B 5.5.5.5 [200/0] via 11.11.11.11, 00:44:53 the metric keyword
172.1.0.0/24 is subnetted, 1 subnets
B 172.1.8.0 [200/0] via 8.8.8.8, 22:04:29
172.5.0.0/24 is subnetted, 1 subnets
B 172.5.14.0 [200/0] via 11.11.11.11, 00:44:53

LTRCCIE-3401 © 2017 Cisco and/or its affiliates. All rights reserved. Cisco Public 78
Ticket 3: Solution
PE9#

router rip
address-family ipv4 vrf A
redistribute bgp 1 metric 4

LTRCCIE-3401 © 2017 Cisco and/or its affiliates. All rights reserved. Cisco Public 79
Ticket 3: Verification
CE3# sh ip route
--snip—
Gateway of last resort is not set

1.0.0.0/32 is subnetted, 1 subnets


R 1.1.1.1 [120/4] via 172.3.9.9, 00:00:04, GigabitEthernet0/1
3.0.0.0/32 is subnetted, 1 subnets
C 3.3.3.3 is directly connected, Loopback0
5.0.0.0/32 is subnetted, 1 subnets
R 5.5.5.5 [120/4] via 172.3.9.9, 00:00:04, GigabitEthernet0/1
172.1.0.0/24 is subnetted, 1 subnets
R 172.1.8.0 [120/4] via 172.3.9.9, 00:00:04, GigabitEthernet0/1
172.3.0.0/16 is variably subnetted, 2 subnets, 2 masks
C 172.3.9.0/24 is directly connected, GigabitEthernet0/1
L 172.3.9.3/32 is directly connected, GigabitEthernet0/1
172.5.0.0/24 is subnetted, 1 subnets
R 172.5.14.0 [120/4] via 172.3.9.9, 00:00:04, GigabitEthernet0/1

LTRCCIE-3401 © 2017 Cisco and/or its affiliates. All rights reserved. Cisco Public 80
Ticket 4: No LDP peering between PE8 and PE10
P10# sh mpls ldp discovery
--snip—
Local LDP Identifier:
10.10.10.10:0
Discovery Sources:
Interfaces:
GigabitEthernet2 (ldp): xmit/recv
LDP Id: 8.8.8.8:0
GigabitEthernet3 (ldp): xmit/recv
P10# sh mpls ldp neighbor
LDP Id: 9.9.9.9:0
--snip—
GigabitEthernet4 (ldp): xmit/recv
Peer LDP Ident: 9.9.9.9:0; Local LDP Ident 10.10.10.10:0
LDP Id: 11.11.11.11:0 TCP connection: 9.9.9.9.646 - 10.10.10.10.15422
State: Oper; Msgs sent/rcvd: 1551/1553; Downstream
Up time: 22:27:46
LDP discovery sources:
GigabitEthernet3, Src IP addr: 1.9.10.9
--snip—
Peer LDP Ident: 11.11.11.11:0; Local LDP Ident 10.10.10.10:0
TCP connection: 11.11.11.11.61200 - 10.10.10.10.646
State: Oper; Msgs sent/rcvd: 1545/1539; Downstream
Up time: 22:27:46
LDP discovery sources:
GigabitEthernet4, Src IP addr: 1.10.11.11
--snip—

LTRCCIE-3401 © 2017 Cisco and/or its affiliates. All rights reserved. Cisco Public 81
Ticket 4: No LDP peering between PE8 and PE10
PE8# sh logging
--snip--
*Jun 15 11:39:01.553: %TCP-6-BADAUTH: Invalid MD5 digest from 10.10.10.10(13640) to
8.8.8.8(646) tableid - 0
*Jun 15 11:39:09.356: %TCP-6-BADAUTH: Invalid MD5 digest from 10.10.10.10(13640) to
8.8.8.8(646) tableid - 0
*Jun 15 11:39:12.907: %TCP-6-BADAUTH: Invalid MD5 digest from 10.10.10.10(20921) to
8.8.8.8(646) tableid - 0
*Jun 15 11:39:14.872: %TCP-6-BADAUTH: Invalid MD5 digest from 10.10.10.10(20921) to
8.8.8.8(646) tableid - 0

PE8# sh running-config | i password password between


mpls ldp neighbor 9.9.9.9 password CISCO with PE10 uses
mpls ldp neighbor 10.10.10.10 password C1SCO
number ’1’ instead of
upper case ’i’

LTRCCIE-3401 © 2017 Cisco and/or its affiliates. All rights reserved. Cisco Public 82
Ticket 4: Solution
PE8#

mpls ldp neighbor 10.10.10.10 password CISCO

LTRCCIE-3401 © 2017 Cisco and/or its affiliates. All rights reserved. Cisco Public 83
Ticket 4: Verification
P10# sh mpls ldp neighbor | i Peer LDP Ident
Peer LDP Ident: 9.9.9.9:0; Local LDP Ident 10.10.10.10:0
Peer LDP Ident: 11.11.11.11:0; Local LDP Ident 10.10.10.10:0
Peer LDP Ident: 8.8.8.8:0; Local LDP Ident 10.10.10.10:0

CE1# traceroute 5.5.5.5


Type escape sequence to abort.
Tracing the route to 5.5.5.5
VRF info: (vrf in name/id, vrf out name/id)
1 172.1.8.8 7 msec 2 msec 2 msec
2 1.8.10.10 [MPLS: Labels 16/28 Exp 0] 24 msec 17 msec 30 msec
3 1.10.11.11 [MPLS: Label 28 Exp 0] 15 msec 12 msec 25 msec
4 1.11.12.12 [MPLS: Label 37 Exp 0] 29 msec 24 msec 89 msec
5 2.12.13.13 [MPLS: Labels 16/26 Exp 0] 30 msec 11 msec 21 msec
6 172.5.14.14 [AS 1] [MPLS: Label 26 Exp 0] 15 msec 7 msec 11 msec
7 172.5.14.5 [AS 1] 25 msec * 18 msec

LTRCCIE-3401 © 2017 Cisco and/or its affiliates. All rights reserved. Cisco Public 84
Ticket 5: CE1 has the BGP TTL Configured
CE1# sh bgp ipv6 unicast neighbors
BGP neighbor is 172:1:8::8, remote AS 1, external link
BGP version 4, remote router ID 0.0.0.0
BGP state = Active
Neighbor sessions:
0 active, is not multisession capable (disabled)
Stateful switchover support enabled: NO for session 0

--snip--

Address tracking is enabled, the RIB does have a route to 172:1:8::8


Connections established 3; dropped 3
Last reset 01:57:13, due to Active open failed
External BGP neighbor may be up to 1 hop away.
External BGP neighbor configured for connected checks (single-hop no-disable-connected-
check)
Interface associated: GigabitEthernet0/1 (peering address in same link)
Transport(tcp) path-mtu-discovery is enabled
Graceful-Restart is disabled
SSO is disabled
No active TCP connection

LTRCCIE-3401 © 2017 Cisco and/or its affiliates. All rights reserved. Cisco Public 85
Ticket 5: PE8 does not BGP TTL Configured
PE8# sh bgp vpnv6 uni all neighbor 172:1:8::1
BGP neighbor is 172:1:8::1, vrf A, remote AS 4, external link
BGP version 4, remote router ID 0.0.0.0
BGP state = Active
Neighbor sessions:
0 active, is not multisession capable (disabled)
Stateful switchover support enabled: NO for session 0

--snip--

Address tracking is enabled, the RIB does have a route to 172:1:8::1


Connections established 0; dropped 0
Last reset never
Transport(tcp) path-mtu-discovery is enabled No message about
Graceful-Restart is disabled
No active TCP connection how many hop away

LTRCCIE-3401 © 2017 Cisco and/or its affiliates. All rights reserved. Cisco Public 86
Ticket 5: Solution
PE8#

router bgp 1
address-family ipv6 vrf A
neighbor 172:1:8::1 ttl-security hops 1

LTRCCIE-3401 © 2017 Cisco and/or its affiliates. All rights reserved. Cisco Public 87
Ticket 5: Verification
CE1# sh bgp ipv6 unicast summary
Load for five secs: 0%/0%; one minute: 0%; five minutes: 0%
Time source is hardware calendar, *17:43:28.076 UTC Thu Jun 22 2017
BGP router identifier 1.1.1.1, local AS number 4
BGP table version is 4, main routing table version 4
3 network entries using 492 bytes of memory
4 path entries using 416 bytes of memory
3/2 BGP path/bestpath attribute entries using 432 bytes of memory
3 BGP AS-PATH entries using 72 bytes of memory
0 BGP route-map cache entries using 0 bytes of memory
0 BGP filter-list cache entries using 0 bytes of memory
BGP using 1412 total bytes of memory
BGP activity 13/3 prefixes, 15/3 paths, scan interval 60 secs

Neighbor V AS MsgRcvd MsgSent TblVer InQ OutQ Up/Down State/PfxRcd


172:1:8::8 4 1 6 5 3 0 0 00:00:10 2

LTRCCIE-3401 © 2017 Cisco and/or its affiliates. All rights reserved. Cisco Public 88
Diagnostics
Module
Answers Key
Task 1: Interior Gateway Protocol
ISP_2 recently deployed OSPFv3 in their backbone. Last weekend an operations engineer
noticed that there isn’t an OSPFv3 adjacency between ISP_2_PE1 and ISP_2_PE2. .t
Your task is to diagnose this issue and to answer the question. What is the root cause of this
issue:

Select an answer:

ISP_2_PE1 and ISP_2_PE2 use the same IPv6 link local address on this link.
There is an area-ID mismatch on the link between ISP_2_PE1 and ISP_2_PE2.
IPv6 is not enabled on the GigabitEthernet0/1 interface of the ISP_2_PE2.
There is a duplicate router-id; both routers, ISP_2_PE1 and ISP_2_PE2, use the same router-id.
There is a network type mismatch on the link between ISP_2_PE1 and ISP_2_PE2.

