HP0-Y43: IMPLEMENTING HP NETWORK INFRASTRUCTURE SOLUTIONS HP Netwrking Exam preparatin guide
HP0-Y43: IMPLEMENTING HP NETWORK INFRASTRUCTURE SOLUTIONS HP Netwrking Exam preparatin guide Overview Requirements fr successful cmpletin This guide helps yu t study fr the Implementing HP Netwrk Infrastructure Slutins (HP0-Y43) exam. Yu can benefit frm this guide whether yu are attempting t expand yur existing HP certificatin r yu have a frmer H3C r a Cisc backgrund and want t get certified with HP. T pass the exam, yu will need t demnstrate knwledge f intermediate ruting and switching technlgies, such as Open Shrtest Path First (OSPF) ruting, multicast frwarding, multicast ruting, Quality f Service (QS), WAN technlgies, and mre as well as the ability t implement these technlgies n HP A-Series and E-Series prducts. Yu must als be able t implement a wide variety f security technlgies built int HP prducts. 2
Table f Cntents Overview... 2 Table f Cntents... 3 Why take the exam?... 5 HP ASE Netwrk Infrastructure [2011] certificatin... 5 Path 1... 5 Path 2... 5 Path 3... 5 HP ASE Wireless Netwrks [2011] certificatin... 6 Path 1... 6 Path 2... 7 Path 3... 7 Path 4... 7 Wh shuld take the exam?... 8 Wh des nt need t take this exam?... 9 Hw t study fr the exam... 9 Study tips based n yur certificatin... 10 HP AIS [2011]... 10 Any ASE certificatin... 11 H3CSE certificatin... 11 CCDP, CCNP Ruting and Switching r Wireless certificatin... 11 Attend recmmended ILTs... 11 HP Cre/Distributin Netwrk Technlgies using PrVisin Sftware... 12 Tpics cvered... 12 Frmat ffered... 12 Mre infrmatin... 12 HP Cre/Distributin Netwrk Technlgies using Cmware Sftware... 12 Tpics cvered... 12 Frmat ffered... 13 Mre infrmatin... 13 Implementing HP Netwrk Infrastructure Security... 13 Tpics cvered... 13 Frmat ffered... 14 Mre infrmatin... 14 Accelerated HP Cre/Distributin Layer Netwrk Technlgies... 14 Tpics cvered... 14 Frmat ffered... 14 Mre infrmatin... 14 Purchase self-study materials... 15 Cmplete recmmended WBTs... 15 HP Switching and Ruting Technlgies... 15 Tpics cvered... 15 Frmat ffered... 16 Mre infrmatin... 16 HP Internet and WAN Technlgies... 16 Tpics cvered... 16 Frmat ffered... 17 Mre infrmatin... 17 HP Netwrk Infrastructure Security Technlgies... 17 Tpics cvered... 17 Frmat ffered... 18 Mre infrmatin... 18 Refer t additinal materials... 18 3
Obtain hands-n experience... 18 Hw t take the Implementing HP Netwrk Infrastructure Slutins (HP0-Y43) exam... 18 Exam cntent... 19 Cmments n the exam... 20 Tips fr taking HP exams... 20 Register... 20 Sample questins... 20 Cnclusin... 23 Appendix: Answers t the sample questins... 24 4
Why take the exam? Passing this test gives yu ne cmpnent tward tw HP Accredited Slutins Expert (ASE) certificatins, described belw. NOTE Anyne can take the exam, but passing it nly helps yu t achieve certificatin if yu have ne f the prir achievements listed in Table 1. If yu are a new candidate, btain the HP ASE Netwrk Infrastructure [2011] certificatin first. HP ASE Netwrk Infrastructure [2011] certificatin The HP ASE Netwrk Infrastructure [2011] certificatin indicates that yu can: Design, implement, and trublesht secure netwrk slutins fr large and cmplex, multivendr campus LAN envirnments using HP E- and A-Series netwrk technlgies Design and implement an HP pen-standards based netwrk slutin, including thse that interperate with nn-hp netwrking slutins There are three paths t achieve this certificatin, as utlined belw. The exams yu must pass are dependent upn which achievements yu currently hld. Path 1 This path is designed fr netwrking prfessinals wh have ne f the fllwing certificatins: ASE HP PrCurve (2008 r later) and HP Enterprise Netwrking Prducts Technical Qualificatin [2010] ASE HP PrCurve Campus LANs [2010] and HP Enterprise Netwrking Prducts Technical Qualificatin [2010] HP ASE Wireless Netwrks [2011] If yu meet ne f these