Home > AAAdot1x Lab Sim

AAAdot1x Lab Sim

May 17th, 2014 in Lab Sim, LabSim Go to comments

Question

Answer and Explanation

 

1) Configure ASW1

Enable AAA on the switch:
ASW1(config)#
aaa new-model

The new-model keyword refers to the use of method lists, by which authentication methods and sources can be grouped or organized.

Define the server along with its secret shared password:
ASW1(config)#radius-server host 172.120.39.46 key rad123

ASW1(config)#aaa authentication dot1x default group radius
This command causes the RADIUS server defined on the switch to be used for 802.1x authentication.

Globally enable port-based authentication (802.1x) on a switch:
ASW1(config)#dot1x system-auth-control

Configure Fa0/1 to use 802.1x:

ASW1(config)#interface fastEthernet 0/1
ASW1(config-if)#dot1x port-control auto
Notice that the word “auto” will force connected PC to authenticate through the 802.1x exchange.

2) Configure DSW1:

Define an access-list:
DSW1(config)#ip access-list standard 10 (syntax: ip access-list {standard | extended} acl-name)
DSW1(config-std-nacl)#permit 172.120.40.0 0.0.0.255
DSW1(config-std-nacl)#exit

Define an access-map which uses the access-list above:
DSW1(config)#vlan access-map MYACCMAP 10 (syntax: vlan access-map map_name [0-65535] )
DSW1(config-access-map)#match ip address 10 (syntax: match ip address {acl_number | acl_name})
DSW1(config-access-map)#action forward
DSW1(config-access-map)#exit

DSW1(config)#vlan access-map MYACCMAP 20
DSW1(config-access-map)#action drop (drop other networks)
DSW1(config-access-map)#exit

Apply a vlan-map into a vlan:
DSW1(config)#vlan filter MYACCMAP vlan-list 20 (syntax: vlan filter mapname vlan-list list)

DSW1#copy running-config startup-config

(Notice: Many reports said the copy running-config startup-config didn’t work but they still got the full mark)

Other lab-sims in this site:

LACP with STP Sim
MLS and EIGRP Sim
VTP Lab 2
VTP Lab
Spanning Tree Lab Sim

Comments
Comment pages
1 30 31 32 41
  1. Mahmoud
    January 5th, 2017

    Please i need the 201q,

    {email not allowed}

    Thanks in advance :)

  2. Anonymous
    January 6th, 2017

    Please send 201q to scottpru124 at gmail dot com

    Thanks!!

  3. Mahmoud
    January 6th, 2017

    dear all

    Please I need 201q ASAP, sent at ( Mahmoud.Mahfouz22 at gmail dot com

    Thanks in Advance.

  4. Anonymous
    January 7th, 2017

    Please send a copy of the 201 Q at {email not allowed}, thanks

  5. Anonymous
    January 7th, 2017

    Please send a copy of the 201 Q at mpl80766atgmaildotcom, thanks

  6. TheGrownUpGeek
    January 7th, 2017

    With regards the 201q dump referenced above? Can anyone link to a recent valid dump file please. Or Upload to https://1drv.ms/f/s!AloRTk2sdKZegbsl9HXmM66WslOSOg
    Thanks in Advance

  7. von Beck
    January 7th, 2017

    Hi Guys, cleared my exam yesterday with 87x. all the questions were from 191q dump, so it is valid.
    Labs: LACP with STP, HSRP and AAA dot1x pretty much the same as it is here on certprepare.

    1. Had a problem with AAA config (which you have to do blindly, yoi can’t test it). On ASW1, int fa0/1 when I started to configure “dot1x port-control auto” the switch returned me to the main root suddenly. The staff from Pearson Vue didn’t help me. Never had a similar experience before! Suspect something is wrong in that lab sim….DSW1 could configure normally.

    2. LACP with STP: ” switch trunk encapsulation dot1q” you have to configure only for switch B.
    With “show version” you can check the device version type.
    SVI vlan 1 was already configured.
    “int range fa0/x-y” did not work for me. So I had to configure interfaces individually one by one.
    You have to enter “no switchport mode access” and “no switchport access vlan 98” as well in fa0/3-4

    As far as etherchannel is concernerd I did the config on port-channel 1 as well although it was explicitly written that configuration must be performed on the physical interface.

    Make sure you always check with “sh run”, “sh ip int brief”, “sh vlan “, “sh ver” commands the lab and your config. Don’t forget “no shut” for the interfaces and “”copy run start” at the end.

    Good luck , heading now for routing.