LTRCCIE-3401 © 2017 Cisco and/or its affiliates. All rights reserved. Cisco Public 90
Task 2: MPLS Traffic Engineering
ISP_1 uses MPLS Traffic Engineering solution in their core network. ISP_1_PE1 device has
a 45 Mbps MPLS TE tunnel configured, where ISP_1_PE2 is the tail-end of this tunnel. The
status of this MPLS TE tunnel is down.
Indicate what is the root cause of this issue?

Select an answer:

ISP_1_PE1 is missing a static route for the MPLS TE tunnel to be activated.


ISP_1_P does not have RSVP enabled on the interface facing ISP_1_PE2.
ISP_1_PE2 does not have mpls traffic-eng enabled globally.
There is not enough bandwidth resource available for the MPLS TE tunnel in the path between
ISP_1_P and ISP_1_PE2.

LTRCCIE-3401 © 2017 Cisco and/or its affiliates. All rights reserved. Cisco Public 91
Task 3: L3VPN
ISP_1 and ISP_2 use an MPLS Inter-AS solutions to provide connectivity between sites of
their common customers. Customer_A opened a case with ISP_1 reporting that the Burnaby
and Delta sites lost connectivity with the Calgary site. Indicate which device is causing this
issue: ISP_1_PE1

A_BURNABY
ISP_1_P ISP_1_ASBR

ISP_1_PE2

A_DELTA

ISP_2_PE1
ISP_2_ASBR1
A_CALGARY INTERNET

ISP_2_PE2
ISP_2_ASBR2

LTRCCIE-3401 © 2017 Cisco and/or its affiliates. All rights reserved. Cisco Public 92
Task 4: PE-CE Connectivity
Customer_A is asking for help with investigating an issue related to a BGP filtering applied
between CE and PE link. Drag and drop the reason why the PE-CE filtering is not working
on the left onto the issue rectangle on the right. Also, drag and drop the device responsible
for this issue on the left onto the device rectangle on the right.
Options Answer Sequence

A_BURNABY This kind of filter are not


supported
an prefix orf must be configured device
A_DELTA
on pE side for the filter to work

ISP_1_PE1 software bug


route-map applied uses an access-
issue
list that does not exist
route-map does not work with
ISP_1_PE2
ACL, it must use prefix-list

ASBR7

LTRCCIE-3401 © 2017 Cisco and/or its affiliates. All rights reserved. Cisco Public 93
Task 5: Routing/Fast Convergence
ISP_2 uses two ASBRs for Internet connectivity. The design engineer has a requirement to
increase fast convergence on the network. For that, the BGP router reflector must have a
second path in the BGP database. Right now, it only learns the path from one of the ASBR
devices. Select one of the option
Apply the bandwidth community attribute to enable ICMP requirement.

Enable BGP multipath on BGP router reflector device.

Apply advertise external path feature on the 2nd ASBR device.

Enable BGP PIC on the core.

Configure IP FRR.

Enable MPLS TE/FRR.

Configure LDP session protection.

LTRCCIE-3401 © 2017 Cisco and/or its affiliates. All rights reserved. Cisco Public 94
Configuration
Section
Answers Key

© 2017 Cisco and/or its affiliates. All rights reserved. Cisco Public 95
Task I.1: MPLS Traffic Engineering
A-PE8#

interface tunnel-te100
ipv4 unnumbered Loopback0
This command sends traffic
signalled-bandwidth 50000 to the tunnel for tunnel
autoroute announce destination.
! This is you do not need to
use static route
destination 11.11.11.11
path-option 1 dynamic

LTRCCIE-3401 © 2017 Cisco and/or its affiliates. All rights reserved. Cisco Public 96
Task I.1: Verification
RP/0/0/CPU0:A-PE8# sh mpls traffic-eng tunnels brief
TUNNEL NAME DESTINATION STATUS STATE
tunnel-te100 11.11.11.11 up up
Displayed 1 (of 1) heads, 0 (of 0) midpoints, 0 (of 0) tails
Displayed 1 up, 0 down, 0 recovering, 0 recovered heads
RP/0/0/CPU0:A-PE8# sh route ipv4 isis
i L2 1.9.10.0/24 [115/20] via 1.8.9.9, 00:03:02, GigabitEthernet0/0/0/2
[115/20] via 1.8.10.10, 00:03:02, GigabitEthernet0/0/0/0
i L2 1.10.11.0/24 [115/20] via 1.8.10.10, 00:27:08, GigabitEthernet0/0/0/0
i L2 9.9.9.9/32 [115/10] via 1.8.9.9, 00:03:02, GigabitEthernet0/0/0/2
i L2 10.10.10.10/32 [115/10] via 1.8.10.10, 00:27:08, GigabitEthernet0/0/0/0
i L2 11.11.11.11/32 [115/20] via 11.11.11.11, 00:05:06, tunnel-te100

LTRCCIE-3401 © 2017 Cisco and/or its affiliates. All rights reserved. Cisco Public 97
Task I.1: Verification
RP/0/0/CPU0:A-PE8# sh mpls traffic-eng tunnels
Name: tunnel-te100 Destination: 11.11.11.11 Ifhandle:0x480
Signalled-Name: A-ASBR11_t100
Status:
Admin: up Oper: up Path: valid Signalling: connected
path option 1, type dynamic (Basis for Setup, path weight 10)
G-PID: 0x0800 (derived from egress interface properties)
Bandwidth Requested: 50000 kbps CT0
Creation Time: Sat Jun 24 19:12:17 2017 (00:06:14 ago)
Config Parameters:
Bandwidth: 50000 kbps (CT0) Priority: 7 7 Affinity: 0x0/0xffff
Metric Type: TE (default)
Hop-limit: disabled
Cost-limit: disabled
AutoRoute: enabled LockDown: disabled Policy class: not set
Forward class: 0 (default)
Forwarding-Adjacency: disabled
Loadshare: 0 equal loadshares
Auto-bw: disabled
--snip--

LTRCCIE-3401 © 2017 Cisco and/or its affiliates. All rights reserved. Cisco Public 98
Task I.2: Multicast
A-PE8#
mpls ldp router pim
mldp address-family ipv4
logging notifications interface Loopback0
! enable
route-policy ROSEN-MLDP ROSEN !
set core-tree mldp-default MLDP !
end-policy vrf Z
! address-family ipv4
multicast-routing rpf topology route-policy ROSEN-MLDP
address-family ipv4 rp-address 172.2.9.9
mdt source Loopback0 interface GigabitEthernet0/0/0/1
interface all enable enable
!
vrf Z
address-family ipv4
interface all enable
mdt default mldp ipv4 8.8.8.8
mdt data mldp 30

LTRCCIE-3401 © 2017 Cisco and/or its affiliates. All rights reserved. Cisco Public 99
Task I.2: Multicast
A-PE9# A-P10#
ip multicast-routing distributed ip multicast mpls mldp
ip multicast-routing vrf Z distributed mpls mldp logging notifications
ip multicast mpls mldp
! Z-CE1#
vrf definition Z ip multicast-routing
ROSEN
vpn id 100:1 interface Loopback 0
address-family ipv4 MLDP ip pim sparse-mode
mdt preference mldp interface GigabitEthernet0/1
mdt default mpls mldp 172.2.9.9 ip pim sparse-mode
mdt default mpls mldp 9.9.9.9 ip pim rp-address 172.2.9.9
!
interface gigabitethernet 3 Z-CE2#
ip pim sparse-mode ip multicast-routing
!
ip multicast-routing distributed interface Loopback 0
ip multicast-routing vrf Z distributed ip pim sparse-mode
ip multicast mpls mldp interface GigabitEthernet0/1
ip pim mpls source Loopback0 ip pim sparse-mode
ip pim vrf Z rp-address 172.2.9.9 ip pim rp-address 172.2.9.9