criteria, yu d nt need t take the HP0-Y43 exam; passing the HP0-Y32 alne gives yu the certificatin. By cmpleting this path, yu will als be granted the HP AIS Netwrk Infrastructure [2011] certificatin. Path 2 This path is designed fr netwrking prfessinals wh have ne f the fllwing certificatins. ASE HP PrCurve (2008 r later) ASE HP PrCurve Campus LANs [2010] H3CSE CCNP Ruting and Switching CCDP If yu meet ne f these criteria, yu must pass the Implementing HP Netwrk Infrastructure Slutins (HP0-Y43) exam and Designing & Trubleshting Open Standard Netwrks (HP0-Y32) exam t earn the certificatin. If yu cmplete this path, yu will als be granted the HP AIS Netwrk Infrastructure [2011] certificatin. Path 3 If yu d nt meet the requirements fr path 1 r path 2, then yu must cmplete this path, which is designed fr new candidates. First, yu must achieve the prerequisite certificatin, HP AIS Netwrk Infrastructure [2011]. Secnd, yu must pass the fllwing exams: Implementing HP Netwrk Infrastructure Slutins (HP0-Y43) Designing & Trubleshting Open Standard Netwrks (HP0-Y32) Table 1 summarizes the requirements fr all three paths. 5
Requirements fr HP ASE Netwrk Infrastructure certificatin Table 1: HP ASE Netwrk Infrastructure [2011] requirements based n current achievement Current achievements Path 1 Path 2 Path 3 HP Enterprise Netwrking Prducts Technical Certificatin [2010] + either: ASE HP PrCurve (2008 r later) ASE HP PrCurve Campus LANs [2010] HP ASE Wireless Netwrks H3CSE CCNP Ruting and Switching* Or CCDP* Either ASE HP PrCurve (2008 r later) ASE HP PrCurve Campus LANs [2010] New r any ther candidate HP AIS Netwrk Infrastructure [2011] certificatin X Prctred Exam Implementing HP Netwrk Infrastructure Slutins (HP0-Y43) Prctred Exam Designing & Trubleshting Open-Standard Netwrks (HP0-Y32) X X X X X X X X X X *Prf f current credential status must be prvided t HP. CCNP specialties such as Vice r Security d nt apply tward HP ASE Netwrks Infrastructure [2011] certificatin. HP ASE Wireless Netwrks [2011] certificatin The HP ASE Wireless Netwrks [2011] achievement certifies that yu: Can design and implement cmplex WLAN netwrk slutins fr large campus LAN envirnments using HP E-Series wireless technlgies There are fur paths t achieve this certificatin, as utlined belw. The exams yu must pass are dependent upn which achievements yu currently hld. The HP0-Y43 exam is required nly fr Path 2 and Path 4 (but the ther paths are described fr yur reference). Path 1 This path is designed fr netwrking prfessinals wh have ne f the fllwing certificatins: HP ASE Netwrk Infrastructure [2011] HP Enterprise Netwrking Prducts Technical Qualificatin [2010] and ASE HP PrCurve (2008 r later) HP Enterprise Netwrking Prducts Technical Qualificatin [2010] and ASE HP PrCurve Campus LANs [2010] 6
If yu meet ne f these criteria, then passing the HP0-Y33 exam alne gives yu the certificatin. By cmpleting this path, yu will als be granted the HP AIS Netwrk Infrastructure [2011] certificatin if yu d nt already have it. Path 2 This path is designed fr netwrking prfessinals wh have ne f the fllwing certificatins. ASE HP PrCurve (2008 r later) ASE HP PrCurve Campus LANs [2010] H3CSE CCNP Wireless, CCNP Ruting & Switching CCDP If yu meet ne f these criteria, yu must pass the HP0-Y43 exam and the Implementing HP Wireless Netwrks (HP0-Y33) exam. By cmpleting this path, yu will als be granted the HP AIS Netwrk Infrastructure [2011] certificatin. Path 3 This path is designed fr netwrking prfessinals wh have the ASE HP PrCurve Mbility [2009 r 2010] certificatin. If yu meet this criterin, yu must pass the Wireless Netwrks ASE 2011 Delta (HP0-Y35) exam. By cmpleting this path, yu will als be granted the HP AIS Netwrk Infrastructure [2011] certificatin. Path 4 If yu d nt meet the requirements fr path 1, path 2, r path 3, then yu must cmplete this path, which is designed fr new candidates. First, yu must achieve the prerequisite certificatin, HP AIS Netwrk Infrastructure [2011]. Secnd, yu must pass the fllwing exams: Implementing HP Netwrk Infrastructure Slutins (HP0-Y43) exam Implementing HP Wireless Netwrks (HP0-Y33) exam Table 1 summarizes these requirements. 7