    Zdrastvuj.

  8. 7oda
    January 7th, 2017

    any simulation for this lab ?

  9. jack reacher
    January 7th, 2017

    Dear all,
    Please send 201q to {email not allowed}

  10. jack reacher
    January 7th, 2017

    k1685597@mvrhtcom

  11. Anonymous
    January 8th, 2017

    Dear All,

    I am taking 300-115 on Jan 17. Kindly please share q201 and q191. Email – tedman2017@gmail dot com

    Please?

  12. Ted
    January 8th, 2017

    Dear All,

    I am taking 300-115 on Jan 17. Kindly please share q201 and q191. Email – tedman2017@gmail dot com

  13. Renju
    January 9th, 2017

    Dears…kindly send 201q to renjith8 at gmail dot com

  14. mt
    January 9th, 2017

    please e-mail 201q. I have the exam monday.
    {email not allowed}
    thanks

  15. mt
    January 9th, 2017

    please e-mail 201q. I have the exam monday.
    matt.taylor999 at googlemail dot com
    thanks

  16. Mark
    January 9th, 2017

    Hi, Dear friends, can you share to me the 201q.
    Please send it to {email not allowed}

  17. Anonymous
    January 9th, 2017

    hello
    some body have vce 300-115 201q Dump please send me to the mail please
    {email not allowed}

  18. Mark
    January 9th, 2017

    One more time =)
    Hi, Dear friends, can you share to me the 201q.

    Please send it to markrudencko at yandex dot ru

  19. Anonymous
    January 10th, 2017

    Can you share with me 201q
    {email not allowed}

  20. Anonymous
    January 10th, 2017

    Can you share with me 201q ?
    emreodabasiiu at gmail dot com

  21. dumps
    January 10th, 2017

    Please share 201 question to m4_prashanthymailcom

  22. ahemd erlrofaie
    January 10th, 2017

    Hi I pass the exam ccnp switching 300-115 yesterday with 979 score (9-1-2017) the questions here is enough , you don’t need to see any other dumps , and this site is still valid .
    but by the way if you have studied the 191 dump , it also valid and you can depend on it completely , so it is your choice to study this site or the 191 dump both are valid.
    Regarding to the simulations it were:
    1-lacp question
    2-aaa dot1x
    3-hsrp question

    Important note:
    Regarding to Lacp question it is important to know that, after creating the port-channel (the logical port) , you have to implement the trunk configuration under the physical interfaces
    You can do that through entering the interface range f0/3-4 and follow the bellow configuration:
    SW-A(config-if-range)# switchport mode trunk
    SW-A(config-if-range)# switchport trunk native vlan 99
    SW-A(config-if-range)# switchport trunk allowed vlan 1, 21-23
    SW-A(config-if-range)#no shutdown

    The reason for that, it because the question ask you to implement all the configuration under the physical interfaces, so configuration under the logical port is not recommended
    I wish for you the best

  23. Bob
    January 10th, 2017

    Can you share with me 201q or 191q
    my address is bestlover2707 at gmail dot com

  24. ahemd erlrofaie
    January 11th, 2017

    Hi every one for any one need the latest pass4sure dumps for ccnp routing , ccnp switching , ccnp tshoot
    Send email on ahmedrofaii at gmail dot com
    They are valid and for free
    Also I have the 191 dump for ccnp switching
    I wish good luck for you all

  25. Anonymous
    January 11th, 2017

    Can you share with me 201q TO ntaratibu at gmail dot com

    Thanks in advance!

  26. Jamespam
    January 11th, 2017

    Das bekannte Steinbeis-Europa-Zentrum führt regelmäßig Untersuchungen und Studien rund um die Ernährung des Menschen durch.Sie möchten von ihren geliebten Ernährungsgewohnheiten kein Stück abrücken und halten sich daher krampfhaft an der Vorstellung fest, sie seien nun einmal ein Allesfresser.000 Mitarbeiter.Welche tricks gibt es damit man seinen bauch und beine d nner wirken lassen kann.Beides kannst du direkt unter diesem Artikel kostenlos anfordern.Darunter versteht man eine Entz ndung der Herzinnenhaut.August 1945 war er als Soldat im Krieg, anschlie end in Kriegsgefangenschaft.auf dein Gewicht ist alles okay.Schritt für Schritt 10 Kilo abnehmen.
    http://ilzxdtlg.xsl.pt/7oq9univ7n172nw-m99f4.html