LTRCCIE-3401 © 2017 Cisco and/or its affiliates. All rights reserved. Cisco Public 100
Task I.2: Verification
RP/0/0/CPU0:A-PE8# sh mpls mldp neighbors
mLDP neighbor database
MLDP peer ID : 9.9.9.9:0, uptime 01:02:04 Up,
Capabilities : Typed Wildcard FEC, P2MP, MP2MP
Target Adj : No
Upstream count : 0
Branch count : 0
Label map timer : never
Policy filter in : None
Path count : 1
Path(s) : 1.8.9.9 GigabitEthernet0/0/0/2 LDP
Adj list : 1.8.9.9 GigabitEthernet0/0/0/2
--snip--
MLDP peer ID : 10.10.10.10:0, uptime 01:02:04 Up,
Capabilities : Typed Wildcard FEC, P2MP, MP2MP
Target Adj : No
Upstream count : 0
Branch count : 0
Label map timer : never
Policy filter in : None
Path count : 1
Path(s) : 1.8.10.10 GigabitEthernet0/0/0/0 LDP
Adj list : 1.8.10.10 GigabitEthernet0/0/0/0
--snip--

LTRCCIE-3401 © 2017 Cisco and/or its affiliates. All rights reserved. Cisco Public 101
Task I.2: Verification
A-PE9# sh mpls mldp neighbors
MLDP peer ID : 10.10.10.10:0, uptime 04:00:43 Up,
Target Adj : No
Session hndl : 1
Upstream count : 0
Branch count : 0
Path count : 1
Path(s) : 1.9.10.10 LDP Port-channel1
Nhop count : 0
MLDP peer ID : 8.8.8.8:0, uptime 04:00:13 Up,
Target Adj : No
Session hndl : 2
Upstream count : 0
Branch count : 0
Path count : 1
Path(s) : 1.8.9.8 LDP GigabitEthernet5
Nhop count : 0
A-P10# sh mpls mldp neighbors | i MLDP peer ID
MLDP peer ID : 9.9.9.9:0, uptime 04:04:16 Up,
MLDP peer ID : 8.8.8.8:0, uptime 04:03:46 Up,
MLDP peer ID : 11.11.11.11:0, uptime 03:48:56 Up,

LTRCCIE-3401 © 2017 Cisco and/or its affiliates. All rights reserved. Cisco Public 102
Task I.2: Verification
RP/0/0/CPU0:A-PE8# sh mpls mldp root
mLDP root database
Root node : 8.8.8.8 (We are the root)
Metric : 0
Distance : 0
FEC count : 1
Path count : 1
Path(s) : 8.8.8.8 LDP nbr: none
A-PE9# sh mpls mldp root
Root node : 172.2.9.9
Metric : 4294967295
Distance : 255
Interface : None (via unicast RT)
FEC count : 1
Path count : 0
Root node : 9.9.9.9 (We are the root)
Metric : 0
Distance : 0
Interface : Loopback0 (via unicast RT)
FEC count : 1
Path count : 1
Path(s) : 9.9.9.9 LDP nbr: none

LTRCCIE-3401 © 2017 Cisco and/or its affiliates. All rights reserved. Cisco Public 103
Task I.2: Verification
RP/0/0/CPU0:A-PE8# sh mpls mldp database
mLDP database
LSM-ID: 0x00003 (RNR LSM-ID: 0x00002) Type: MP2MP Uptime: 01:07:22
FEC Root : 8.8.8.8 (we are the root)
Opaque decoded : [mdt 100:1 0]
RNR active LSP : (this entry)
Candidate RNR ID(s):
Upstream neighbor(s) :
None
Downstream client(s):
PIM MDT Uptime: 01:07:22
Egress intf : LmdtZ
Table ID : IPv4: 0xe0000011 IPv6: 0xe0800011
RPF ID : 1
Local Label : 24010 (internal)

LTRCCIE-3401 © 2017 Cisco and/or its affiliates. All rights reserved. Cisco Public 104
Task I.2: Verification
A-PE9# sh mpls mldp database
--snip--
LSM ID : 3 (RNR LSM ID: 2) Type: MP2MP Uptime : 01:19:32
FEC Root : 9.9.9.9 (we are the root)
Opaque decoded : [mdt 100:1 0]
Opaque length : 11 bytes
Opaque value : 02 000B 0001000000000100000000
RNR active LSP : (this entry)
Candidate RNR ID(s): 1
Upstream client(s) :
None
Expires : N/A Path Set ID : 3
Replication client(s):
MDT (VRF Z)
Uptime : 01:19:32 Path Set ID : 4
Interface : Lspvif1
LSM ID : 1 (RNR LSM ID: 2) Type: MP2MP Uptime : 01:22:17
FEC Root : 172.2.9.9
Opaque decoded : [mdt 100:1 0]
Opaque length : 11 bytes
--snip--
Replication client(s):
MDT (VRF Z)
Uptime : 01:22:17 Path Set ID : 2
Interface : Lspvif1

LTRCCIE-3401 © 2017 Cisco and/or its affiliates. All rights reserved. Cisco Public 105
Task I.2: Verification
RP/0/0/CPU0:A-PE8# sh pim vrf Z neighbor
PIM neighbors in VRF Z
Flag: B - Bidir capable, P - Proxy capable, DR - Designated Router,
E - ECMP Redirect capable
* indicates the neighbor created for this router
Neighbor Address Interface Uptime Expires DR pri Flags
172.1.8.1 GigabitEthernet0/0/0/1 01:04:31 00:01:43 1 P
172.1.8.8* GigabitEthernet0/0/0/1 01:04:34 00:01:30 1 (DR) B P E
8.8.8.8* LmdtZ 01:21:27 00:01:25 1 (DR) P

A-PE9# sh ip pim vrf Z neighbor


PIM Neighbor Table
Mode: B - Bidir Capable, DR - Designated Router, N - Default DR Priority,
P - Proxy Capable, S - State Refresh Capable, G - GenID Capable,
L - DR Load-balancing Capable
Neighbor Interface Uptime/Expires Ver DR
Address Prio/Mode
172.2.9.2 GigabitEthernet3 01:07:12/00:01:29 v2 1 / S P G A

LTRCCIE-3401 © 2017 Cisco and/or its affiliates. All rights reserved. Cisco Public 106
Task I.2: Verification
RP/0/0/CPU0:A-PE8# sh pim vrf Z rp mapping
PIM Group-to-RP Mappings
Group(s) 224.0.0.0/4
RP 172.2.9.9 (?), v2
Info source: 0.0.0.0 (?), elected via config
Uptime: 01:23:19, expires: never

LTRCCIE-3401 © 2017 Cisco and/or its affiliates. All rights reserved. Cisco Public 107
Task I.3: Quality of Service
A-P10#

class-map match-all EXP_3


match mpls experimental topmost 3 match mpls in the core
!
policy-map Z_CE1
class EXP_3
bandwidth 5000

interface GigabitEthernet4
service-policy output Z_CE1

LTRCCIE-3401 © 2017 Cisco and/or its affiliates. All rights reserved. Cisco Public 108
Task I.3: Verification
A-P10# sh policy-map interface gigabitEthernet 4
GigabitEthernet4
Service-policy output: Z_CE1
Class-map: EXP_3 (match-all)
0 packets, 0 bytes
5 minute offered rate 0000 bps, drop rate 0000 bps
Match: mpls experimental topmost 3
Queueing
queue limit 64 packets
(queue depth/total drops/no-buffer drops) 0/0/0
(pkts output/bytes output) 0/0
bandwidth 5000 kbps
Class-map: class-default (match-any)
4 packets, 1738 bytes
5 minute offered rate 0000 bps, drop rate 0000 bps
Match: any
queue limit 64 packets
(queue depth/total drops/no-buffer drops) 0/0/0
(pkts output/bytes output) 1/73

LTRCCIE-3401 © 2017 Cisco and/or its affiliates. All rights reserved. Cisco Public 109
Task II.1: L3VPN
A-ASBR11# B-ASBR12#
router bgp 1 router bgp 2
neighbor 12.12.12.12 remote-as 2 neighbor 11.11.11.11 remote-as 1
neighbor 12.12.12.12 ebgp-multihop 10 neighbor 11.11.11.11 ebgp-multihop 10
neighbor 12.12.12.12 update-source Loopback0 neighbor 11.11.11.11 update-source Loopback0
! !
address-family ipv4 CSC with address-family ipv4
neighbor 1.7.11.7 send-label BGP neighbor 2.7.12.7 send-label
! send-label !
address-family vpnv4 address-family vpnv4
neighbor 12.12.12.12 activate neighbor 11.11.11.11 activate
neighbor 12.12.12.12 send-community both neighbor 11.11.11.11 send-community extended
! !
address-family vpnv6 address-family vpnv6
neighbor 12.12.12.12 activate neighbor 11.11.11.11 activate
neighbor 12.12.12.12 send-community both neighbor 11.11.11.11 send-community extended

Need to create a new BGP VPNv4 and VPNv6 peering between A-ASBR11 and B-ASB12
because the original peering is down due to interface status is down

LTRCCIE-3401 © 2017 Cisco and/or its affiliates. All rights reserved. Cisco Public 110
Task II.1: L3VPN
C-ASBR7#
router bgp 3 For the CSC device it can be as simple as just send the
address-family ipv4 BGP label.
neighbor 1.7.11.11 send-label This will attached a label for the BGP VPNv4 and VPNv6
next-hope.
neighbor 2.7.12.12 send-label
exit-address-family In case there are more ISP for be transported and it
requires to be isolated to each other, then you will need
to create a VRF to separate the traffic.