Requirements fr ASE Wireless certificatin Table 1: HP ASE Wireless Netwrks [2011] requirements based n current achievement Current achievements Path 1 Path 2 Path 3 Path 4 HP ASE Netwrk Infrastructure [2011] HP Enterprise Netwrking Prducts Technical Certificatin [2010] + either: ASE HP PrCurve (2008 r later) Either: ASE HP PrCurve (2008 r later) ASE HP PrCurve Campus LANs [2010] H3CSE CCNP Wireless* r CCNP Ruting and Switching * r CCDP * ASE HP PrCurve Mbility [2009 r 2010] New r any ther candidate ASE HP PrCurve Campus LANs [2010] HP AIS Netwrk Infrastructure [2011] certificatin Prctred Exam Implementing HP Netwrk Infrastructure Slutins (HP0-Y43) X X X X X Prctred Exam Implementing HP Wireless Netwrks (HP0-Y33) Prctred Exam Wireless Netwrks ASE 2011 Delta (HP0-Y35) X X X X X X X * Prf f current credential status must be prvided t HP. CCNP specialties such as Vice r Security d nt apply tward HP ASE Wireless Netwrks [2011] certificatin. Wh shuld take the exam? Anyne can take the Implementing HP Netwrk Infrastructure Slutins (HP0-Y43) exam, but mst successful candidates have tw years f real-wrld experience implementing r maintaining netwrk infrastructure slutins in a campus LAN r enterprise envirnment. Successful candidates als prepare fr the test in a variety f ways. This guide describes sme f these ways and prvides references t materials fr further preparatin. 8
NOTE Anyne can take the exam, but passing it nly helps yu t achieve certificatin if yu have ne f the prir achievements listed in Table 1 r Table 2. If yu are a new candidate, btain the HP AIS [2011] certificatin first. Wh des nt need t take this exam? Yu d nt need t take this exam if yu have achieved any f the fllwing: ASE HP PrCurve (2008 r later) and HP Enterprise Netwrking Prducts Technical Qualificatin [2010] ASE HP PrCurve Campus LANs [2010] and HP Enterprise Netwrking Prducts Technical Qualificatin [2010] HP ASE Wireless Netwrks [2011] ASE HP PrCurve Mbility (2009 r 2010) certificatin If yu have any f the first three achievements, yu nly need t take the Designing and Trubleshting Open Standard Netwrks (HP0-Y32) exam t btain the HP ASE Netwrk Infrastructure [2011] certificatin. If yu need the HP ASE Wireless Netwrks [2011] certificatin, yu can then take nly the Implementing HP Wireless Netwrks (HP0-Y33) exam. If yu have ASE HP PrCurve Mbility (2009 r 2010) certificatin, take nly the Wireless Netwrks ASE 2010 Delta (HP0-Y35) exam t earn the HP ASE Wireless Netwrks [2011] certificatin. Then, after yu pass the Designing and Trubleshting Open Standard Netwrks (HP0-Y32) exam, yu als receive the HP ASE Netwrk Infrastructure [2011] certificatin. Hw t study fr the exam The Implementing HP Netwrk Infrastructure Slutins (HP0-Y43) exam tests yu n tpics that are cvered in several HP instructr-led training (ILT) and Web-based training (WBT) curses. Table 3 indicates the training specifically recmmended fr yu based n yur current achievements. While it is recmmended that yu cmplete this training, the training is neither required nr des it guarantee that yu will pass the exam. It is expected that yu will als study n yur wn and draw n yur real-wrld experience. Read the sectins belw t further assess yur ptins. Even if yu d nt intend t cmplete the recmmended ILTs and WBTs, yu shuld examine the tpics that they cver because the exam will test yu n yur mastery f these tpics. 9