  27. Mahmoud
    January 11th, 2017

    Just passed 300-115 today with 954, 191q still valid,

    LACP with STP

    SW-B

    no need to config vlan 1, because it’s already configured with ip address 192.168.1.11/24
    and also it’s configured on SW-A with ip address 192.168.1.10/24

    but I have configured ip default-gateway on both switches, with ip address 192.168.1.1/24, show cdp neighbor doesn’t show the ip of the router, so i just made like that, and it worked well and all switches can ping the router and can ping each other,

    – I put the configuration under physical interface ” fa0/3 and 0/4 ” as the mentioned in the exam that we have to put it under physical interface level,

    – vlan 11,12 and 13 already configured on SW-A

    I started configuration with SW-B first, I just made that cause when I was trying the lap on the Packet tracer, if I started with SW-A it will give me error with port ” fa0/3 and fa0/4 ” on SW-B that dtp is on, and the port is not compatible, I just was afraid if that would happened on the exam too, so I started configure SW-B first ….. so maybe it’s meaningless and you can start with any switch of them …

    * AAA Lab is the same as here!

    * HSRP lab

    you should focus on the question, it’s almost the same question but sometimes ther change the port number like ” fa0/0 instead of fa0/1 “, exchange between R1 and R2.

    Best of luck for all of you.

  28. MCA
    January 11th, 2017

    Hi Mahmoud,

    Congrats on passing the exam. Were you able to save the config for the lab questions. If so, which command was used.

  29. Areak Jai
    January 12th, 2017

    Hi People i am due to take my ccnp Exam very soon, But i have not been able to practice the AAADOt1x Question. How are you guys practicing for this lab??

  30. Anonymous
    January 12th, 2017

    q201 can someone send me by mail {email not allowed}

  31. BGP_MAN
    January 14th, 2017

    I am writing on 17/1/17 wish me the best luck

    very special date for a special exam. :)

  32. Anonymous
    January 16th, 2017

    Hi can anybody send me latest dump please (201 q i think)… mailto: asecret900 at gmail.com

    I am sitting 300-115 exam 17Jan 2017. Many thanks :)

  33. Anonymous
    January 16th, 2017

    Can you share with me 201q TO ntaratibu at gmail dot com

    Thanks in advance!

  34. Anonymous
    January 16th, 2017

    i have passed the exam today with 958. 191q still valid
    LACP-STP
    AAA dot1x
    HSRP
    in LACP-STP

    do this switchport trunk allawed vlan 1,21-23 on both sides under the physical interface or under the logical interface.

    Good luck
    see you guys in the tshoot exam.

  35. GYH
    January 16th, 2017

    Hi can Anonymous or someone else send me the 958.191q or 201q. my email: {email not allowed}

  36. GYH
    January 16th, 2017

    i can Anonymous or someone else send me the 958.191q or 201q. my email gyh.beauty at gmail.com

  37. GYH
    January 16th, 2017

    Hi can Anonymous or someone else send me the 958.191q or 201q. my email gyh.beauty at gmail.com

  38. Anonymous
    January 17th, 2017

    please i need 201q 300-115 send me {email not allowed}

  39. kokwkz
    January 17th, 2017

    in this lap :after applying the configuration how to know if that correct or now is there any way to know ??

  40. Anonymous
    January 17th, 2017

    hi every one
    aaa new model
    in configuration ip address is
    radius-server host 172.120.39.46 key rad123
    but in question
    radius-server host 172.120.40.46 key rad123

    what does ir mean…

  41. Anonymous
    January 17th, 2017

    Today i passed the CCNP Switch exam. 191a is still valid.
    Labs=aaa, hsrp and lacp
    In LACP lab, there was written in question to apply config on PHYSICAL INTERFACE. So when i just applied config on logical interface it didnt work.
    Hence its a advice to forcefully apply config on physical interfaces…..

  42. Sooraj Mathew
    January 17th, 2017

    Hi guys,
    am preparing to write ccnp switch exam soon in a month. i was in search of dumps .i saw discussing here about 191q & 201q dumps.so please help me out to prepare for exam. pls mail me the dumps to soorajnila82 at gmail dot com …..thanks in advance .god bless.

  43. kokwkz
    January 17th, 2017

    in this lap :after applying the configuration how to know if that correct or now is there any way to know ?????

  44. Anonymous
    January 18th, 2017

    @Anonymous, when u apply the configuration on the physical interface only, was the ether-channel was up at the end. Did u check the ether-channel status at last?
    Also did u configured ip default-gatway in Sw1 & SW2?
    Thanks in Advance

Comment pages
1 30 31 32 41
  1. No trackbacks yet.