LTRCCIE-3401 © 2017 Cisco and/or its affiliates. All rights reserved. Cisco Public 111
Task II.1: Verification
A-ASBR11# ping mpls ipv4 12.12.12.12/32 source 11.11.11.11
--snip--
Type escape sequence to abort.
!!!!!
Success rate is 100 percent (5/5), round-trip min/avg/max = 5/18/66 ms
Total Time Elapsed 94 ms
A-ASBR11# sh bgp vpnv4 uni all summary
--snip--
Neighbor V AS MsgRcvd MsgSent TblVer InQ OutQ Up/Down State/PfxRcd
1.11.12.12 4 2 0 0 1 0 0 never Active
8.8.8.8 4 1 139 166 12 0 0 02:08:51 2
9.9.9.9 4 1 178 167 12 0 0 02:08:52 2
12.12.12.12 4 2 147 147 12 0 0 02:05:52 3
A-ASBR11# sh ip cef 12.12.12.12/32 detail
Load for five secs: 1%/0%; one minute: 1%; five minutes: 1%
12.12.12.12/32, epoch 2, flags [rib defined all labels]
1 RR source [no flags]
recursive via 1.7.11.7 label 21
attached to GigabitEthernet4

LTRCCIE-3401 © 2017 Cisco and/or its affiliates. All rights reserved. Cisco Public 112
Task II.1: Verification
RP/0/0/CPU0:A-PE8# sh bgp vpnv4 unicast
--snip--
Route Distinguisher: 8:8 (default for vrf Z)
*> 1.1.1.1/32 172.1.8.1 0 0 4 ?
*>i2.2.2.2/32 9.9.9.9 0 100 0 4 ?
*>i5.5.5.5/32 11.11.11.11 0 100 0 2 5 ?
*> 172.1.8.0/24 0.0.0.0 0 32768 ?
* 172.1.8.1 0 0 4 ?
*>i172.2.9.0/24 9.9.9.9 0 100 0 ?
*>i172.5.14.0/24 11.11.11.11 0 100 0 2 5 ?
*>i172.15.15.15/32 11.11.11.11 0 100 0 2 ?
Route Distinguisher: 9:9
*>i2.2.2.2/32 9.9.9.9 0 100 0 4 ?
*>i172.2.9.0/24 9.9.9.9 0 100 0 ?
Route Distinguisher: 14:14
*>i5.5.5.5/32 11.11.11.11 0 100 0 2 5 ?
*>i172.5.14.0/24 11.11.11.11 0 100 0 2 5 ?
Route Distinguisher: 15:15
*>i172.15.15.15/32 11.11.11.11 0 100 0 2 ?

ASBR11 as the BGP


next-hop

LTRCCIE-3401 © 2017 Cisco and/or its affiliates. All rights reserved. Cisco Public 113
Task II.1: Verification
A-ASBR11# sh bgp vpnv4 unicast all 5.5.5.5/32
BGP routing table entry for 14:14:5.5.5.5/32, version 10 ASBR12 as the BGP
Paths: (1 available, best #1, no table)
Advertised to update-groups: next-hop
1
Refresh Epoch 1
2 5
12.12.12.12 (via default) from 12.12.12.12 (12.12.12.12)
Origin incomplete, localpref 100, valid, external, best
Extended Community: RT:1:1
mpls labels in/out 31/26
rx pathid: 0, tx pathid: 0x0
Z-CE1# trace 5.5.5.5
Type escape sequence to abort.
Tracing the route to 5.5.5.5
VRF info: (vrf in name/id, vrf out name/id)
1 172.1.8.8 9 msec 2 msec 2 msec
2 1.8.10.10 [MPLS: Labels 19/31 Exp 3] 13 msec 15 msec 16 msec
3 1.10.11.11 [MPLS: Label 31 Exp 3] 26 msec 12 msec 22 msec
4 1.7.11.7 [MPLS: Labels 21/26 Exp 3] 24 msec 11 msec 19 msec
5 2.12.13.13 [MPLS: Labels 16/20 Exp 3] 23 msec 16 msec 27 msec
6 172.5.14.14 [AS 5] [MPLS: Label 20 Exp 3] 24 msec 9 msec 20 msec
7 172.5.14.5 [AS 5] 15 msec * 33 msec

LTRCCIE-3401 © 2017 Cisco and/or its affiliates. All rights reserved. Cisco Public 114
Task II.2: Internet Service
A-ASBR11# A-PE8#
router bgp 1 router bgp 1
address-family ipv6 unicast address-family ipv6 unicast
neighbor 8.8.8.8 activate allocate-label all
neighbor 8.8.8.8 send-label !
neighbor 8.8.8.8 next-hop-self neighbor 11.11.11.11
neighbor 9.9.9.9 activate address-family ipv6 labeled-unicast
neighbor 9.9.9.9 send-label next-hop-self
neighbor 9.9.9.9 next-hop-self !
neighbor 9.9.9.9
address-family ipv6 labeled-unicast
next-hop-self

6PE uses BGP send-label under IPv6 address-family


IBGP peering uses IPv4 address

LTRCCIE-3401 © 2017 Cisco and/or its affiliates. All rights reserved. Cisco Public 115
Task II.2: Internet Service
A-PE9# Y-CE3#
router bgp 1 router bgp 6
neighbor 172:3:9::3 remote-as 6 no bgp default ipv4-unicast
! neighbor 172:3:9::9 remote-as 1
address-family ipv6 !
neighbor 172:3:9::3 activate address-family ipv6
neighbor 8.8.8.8 activate
redistribute connected
neighbor 8.8.8.8 next-hop-self
neighbor 172:3:9::9 activate
neighbor 8.8.8.8 send-label
exit-address-family
neighbor 11.11.11.11 activate
neighbor 11.11.11.11 next-hop-self
neighbor 11.11.11.11 send-label 6PE uses BGP send-label under IPv6 address-family
IBGP peering uses IPv4 address
exit-address-family

LTRCCIE-3401 © 2017 Cisco and/or its affiliates. All rights reserved. Cisco Public 116
Task II.2: Verification
RP/0/0/CPU0:A-ASBR11# sh bgp ipv6 unicast summary
--snip--
Neighbor Spk AS MsgRcvd MsgSent TblVer InQ OutQ Up/Down St/PfxRcd
8.8.8.8 0 1 2215 2251 21 0 0 03:40:24 0
9.9.9.9 0 1 2573 2242 21 0 0 03:41:13 2
A-PE9# sh bgp ipv6 uni summary
--snip--
172:3:9::3 4 6 24 28 64 0 0 00:18:01 2
8.8.8.8 4 1 232 281 64 0 0 03:40:54 0
11.11.11.11 4 1 244 278 64 0 0 03:41:52 4
Y-CE3# sh ipv6 route bgp
--snip--
B 7::7/128 [20/0]
via FE80::F816:3EFF:FE67:5411, GigabitEthernet0/1
B 12::12/128 [20/0]
via FE80::F816:3EFF:FE67:5411, GigabitEthernet0/1
B 14::14/128 [20/0]
via FE80::F816:3EFF:FE67:5411, GigabitEthernet0/1
B 15::15/128 [20/0]
via FE80::F816:3EFF:FE67:5411, GigabitEthernet0/1

LTRCCIE-3401 © 2017 Cisco and/or its affiliates. All rights reserved. Cisco Public 117
Task II.2: Verification
Y-CE3# ping 7::7 source loopback0
Type escape sequence to abort.
Sending 5, 100-byte ICMP Echos to 7::7, timeout is 2 seconds:
Packet sent with a source address of 3::3
!!!!!
Success rate is 100 percent (5/5), round-trip min/avg/max = 4/6/11 ms
A-PE9# sh bgp ipv6 uni label
Network Next Hop In label/Out label
3::3/128 172:3:9::3 26/nolabel
7::7/128 ::FFFF:11.11.11.11
nolabel/24024
12::12/128 ::FFFF:11.11.11.11
nolabel/24025
14::14/128 ::FFFF:11.11.11.11
nolabel/24026
15::15/128 ::FFFF:11.11.11.11
nolabel/24027
172:3:9::/64 172:3:9::3 23/nolabel
:: 23/nolabel