Curses fr the HP0Y43 exam Table 3: Recmmended training based n current achievement Current achievements HP AIS [2011] ASE HP PrCurve (2008 r later) ASE HP PrCurve Campus LANs [2010] H3CSE CCNP Ruting and Switching CCNP Wireless CCDP HP Cre/Distributin Netwrk Technlgies using Cmware Sftware (5-day ILT) HP Cre/Distributin Netwrk Technlgies using PrVisin Sftware (4-day ILT) X X X X X X X X X Implementing HP Netwrk Infrastructure Security (2-day ILT) X X X X HP Switching and Ruting Technlgies (WBT) X X Internet and WAN Technlgies (WBT) HP Netwrk Infrastructure Security Technlgies (WBT) Ttal days fr recmmended training X X X X X X 11 days 5 days 5 days 6 days 11 days 11 days NOTE There is als a furth HP ILT, Accelerated HP Cre/Distributin Layer Netwrk Technlgies, which cmbines the cntent cvered in the three ILTs listed in Table 3 and is cmpleted in just 5 days. Mre infrmatin n all fur ILTs including the recmmended qualificatins fr candidates attending the Accelerated curse is available in this exam preparatin guide. Mre infrmatin is als prvided n the WBTs. Study tips based n yur certificatin First yu might want t chse tpics n which t fcus based n yur current skills: HP AIS Netwrk Infrastructure [2011] Any ASE H3CSE CCDP, CCNP Ruting and Switching r Wireless Yu can then read abut specific study methds. HP AIS [2011] With yur current certificatin, yu are ready t succeed at training at the ASE level. All f the training at this level is recmmended fr yu t give yu the best chances at succeeding. This guide als prvides ther suggestins fr preparing. T learn mre abut ways t prepare fr the Implementing HP Netwrk Infrastructure Slutins (HP0-Y43) exam, cntinue reading, beginning at: Attend recmmended ILTs. 10
Any ASE certificatin Yur current knwledge f HP E-Series prducts, including their security features, shuld be sufficient. (Of curse, yu might need t review if yu received yur certificatin several years ag.) Hwever, yu will need t expand yur knwledge f the HP A-Series prducts and technlgies t pass the exam. As indicated in the table, yu might cnsider taking just the HP Cre/Distributin Netwrk Technlgies using Cmware Sftware ILT and reviewing the Internet and WAN Technlgies WBT, if yu have nt cmpleted that WBT befre. T learn mre abut ways t prepare fr the Implementing HP Netwrk Infrastructure Slutins (HP0-Y43) exam, cntinue reading, beginning at: Attend recmmended ILTs. H3CSE certificatin Yur current knwledge f HP A-Series prducts shuld be sufficient. Hwever, yu must understand hw t implement the same prtcls with which yu are familiar n A-Series prducts n E-Series prducts as well. In additin, yu must be able t implement netwrk security n bth HP A-Series and E-Series prducts as well as understand general cncepts related t HP security technlgies. Yu shuld take the ILTs and WBTs recmmended t yu. T learn mre abut ways t prepare fr the Implementing HP Netwrk Infrastructure Slutins (HP0-Y43) exam, cntinue reading, beginning at: Attend recmmended ILTs. CCDP, CCNP Ruting and Switching r Wireless certificatin The Implementing HP Netwrk Infrastructure Slutins (HP0-Y43) exam tests bth yur general knwledge f intermediate switching, ruting, and security technlgies as well as yur specific ability t implement these technlgies n HP prducts. As a Cisc-certified prfessinal, yu shuld nt find the general knwledge questins difficult althugh yu might want t review cncepts that yu have nt studied recently using the WBTs described later in this guide. In particular, if yu have the Wireless certificatin, yu might need t expand yur knwledge f switching and security technlgies. While yu d nt need t prduce exact CLI cmmands frm memry, yu must demnstrate that yu can navigate HP prducts CLIs and fllw the prper prcedures t cnfigure settings. If yu d nt attend the recmmended ILTs, which prvide hands-n experience in a lab, yu shuld practice cnfiguring the switching and ruting technlgies cvered in the curses n actual HP A-Series and E-Series prducts. T learn mre abut ways t prepare fr the exam, cntinue reading, beginning at: Attend recmmended ILTs. Attend recmmended ILTs Fur ILTs are available t help yu