LTRCCIE-3401 © 2017 Cisco and/or its affiliates. All rights reserved. Cisco Public 118
Task III.1: Transport and Encapsulation Technologies
A-PE9# A-P10#
default interface GigabitEthernet 2 default interface GigabitEthernet3
interface port-channel 1 interface port-channel 1
ip address 1.9.10.9 255.255.255.0 ip address 1.9.10.10 255.255.255.0
ip router isis 1 ip router isis 1
mpls traffic-eng tunnels negotiation auto
isis network point-to-point mpls traffic-eng tunnels
ip rsvp bandwidth isis network point-to-point
interface GigabitEthernet 2 ip rsvp bandwidth
channel-group 1 mode active link bundle interface GigabitEthernet 3
cdp enable channel-group 1 mode active
interface GigabitEthernet6 cdp enable
channel-group 1 mode active interface GigabitEthernet5
cdp enable channel-group 1 mode active
cdp enable

LTRCCIE-3401 © 2017 Cisco and/or its affiliates. All rights reserved. Cisco Public 119
Task III.1: Verification
A-PE9# sh lacp 1 neighbor
--snip--
Partner Partner LACP Partner Partner Partner Partner Partner
Port Flags State Port Priority Admin Key Oper Key Port Number Port State
Gi2 SA bndl 32768 0x0 0x1 0x1 0x3D
Gi6 SA bndl 32768 0x0 0x1 0x1 0x3D
A-P10# sh lacp 1 neighbor
--snip--
Partner Partner LACP Partner Partner Partner Partner Partner
Port Flags State Port Priority Admin Key Oper Key Port Number Port State
Gi3 SA bndl 32768 0x0 0x1 0x1 0x3D
Gi5 SA bndl 32768 0x0 0x1 0x1 0x3D

A-P10# sh isis neighbor


Tag 1:
System Id Type Interface IP Address State Holdtime Circuit Id
A-PE8 L2 Gi2 1.8.10.8 UP 24 00
A-PE9 L2 Po1 1.9.10.9 UP 26 00
A-ASBR11 L2 Gi4 1.10.11.11 UP 29 00

LTRCCIE-3401 © 2017 Cisco and/or its affiliates. All rights reserved. Cisco Public 120
Task III.2: PE-CE Connectivity
A-PE9#
router bgp 1
address-family ipv4 vrf Z
neighbor 172.2.9.2 remote-as 4
neighbor 172.2.9.2 activate don’t forget BGP as-override
neighbor 172.2.9.2 as-override
exit-address-family Z-CE1 and Z-CE3 use the same AS number
address-family ipv6 vrf Z
neighbor 172:2:9::2 remote-as 4
neighbor 172:2:9::2 activate
neighbor 172:2:9::2 as-override
exit-address-family

A-PE8#
router bgp 1
vrf Z
neighbor 172.1.8.1
address-family ipv4 unicast
as-override
neighbor 172:1:8::1
address-family ipv6 unicast
as-override

LTRCCIE-3401 © 2017 Cisco and/or its affiliates. All rights reserved. Cisco Public 121
Task III.2: PE-CE Connectivity
Z-CE2#
router bgp 4
bgp log-neighbor-changes
no bgp default ipv4-unicast
neighbor 172:2:9::9 remote-as 1
neighbor 172.2.9.9 remote-as 1
!
address-family ipv4
redistribute connected
neighbor 172.2.9.9 activate
exit-address-family
!
address-family ipv6
redistribute connected
neighbor 172:2:9::9 activate

LTRCCIE-3401 © 2017 Cisco and/or its affiliates. All rights reserved. Cisco Public 122
Task III.2: Verification
Z-CE2# sh ip route bgp
--snip--
1.0.0.0/32 is subnetted, 1 subnets
B 1.1.1.1 [20/0] via 172.2.9.9, 00:12:33
5.0.0.0/32 is subnetted, 1 subnets
B 5.5.5.5 [20/0] via 172.2.9.9, 00:12:33
172.1.0.0/24 is subnetted, 1 subnets
B 172.1.8.0 [20/0] via 172.2.9.9, 00:12:33
172.5.0.0/24 is subnetted, 1 subnets
B 172.5.14.0 [20/0] via 172.2.9.9, 00:12:33
172.15.0.0/32 is subnetted, 1 subnets
B 172.15.15.15 [20/0] via 172.2.9.9, 00:12:33

Z-CE2# ping 1.1.1.1 source 2.2.2.2


Type escape sequence to abort.
Sending 5, 100-byte ICMP Echos to 1.1.1.1, timeout is 2 seconds:
Packet sent with a source address of 2.2.2.2
!!!!!
Success rate is 100 percent (5/5), round-trip min/avg/max = 4/7/18 ms

LTRCCIE-3401 © 2017 Cisco and/or its affiliates. All rights reserved. Cisco Public 123
Task IV.1: System Level High Availability
B-ASBR12, B-P13, B-PE14, and B-PE15#

router isis 2 LDP-IGP SYNC


mpls ldp sync
make sure you are using the
correct process ID

LTRCCIE-3401 © 2017 Cisco and/or its affiliates. All rights reserved. Cisco Public 124
Task IV.1: Verification
B-P13# sh mpls ldp igp sync
GigabitEthernet0/1:
LDP configured; LDP-IGP Synchronization enabled.
Sync status: sync achieved; peer reachable.
Sync delay time: 0 seconds (0 seconds left)
IGP holddown time: infinite.
Peer LDP Ident: 14.14.14.14:0
IGP enabled: ISIS 2
GigabitEthernet0/2:
LDP configured; LDP-IGP Synchronization enabled.
Sync status: sync achieved; peer reachable.
Sync delay time: 0 seconds (0 seconds left)
IGP holddown time: infinite.
Peer LDP Ident: 12.12.12.12:0
IGP enabled: ISIS 2
GigabitEthernet0/3:
LDP configured; LDP-IGP Synchronization enabled.
Sync status: sync achieved; peer reachable.
Sync delay time: 0 seconds (0 seconds left)
IGP holddown time: infinite.
Peer LDP Ident: 15.15.15.15:0
IGP enabled: ISIS 2

LTRCCIE-3401 © 2017 Cisco and/or its affiliates. All rights reserved. Cisco Public 125
Task IV.1: Verification
B-PE14# sh mpls ldp igp sync
GigabitEthernet0/1:
LDP configured; LDP-IGP Synchronization enabled.
Sync status: sync achieved; peer reachable.
Sync delay time: 0 seconds (0 seconds left)
IGP holddown time: infinite.
Peer LDP Ident: 13.13.13.13:0
IGP enabled: ISIS 2
GigabitEthernet0/4:
LDP configured; LDP-IGP Synchronization enabled.
Sync status: sync achieved; peer reachable.
Sync delay time: 0 seconds (0 seconds left)
IGP holddown time: infinite.
Peer LDP Ident: 15.15.15.15:0
IGP enabled: ISIS 2

LTRCCIE-3401 © 2017 Cisco and/or its affiliates. All rights reserved. Cisco Public 126
Task IV.2: Routing/Fast Convergence
RP/0/0/CPU0:A-PE8# sh mpls traffic-eng tunnels | begin Path info
Path info (IS-IS 1 level-2):
1st we need to check which physical
Node hop count: 2
interface the primary tunnel is using. So
Hop0: 1.8.10.10
that, we can apply the backup tunnel to
Hop1: 1.10.11.11
protect that link
Hop2: 11.11.11.11
Displayed 1 (of 1) heads, 0 (of 0) midpoints, 0 (of 0) tails
Displayed 1 up, 0 down, 0 recovering, 0 recovered heads
RP/0/0/CPU0:A-PE8# sh ipv4 interface brief
Interface IP-Address Status Protocol
Loopback0 8.8.8.8 Up Up
tunnel-te100 8.8.8.8 Up Up
MgmtEth0/0/CPU0/0 unassigned Shutdown Down
GigabitEthernet0/0/0/0 1.8.10.8 Up Up
GigabitEthernet0/0/0/2 1.8.9.8 Up Up

LTRCCIE-3401 © 2017 Cisco and/or its affiliates. All rights reserved. Cisco Public 127
Task IV.2: Routing/Fast Convergence
Explicit path can either specify
A-PE8#
the alternate path via adding
explicit-path name VIA-A-PE9
an ip-address of the alternate
index 1 next-address loose ipv4 unicast 1.8.9.9
path or excluding the ip-
interface tunnel-te100
address used in the primary
fast-reroute
tunnel
interface tunnel-te200
bandwidth 50000
ipv4 unnumbered Loopback0
signalled-bandwidth 50000
destination 11.11.11.11
path-option 1 explicit name VIA-A-PE9 Backup tunnel must be an explicit path
mpls traffic-eng
interface GigabitEthernet0/0/0/0
backup-path tunnel-te 200

LTRCCIE-3401 © 2017 Cisco and/or its affiliates. All rights reserved. Cisco Public 128
Task IV.2: Verification
RP/0/0/CPU0:A-PE8# sh mpls traffic-eng tunnels brief
TUNNEL NAME DESTINATION STATUS STATE
tunnel-te100 11.11.11.11 up up
tunnel-te200 11.11.11.11 up up
Displayed 2 (of 2) heads, 0 (of 0) midpoints, 0 (of 0) tails
Displayed 2 up, 0 down, 0 recovering, 0 recovered heads

RP/0/0/CPU0:A-PE8# sh rsvp fast-reroute destination 11.11.11.11


Type Destination TunID Source PSBs RSBs
---- --------------- ----- --------------- ---------- ----------
LSP4 11.11.11.11 100 8.8.8.8 Ready Ready

LTRCCIE-3401 © 2017 Cisco and/or its affiliates. All rights reserved. Cisco Public 129
Task IV.2: Verification
RP/0/0/CPU0:A-PE8# sh mpls traffic-eng tunnels 100 | begin Config
Config Parameters:
Bandwidth: 50000 kbps (CT0) Priority: 7 7 Affinity: 0x0/0xffff
Metric Type: TE (default)
Hop-limit: disabled
Cost-limit: disabled
AutoRoute: enabled LockDown: disabled Policy class: not set
Forward class: 0 (default)
Forwarding-Adjacency: disabled
Loadshare: 0 equal loadshares
Auto-bw: disabled
Fast Reroute: Enabled, Protection Desired: Any
Path Protection: Not Enabled
BFD Fast Detection: Disabled
Reoptimization after affinity failure: Enabled
Soft Preemption: Disabled
History:
--snip--

LTRCCIE-3401 © 2017 Cisco and/or its affiliates. All rights reserved. Cisco Public 130
Task V.1: Control Plane Security
B-P13#
mpls ldp neighbor 15.15.15.15 password CISCO
mpls ldp neighbor 14.14.14.14 password CISCO
mpls ldp neighbor 12.12.12.12 password CISCO

B-ASBR12#
mpls ldp neighbor 13.13.13.13 password CISCO LDP MD5 in all LDP neighbors
in ISP-B
B-PE15#
mpls ldp neighbor 13.13.13.13 password CISCO
mpls ldp neighbor 14.14.14.14 password CISCO

B-PE14#
mpls ldp neighbor 13.13.13.13 password CISCO
mpls ldp neighbor 15.15.15.15 password CISCO

LTRCCIE-3401 © 2017 Cisco and/or its affiliates. All rights reserved. Cisco Public 131
Task V.1: Verification
B-P13# sh mpls ldp neighbor password

Peer LDP Ident: 15.15.15.15:0; Local LDP Ident 13.13.13.13:0


TCP connection: 15.15.15.15.52364 - 13.13.13.13.646
Password: not required, neighbor, in use
State: Oper; Msgs sent/rcvd: 22/21
Peer LDP Ident: 14.14.14.14:0; Local LDP Ident 13.13.13.13:0
TCP connection: 14.14.14.14.62781 - 13.13.13.13.646
Password: not required, neighbor, in use
State: Oper; Msgs sent/rcvd: 22/22
Peer LDP Ident: 12.12.12.12:0; Local LDP Ident 13.13.13.13:0
TCP connection: 12.12.12.12.646 - 13.13.13.13.33010
Password: not required, neighbor, in use
State: Oper; Msgs sent/rcvd: 21/25

LTRCCIE-3401 © 2017 Cisco and/or its affiliates. All rights reserved. Cisco Public 132
Task V.1: Verification
B-P13# sh tcp tcb
Stand-alone TCP connection to host 12.12.12.12
Connection state is ESTAB, I/O status: 1, unread input bytes: 0
Connection is ECN Disabled, Mininum incoming TTL 0, Outgoing TTL 255
Local host: 13.13.13.13, Local port: 33010
Foreign host: 12.12.12.12, Foreign port: 646
Connection tableid (VRF): 0
Maximum output segment queue size: 50
--snip--
SRTT: 607 ms, RTTO: 2949 ms, RTV: 2342 ms, KRTT: 0 ms
minRTT: 1 ms, maxRTT: 1000 ms, ACK hold: 200 ms
uptime: 256781 ms, Sent idletime: 39994 ms, Receive idletime: 39792 ms
Status Flags: active open
Option Flags: non-blocking reads, non-blocking writes,
MD5 lossless password switchover, Retrans timeout
IP Precedence value : 6
--snip—
...

LTRCCIE-3401 © 2017 Cisco and/or its affiliates. All rights reserved. Cisco Public 133
Task V.1: Verification (Cont.)
...
Stand-alone TCP connection from host 14.14.14.14
Connection state is ESTAB, I/O status: 1, unread input bytes: 0
Connection is ECN Disabled, Mininum incoming TTL 0, Outgoing TTL 255
Local host: 13.13.13.13, Local port: 646
Foreign host: 14.14.14.14, Foreign port: 62781
Connection tableid (VRF): 0
Maximum output segment queue size: 50
--snip--
SRTT: 607 ms, RTTO: 2949 ms, RTV: 2342 ms, KRTT: 0 ms
minRTT: 6 ms, maxRTT: 1000 ms, ACK hold: 200 ms
uptime: 259418 ms, Sent idletime: 4305 ms, Receive idletime: 4505 ms
Status Flags: passive open, gen tcbs
Option Flags: non-blocking reads, non-blocking writes,
MD5 lossless password switchover, Retrans timeout
IP Precedence value : 6
--snip—
...

LTRCCIE-3401 © 2017 Cisco and/or its affiliates. All rights reserved. Cisco Public 134
Task V.1: Verification (Cont.)
...
Stand-alone TCP connection from host 15.15.15.15
Connection state is ESTAB, I/O status: 1, unread input bytes: 0
Connection is ECN Disabled, Mininum incoming TTL 0, Outgoing TTL 255
Local host: 13.13.13.13, Local port: 646
Foreign host: 15.15.15.15, Foreign port: 52364
Connection tableid (VRF): 0
Maximum output segment queue size: 50
--snip--
SRTT: 607 ms, RTTO: 2949 ms, RTV: 2342 ms, KRTT: 0 ms
minRTT: 6 ms, maxRTT: 1000 ms, ACK hold: 200 ms
uptime: 262320 ms, Sent idletime: 48548 ms, Receive idletime: 48348 ms
Status Flags: passive open, gen tcbs
Option Flags: non-blocking reads, non-blocking writes,
MD5 lossless password switchover, Retrans timeout
IP Precedence value : 6
--snip--

LTRCCIE-3401 © 2017 Cisco and/or its affiliates. All rights reserved. Cisco Public 135
Task V.1: Management Plane Security
A-PE8#

control-plane
management-plane MPP
inband
interface GigabitEthernet0/0/0/0
allow SSH
allow Telnet

LTRCCIE-3401 © 2017 Cisco and/or its affiliates. All rights reserved. Cisco Public 136
Task V.2: Verification
RP/0/0/CPU0:A-PE8# sh mgmt-plane

Management Plane Protection


inband interfaces
----------------------
interface - GigabitEthernet0/0/0/0
ssh configured -
All peers allowed
telnet configured -
All peers allowed

LTRCCIE-3401 © 2017 Cisco and/or its affiliates. All rights reserved. Cisco Public 137
Questions and
Answers
Continue Your Education
• TECCCIE-3406: CCIE Service Provider
• Walk-in Self-Paced Labs (WISP)
• LABCCIE-3007: CCIE SP – Troubleshoot MPLS
• LABCCIE-3008: CCIE SP – DIAG module
• LABCCIE-3009: CCIE SP – Troubleshooting IGP
• LABCCIE-3010: CCIE SP – Multicast VPN
• LABCCIE-3011: CCIE SP – Fast Convergence

• Lunch & Learn


• Meet the Engineer 1:1 meetings
• CCIE SP workbook on CLN
• https://learningnetworkstore.cisco.com/cisco-ccie-expert-training/level-for-service-provider-v4-1-lab-workbook-360-sp-04-wkb-core-020997

• CCIE SP study group


• https://learningnetwork.cisco.com/groups/ccie-sp-study-group

LTRCCIE-3401 © 2017 Cisco and/or its affiliates. All rights reserved. Cisco Public 139
Become a Cisco Subject Matter Expert
• Do you consider yourself a Subject Matter Expert?
• Would like to lend your expertise to the Cisco Certification Exam?
http://www.cisco.com/go/certsme

LTRCCIE-3401 © 2017 Cisco and/or its affiliates. All rights reserved. Cisco Public 140
Complete Your Online
Session Evaluation
• Give us your feedback to be
entered into a Daily Survey
Drawing. A daily winner will
receive a $750 gift card.
• Complete your session surveys
through the Cisco Live mobile
app or on www.CiscoLive.com/us.

Don’t forget: Cisco Live sessions will be


available for viewing on demand after the
event at www.CiscoLive.com/Online.