t prepare fr this exam. The first three are: HP Cre/Distributin Netwrk Technlgies using PrVisin Sftware, Rev 10.41 r later (4 days) HP Cre/Distributin Netwrk Technlgies using Cmware Sftware, Rev. 11.41 r later (5 days) Implementing HP Netwrk Infrastructure Security, Rev. 10.41 r later (2 days) Yu are highly encuraged t attend these curses, where yu will expand yur knwledge f netwrking and security technlgies and gain hands-n experience implementing these technlgies n HP equipment. Yu may als have the ptin f taking Accelerated HP Cre/Distributin Layer Netwrk Technlgies, Rev. 11.31 r later as an alternative t the three ILTs listed abve. This ILT cmbines HP Cre/Distributin Netwrk Technlgies using PrVisin Sftware, HP Cre/Distributin Netwrk Technlgies using Cmware Sftware, and Implementing HP Netwrk Infrastructure Security and delivers the material in a cmpressed timeframe: 5 days instead f 11. Qualificatins fr this curse are listed belw. Yu can register fr these ILTs in The Learning Center f yur HP Partner Prtal, which is the HP Learning Management System fr HP custmers and partners. Yu will require an HP Learner ID t register fr a class. Nte that, while it nly takes a few minutes t request the ID, the prcess f activating it may take up t several days. Please btain this ID and then register fr classes at least ne week in advance. Csts and scheduling vary accrding t regin. 11
HP Cre/Distributin Netwrk Technlgies using PrVisin Sftware HP Cre/Distributin Netwrk Technlgies using PrVisin Sftware describes techniques fr designing and implementing resilient switched and ruted cnverged netwrks based n the HP E-Series PrVisin ASIC switches. These netwrks will be capable f fulfilling the triple play requirement f supprting vice, vide, and data transmissins n a unified infrastructure. Tpics cvered In this curse, yu learn abut: PrVisin ASIC netwrking prducts and technlgies Prviding redundant links and default gateways with Multiple Spanning Tree Prtcl (MSTP)/Virtual Ruter Redundancy Prtcl (VRRP) Designing and implementing IPv4 netwrks Designing and implementing OSPFv2 ruting Designing and implementing Layer 2 and Layer 3 QS Designing and implementing Internet Grup Management Prtcl (IGMP), Prtcl Independent Multicast Sparse Mde (PIM-SM), and PIM-Dense (PIM-DM) Designing and implementing QinQ Designing and implementing IPv6, OSPFv3, and DHCPv6 Frmat ffered 4-day instructr-led curse, 40% lecture and 60% hands-n labs and classrm activities. The curse may be delivered using a remte lab envirnment. Mre infrmatin If yu are interested, the curse datasheet discusses HP Cre/Distributin Netwrk Technlgies using PrVisin Sftware in mre detail. It is available at http://h17007.www1.hp.cm/us/en/training/certificatins/technical/ase-netwrk-infrastructure.aspx. HP Cre/Distributin Netwrk Technlgies using Cmware Sftware The HP Cre/Distributin Netwrk Technlgies using Cmware Sftware curse fcuses n the advanced features required in enterprise level netwrks and hw they can be implemented in HP Netwrking A-Series switches and ruters. After successful cmpletin f this curse, yu will have acquired the cncepts and the skills necessary t install, maintain and trublesht an HP A-Series enterprise level netwrk. Tpics cvered This curse teaches yu abut these tpics: Special VLAN types: Prt-based VLANs Prtcl-based VLANs IP-subnet-based VLANs MAC-address-based VLANs SuperVLANs Islate-user VLANs IP gateway features IP ruting Lcal-prxy-ARP MSTP + VRRP redundancy slutin OSPF netwrk types and multi-area netwrks BGP 12