© 2017 Cisco and/or its affiliates. All rights reserved. Cisco Public
Thank you
CCIE Program Update
“It’s not the strongest of the
species that survives, nor the
most intelligent, but the one
The evolution of CCIE most responsive to change.”
Minor Revisions (Charles Darwin)

Learning Matrix
Continuing Education
Virtual Reality
The Evolution of CCIE
Changing Priorities: Role, Technologies % of CCIEs Prioritizing Area
DESIGN/ARCHITECTURE 58
DATA CENTER 41
NETWORK OPTIMIZATION 36
Leading… SDN
SYSTEMS INTEGRATION 30
33

Strongly involved in today ... 0 10 20 30 40 50 60 70

CLOUD 35
Accelerating… NETWORK PROGRAMMING 28
INTERNET OF THINGS 23
CCIEs are preparing for ... PROJECT/PRODUCT MGMT 20
ANALYTICS 8
0 10 20 30 40
Source: L@C Customer Insights Survey, Cisco, November 2016

LTRCCIE-3401 © 2017 Cisco and/or its affiliates. All rights reserved. Cisco Public 145
The Evolution of CCIE
Changing Priorities: Role, Technologies

Traditional skills New skills


The Hybrid Engineer

LTRCCIE-3401 © 2017 Cisco and/or its affiliates. All rights reserved. Cisco Public 146
Cisco Certifications Evolution

Security

IoT and Cloud


Data
Analytics Baseline
Skills

Business Network
Skills Programmability

LTRCCIE-3401 © 2017 Cisco and/or its affiliates. All rights reserved. Cisco Public 147
CCIE Program Updates
Last 1 year

CCIE Data Center CCIE SECU CCIE SP CCIE WIR


v2.0 v5.0 v4.1 v3.1
July 2016 January 2017 June 2017 November 2017

All written BPs Learning Matrix Continuing


incorporate new Education
Evolving technology &
domain Agile BP

LTRCCIE-3401 © 2017 Cisco and/or its affiliates. All rights reserved. Cisco Public 148
AGILE
Minor Revisions
Minor Revisions Major Revisions
Definition Minor revision entails smaller but Major revision entails larger
frequent changes to the exam track infrequent changes to the exam track
Frequency
Every 1-2 years Every 3-5 years

Blueprint (Exam Topics) Percent Change


Below 20% Above 20%

Software Changes Yes (if needed) Yes

Hardware/Equipment Model Changes Yes, but kept to a minimum Yes


(including real & virtual), and EOL devices (focus on Virtualization, or EOL)

Notification / Announcement ~ 4 months ~ 6 months

Major Minor … Minor Major

https://learningnetwork.cisco.com/community/expert-level-certifications-agile-blueprints
https://learningnetwork.cisco.com/community/ccie-sp-written-and-lab-content-updates

LTRCCIE-3401 © 2017 Cisco and/or its affiliates. All rights reserved. Cisco Public 149
CCIE Learning Matrix

https://learningnetwork.cisco.com/community/learning_center/study_learn_content

LTRCCIE-3401 © 2017 Cisco and/or its affiliates. All rights reserved. Cisco Public 150
Learning Matrix Reference books with specific chapters
Resources identified

Cisco® Validated Design documents

Cisco Live presentations

Training courses

Webinars

VoDs

Solution Reference Network


Designs (SRNDs)
The matrix focusses primarily on Cisco and Cisco Press content
White papers

Case studies, design guides, Design


TechNotes, reference guides, etc.

© 2017 Cisco and/or its affiliates. All rights reserved. Cisco Confidential

LTRCCIE-3401 © 2017 Cisco and/or its affiliates. All rights reserved. Cisco Public
Continuing Education Program
• A flexible alternative option to recertify
• To encourage candidates to diversify their skill sets
• Currently available for CCIE/CCDE only (in active or suspended state)
• Launched June 6th 2017
Option 1 : Written exam Option 2: Continuing Education

1. Enroll to the program


2. Earn 100 credits (by completing any of the
Take the qualification exam (no policy change)
approved offerings)
3. Administrative fee

https://ce.cisco.com/
LTRCCIE-3401 © 2017 Cisco and/or its affiliates. All rights reserved. Cisco Public 152
Continuing Education Program
Dashboard

The catalog includes courses offered by


Authorized Cisco training partners only
§ Validity
§ Integrity

§ CCIE/CCDE Techtorial (8hrs) 10


§ Item authoring (+20 items) 21
§ Cisco DNA Implementation Essentials 40
§ Developing with Cisco Network Programm. 50

Tips: Check if you have company access to courses on the Cisco digital learning library.
You can indicate you attended CLUS, so you can start earning credits.

LTRCCIE-3401 © 2017 Cisco and/or its affiliates. All rights reserved. Cisco Public 153
Continuing Education Program
Business Rules

§ Credits, once earned, is valid for 3 years from the date they were earned
§ Credits expire
ü If a new recertification cycle starts, i.e. by passing an written exam
ü If your certification becomes inactive before completing the CE requirements
§ Credits earned for a given course can only be counted once within the recertification
cycle
v Repeating the same course will not count towards recertification credits
§ Credits, once used, cannot be reused for any other certification track or level
§ Credits must be used either
Ø before they expire
Ø or during the certification cycle in which they were earned
v whichever occurs earlier
§ CE administrative fee must be paid once you have earned all of credits
§ You can pay the fee by visiting
www.cisco.com/go/continuingeducation
LTRCCIE-3401 © 2017 Cisco and/or its affiliates. All rights reserved. Cisco Public 154
3D/Virtual Reality
Developed by the CCIE team

• Industry first from industry leader


• State-of-the-art Virtual Reality (VR)
solution
• 3D visualization of technical content
Live IOL and L2IOL instance running inside the VR application
• Interacts with simulated physical
environment and virtualized
Racks Racks
infrastructure
• Custom API that integrates IOL
with VR application
3D graphics 3D graphics

© 2017 Cisco and/or its affiliates. All rights reserved. Cisco Confidential

LTRCCIE-3401 © 2017 Cisco and/or its affiliates. All rights reserved. Cisco Public
Virtual Reality
BeTheRouter (BTR) TroubleshootTheLab (TTL)

Available in the
Certifications Lounge
June 26-29

Live DEMO @ the Certification Lounge!


LTRCCIE-3401 © 2017 Cisco and/or its affiliates. All rights reserved. Cisco Public 156
Reference
Preparation Materials
• Configuration Guide, Products, Technology
• Cisco Tools, Cisco Press, Whitepapers
• Cisco Learning Network (CLN)
• Design Zone, Cisco Forums
• Cisco Training Program
• External Resources
https://supportforums.cisco.com
http://docwiki.cisco.com
www.cisco.com/go/documentation
www.cisco.com/go/tools

LTRCCIE-3401 © 2017 Cisco and/or its affiliates. All rights reserved. Cisco Public 158
Recommended Reading

LTRCCIE-3401 © 2017 Cisco and/or its affiliates. All rights reserved. Cisco Public 159
Cisco SP Certification & Product Training Portfolio
Next-Generation Networks
Training and certification of capabilities and skills required
Foundation for: Business Critical for end-to-end of next generation SP infrastructure
and Digital Transformation
CCNA CCNP CCIE Products
SPNGN1 SPROUTE SPCORE Written Exam NCS, CRS
SPNGN2 SPADVROUTE SPEDGE Lab Exam

• SP Routing, SP Mobility, Optical Networking, SP Video


• BGP, MPLS
• Segment Routing
• NSO
• Network Programmability, Virtualization
• IOS-XR
• Cisco Certifications Training
https://learningnetwork.cisco.com/community/certifications
http://www.cisco.com/c/en/us/training-events/resources/learning-services/technology.html

LTRCCIE-3401 © 2017 Cisco and/or its affiliates. All rights reserved. Cisco Public 160
SP Skills Required for Digital Business Transformation
SP Open Network Architecture

SP Transformation with SDN, NFV, Cloud

Security, Analytics, Open APIs and Model-based


Job roles have evolved:
Automation
Expanded responsibilities,
deep knowledge Virtualization and Cloud Transformation
and skills

Manage policy-driven infrastructure across physical &


virtual resources

71% enterprise IT will increase investment in DC professionals 2015 – 2018 *

* AFCOM State of Data Center Survey, 2015

LTRCCIE-3401 © 2017 Cisco and/or its affiliates. All rights reserved. Cisco Public 161
Service Provider Certification Portfolio

Job Role, Provides Role-based, Achieve greater


Technology based validation of skills extensive hands- ROI
certification portfolio and certification on training and faster results

LTRCCIE-3401 © 2017 Cisco and/or its affiliates. All rights reserved. Cisco Public 162
Service Provider Cisco Education Offerings
Course Description Cisco Certification
Deploying Cisco Service Provider Network Routing SPROUTE covers the implementation of routing protocols (OSPF, IS-IS, BGP), CCNP Service Provider®
(SPROUTE) & Advanced (SPADVROUTE) route manipulations, and HA routing features; SPADVROUTE covers advanced
routing topics in BGP, multicast services including PIM-SM, and IPv6;
Implementing Cisco Service Provider Next-Generation
Core Network Services (SPCORE) SPCORE covers network services, including MPLS-LDP, MPLS traffic engineering,
QoS mechanisms, and transport technologies;
Edge Network Services (SPEDGE) SPEDGE covers network services, including MPLS Layer 3 VPNs, Layer 2 VPNs,
and Carrier Ethernet services; all within SP IP NGN environments.