IP multicast QS IPv6 IGMP IGMP snping Multicast VLAN PIM-DM PIM-SM QS plicies ACLs Priritizatin QS applicatins OSPFv3 Multicasting IPv6 transitin mechanisms QS Netwrk management Prt mirrring (lcal and remte) SNMP cnfiguratin IMC fundamentals Intelligent Resilient Framewrk (IRF) Frmat ffered 5-day instructr-led, 15% lecture, 35% learner research/grup analysis, and 50% hands-n labs Mre infrmatin If yu are interested, the curse datasheet discusses HP Cre/Distributin Netwrk Technlgies using Cmware Sftware in mre detail. It is available at http://h17007.www1.hp.cm/us/en/training/certificatins/technical/ase-netwrk-infrastructure.aspx. Implementing HP Netwrk Infrastructure Security The Implementing HP Netwrk Infrastructure Security curse prepares netwrk engineers and netwrk administratrs t cnfigure, trublesht and implement security features used t prtect a netwrk. Netwrk prtectin features n bth the A-Series and E-Series devices will be explred. Tpics cvered This curse teaches yu abut these tpics: Certificate Authrity (CA)-signed certificates Traffic mirrring Access cntrl lists (ACLs) used t filter netwrk traffic MAC address prtectin Prt security Traffic filters Surce prt filters Prt islatin 13
Spanning tree prtectin DHCP prtectin Address Reslutin Prtcl (ARP) prtectin IP spfing prtectin Threat detectin and Virus Thrttling Frmat ffered 2-day instructr-led, 15% lecture, 15% activity and 60% hands-n labs Mre infrmatin If yu are interested, the curse datasheet discusses Implementing HP Netwrk Infrastructure Security in mre detail. It is available at http://h17007.www1.hp.cm/us/en/training/certificatins/technical/ase-netwrkinfrastructure.aspx. Accelerated HP Cre/Distributin Layer Netwrk Technlgies The Accelerated HP Cre/Distributin Layer Netwrk Technlgies ILT cmbines the material presented in the HP Cre/Distributin Netwrk Technlgies using PrVisin Sftware, HP Cre/Distributin Netwrk Technlgies using Cmware Sftware, and Implementing HP Netwrk Infrastructure Security ILTs. It is delivered in less time than it wuld take t attend the ILTs separately. NOTE Given the cmpressed timeframe, the Accelerated curse is designed t train nly experienced netwrk administratrs in these tpics. T attend Accelerated HP Cre/Distributin Layer Netwrk Technlgies, yu shuld have ne f the fllwing active certificatins: ASE HP PrCurve (2008 r later) ASE HP PrCurve Campus LANs [2010] H3CSE CCNP Ruting and Switching, CCNP Wireless CCDP Tpics cvered In this curse yu learn abut: Deplying and cnfiguring HP A-Series and E-Series switches Designing, implementing, and trubleshting ruted and bridged netwrks using industry-standard prtcls, fcusing n OSPF, ebgp, VRRP, and MSTP Designing and implementing triple play netwrks using HP priritizatin and QS features Designing and implementing IGMP, PIM Dense, and PIM Sparse Designing and implementing IPv6 and OSPFv3 Designing and implementing IRF Designing and implementing secure infrastructure netwrks fcusing n STP, DHCP, and ARP prtectin; traffic mirrring; access cntrl lists (ACLs); and Virus Thrttling Frmat ffered Five-day instructr-led, 20% lecture and 80% lab and classrm activities. The curse may be delivered using a remte lab envirnment. Mre infrmatin If yu are interested, the curse datasheet discusses Accelerated HP Cre/Distributin Layer Netwrk Technlgies in mre detail. It is available at http://h17007.www1.hp.cm/us/en/training/certificatins/technical/ase-netwrk-infrastructure.aspx. 14
Purchase self-study materials Rather than attend the ILT, yu can prepare fr HP certificatin exams at yur cnvenience, with HP-apprved Official Exam Certificatin Guides. Learn at yur wn pace, with self-study guides written by industry experts. Each guide takes yu thrugh cmplex subjects with detailed, step-by-step explanatins, diagrams, chapter quizzes and a practice exam. Remember that simply reading the self-study materials will nt give yu the hands-n experience prvided by labs in the ILT. Bth the study guide and exam assumes that yu have real-wrld experience implementing enterprise netwrks. The same pre-requisite rules, as described in this Exam Preparatin Guide, apply if yu us the HP-apprved Official Exam Certificatin Guides t prepare fr this exam. T purchase the self-study materials assciated with this