Building Cisco Service Provider Next-Generation The two courses introduce networking technologies and solutions, including OSI CCNA Service Provider®
Networks, Part 1&2 (SPNGN1), (SPNGN2) and TCP/IP models, IPv4/v6, switching, routing, transport types, security, network
management, and Cisco OS (IOS and IOS XR).

Implementing Cisco Service Provider Mobility UMTS The three courses (SPUMTS, SPCDMA, SPLTE) cover knowledge and skills Cisco Service Provider Mobility
Networks (SPUMTS); required to understand products, technologies, and architectures that are found in CDMA to LTE Specialist;
Implementing Cisco Service Provider Mobility CDMA Universal Mobile Telecommunications Systems (UMTS) and Code Division Multiple Cisco Service Provider Mobility UMTS
Networks (SPCDMA); Access (CDMA) packet core networks, plus their migration to Long-Term Evolution to LTE Specialist
Implementing Cisco Service Provider Mobility LTE (LTE) Evolved Packet Systems (EPS), including Evolved Packet Core (EPC) and
Networks (SPLTE) Radio Access Networks (RANs).

Implementing and Maintaining Cisco Technologies Service Provider/Enterprise engineers to implement, verification-test, and optimize Cisco IOS XR Specialist
Using IOS XR (IMTXR) core/edge technologies in a Cisco IOS XR environment.

For more details, please visit: http://learningnetwork.cisco.com


Questions? Visit the Learning@Cisco Booth

LTRCCIE-3401 © 2017 Cisco and/or its affiliates. All rights reserved. Cisco Public 163
Internet of Things (IoT) Cisco Education Offerings
Course Description Cisco Certification
NEW! Managing Industrial Networks for An associate level instructor led lab based training focuses CCNA® Industrial
Manufacturing (IMINS2 v1.3) on common industrial application protocols, security, wireless
and troubleshooting designed to prepare you for the CCNA
Industrial certification
Managing Industrial Networks with This instructor led lab based training addresses foundational Cisco Industrial
Cisco Networking Technologies (IMINS) skills needed to manage and administer networked industrial Networking Specialist
control systems for today's connected plants and enterprises.
It helps prepare plant administrators, control system
engineers and traditional network engineers for the Cisco
Industrial Networking Specialist certification.
Control Systems Fundamentals For IT and Network Engineers, provides an introduction to Pre-learning for IMINS,
for Industrial Networking (ICINS) industry IoT verticals, automation environment and an IMINS2 training &
overview of industrial control networks (E-Learning) certifications
Networking Fundamentals For Industrial Engineers and Control System Technicians, Pre-learning for IMINS,
for Industrial Control Systems (INICS) covers basic IP and networking concepts, and introductory IMINS2 training &
overview of Automation industry Protocols. certifications
For more details, please visit: http://learningnetwork.cisco.com
Questions? Visit the Learning@Cisco Booth

LTRCCIE-3401 © 2017 Cisco and/or its affiliates. All rights reserved. Cisco Public 164
Network Programmability Cisco Education Offerings
Course Description Cisco Certification
Developing with Cisco Network Programmability Provides Application Developers with comprehensive curriculum to Cisco Network Programmability
(NPDEV) develop infrastructure programming skills; Developer (NPDEV) Specialist
Addresses needs of software engineers who automate network Certification
infrastructure and/or utilize APIs and toolkits to interface with SDN
controllers and individual devices
Designing and Implementing Cisco Network Provides network engineers with comprehensive soup-to-nuts curriculum Cisco Network Programmability
Programmability (NPDESI) to develop and validate automation and programming skills; Design and Implementation
Directly addresses the evolving role of network engineers towards more (NPDESI) Specialist Certification
programmability, automation and orchestration

Programming for Network Engineers (PRNE) Learn the fundamentals of Python programming – within the context of Recommended pre-requisite for
performing functions relevant to network engineers. Use Network NPDESI and NPDEV Specialist
Programming to simplify or automate tasks Certifications

Cisco Digital Network Architecture This training provides students with the guiding principles and core None
Implementation Essentials (DNAIE) elements of Cisco’s Digital Network Architecture (DNA) architecture and its
solution components including; APIC-EM, NFV, Analytics, Security and
Fabric.

For more details, please visit: http://learningnetwork.cisco.com


Questions? Visit the Learning@Cisco Booth

LTRCCIE-3401 © 2017 Cisco and/or its affiliates. All rights reserved. Cisco Public 165
Cloud Cisco Education Offerings
Course Description Cisco Certification
Learn how to perform foundational tasks related to
Understanding Cloud Fundamentals (CLDFND)
Cloud computing, and the essentials of Cloud CCNA Cloud
Introducing Cloud Administration (CLDADM)
infrastructure, administration and operations
Implementing and Troubleshooting the Cisco Cloud Infrastructure (CLDINF);
Obtain professional level skills to design, automate,
Designing the Cisco Cloud (CLDDES);
secure, provision and manage private and hybrid CCNP Cloud
Automating the Cisco Enterprise Cloud (CLDAUT);
Clouds
Building the Cisco Cloud with Application Centric Infrastructure (CLDACI)

Product Training Portfolio:


Gain in-depth hands-on skills using Cisco solutions
UCS Director: UCSDF, UCSDACI
to configure, deploy, manage and troubleshoot
Prime Service Catalog: PSCF, PSCI, PSCD
Cloud deployments
MetaPod: MPODF20

For more details, please visit: http://learningnetwork.cisco.com


Questions? Visit the Learning@Cisco Booth

LTRCCIE-3401 © 2017 Cisco and/or its affiliates. All rights reserved. Cisco Public 166
Data and Analytics Cisco Education Offerings
Course Description
ANDMB – Data Management, Architecture and Applications Provides hands on training with a technical mix of application, compute, storage and
networking topics concerning the deployment of Big Data clusters.

ANDMA – Advanced Data Management, Architecture and Covers major architecture design to cater to different needs of the application, data center or
Applications deployment requirements. It provides architectural designs and advanced hands-on training on
topics covering Scaling of cluster to thousands of nodes and management, Data Life Cycle
management with HDFS tiered storage, and different approaches for Multi-tenant Hadoop
cluster deployments with Openstack
ANCISB – Basic Course in Data Virtualization based on Cisco Hands-on accelerated training on installing and developing with Cisco Information Server
Information Server Application Data Services. It provides technical guidance to engineers who will be performing
complex integration activities.

ANCISV – Advanced Course in Data Virtualization based on Recommended course for administrators who need to understand how Cisco Information
Cisco Information Server Server fits into their environment and the types of administration tasks typically required by the
product.
ANCISM – Administration Course in Data Virtualization based Course is for candidates who are familiar with Cisco Data Virtualization “basics” and want to
on Cisco Information Server focus on advanced Cisco Information Server features.

Data and Analytics training page: http://www.cisco.com/c/en/us/training-events/resources/learning-services/technology/data-analytics.html


For more details, please visit: http://learningnetwork.cisco.com
Questions? Visit the Learning@Cisco Booth

LTRCCIE-3401 © 2017 Cisco and/or its affiliates. All rights reserved. Cisco Public 167
Digital Business Transformation Cisco Education
Course Description Cisco Certification
For IT and Network Professionals:

Building Business Specialist Skills • Builds non-technical skills key to ensure business impact and influence. Cisco Enterprise IT
Topics include: business analysis, finance, technology adoption and Business Specialist
effective communications.

• Bridges IT and business impacts of mature and emerging solutions


including cloud plus Internet of Everything
For Technology Sellers:

Applying Cisco Specialized Business Value Builds skills to discover and address technology needs using a business- Cisco Business Value Specialist
Analysis Skills focused, consultative sales approach
Executing Advanced Cisco Business Value Enables customer transformation through business architecture and Cisco Certified Business
Analysis and Design Techniques solution selling expertise Value Practitioner
Performing Cisco Business-Focused Provides skills and an approach to build a strategic roadmap of IT Cisco Transformative
Transformative Architecture Engagements initiatives, aligned to business priorities Architecture Specialist
Cisco Customer Success Manager Specialist Prepares for the crucial role that drives adoption and enablement, ensuring Cisco Certified Customer
that customers achieve their expected business outcomes, and reduces Success Manager
churn/increases renewal for services and subscription based products.

For more details, please visit: http://learningnetwork.cisco.com


Questions? Visit the Learning@Cisco Booth

LTRCCIE-3401 © 2017 Cisco and/or its affiliates. All rights reserved. Cisco Public 168

You might also like