exam, visit http://www.hppress.cm. Cmplete recmmended WBTs HP als recmmends that yu cmplete several WBTs, which delve int the technlgies that underlie HP netwrking slutins: HP Switching and Ruting Technlgies, Rev 10.41r later (a prerequisite fr the HP Cre/Distributin Netwrk Technlgies using PrVisin Sftware and HP Cre/Distributin Netwrk Technlgies using Cmware Sftware ILTs described abve) HP Internet and WAN Technlgies, Rev 10.41 r later HP Netwrk Infrastructure Security Technlgies, Rev 10.41 r later (a prerequisite fr the Implementing HP Netwrk Infrastructure Security ILT described abve) These WBTs are freely available thrugh the Learning Center f yur HP Partner Prtal. Yu will need t register fr the WBT, which requires an HP Learner ID. Nte that, while it nly takes a few minutes t request the ID, the prcess f activating it up may take several days. Please d nt wait until the last minute. HP Switching and Ruting Technlgies This curse describes the peratin f standards and prtcls that facilitate resilient and predictable netwrk peratin. It begins by aligning the standards with strategies fr utilizing redundant links and netwrk devices, and it cncludes with a discussin f cmmnly used standards that enable an infrastructure t supprt cnverged applicatins. Tpics cvered The WBT teaches yu abut these cncepts: Interactins amng netwrk devices that supprt VRRP v2 Strategies fr sharing default gateway respnsibilities between tw Layer 3 switches IP ruter frwarding decisins fr packets that match with multiple rute table entries Cmparisn f autmatic and manual IP address space summarizatin OSPF characteristics that make it suitable t resilient, large-scale intranets OSPF ruter rles and the significance each has t sharing rute infrmatin The functin and scpe f each OSPF message type Prper use f OSPF area types The rles f IGMP and PIM in multicast cmmunicatins, and the scpe f each prtcl The peratin f PIM Dense and PIM Sparse and their apprpriate netwrk deplyments The characteristics f and requirements fr data traffic versus real-time traffic Layer 2 and Layer 3 priritizatin standards and their apprpriate implementatins in cntemprary enterprise netwrks The LLDP-MED standard and its relevance t QS fr VIP and ther applicatins 15
Frmat ffered The WBT is a fur-hur, self-paced curse, which features animatin and interactin. At the end f the WBT, yu take a test t assess what yu have learned. Mre infrmatin If yu are interested, the curse datasheet discusses HP Switching and Ruting Technlgies in mre detail. It is available at http://h17007.www1.hp.cm/us/en/training/certificatins/technical/ase-netwrkinfrastructure.aspx. HP Internet and WAN Technlgies This WBT is designed and delivered by an industry expert t help yu understand the technlgies that pwer the Internet and Wide Area Netwrks (WANs). The Internet has permeated every crner f the glbe. Mst large crpratins are multi-natinal. High-speed cnnectivity t the rest f the wrld is nw a must-have. But hw is that cnnectivity prvided? There are several technlgies ne can chse frm t enable cnnectivity. Service prviders ffer many access ptins t their managed netwrks r t the Internet. These netwrks then emply varius technlgies t enable lgical cnnectivity fr public Internet traffic, r fr Virtual Private Netwrks (VPNs). This WBT gives yu the knwledge t identify the varius prtcls and technlgies used in service delivery. Tpics cvered The WBT teaches yu abut these cncepts: Internet basics Histry f the Internet Current and future trends Next Generatin Internet requirements IP ruting fundamentals IS-IS ruting BGP ruting MPLS Cntrl Plane/Data Plane fundamentals Static versus dynamic ruting Categries f dynamic ruting prtcls IS-IS terminlgy IS-IS hierarchy and peratin IS-IS addressing IS-IS messaging IS-IS cmpared t OSPF BGP terminlgy Prtcl interactin BGP use mdels Rute advertising principals BGP rute attributes MPLS prtcls Cntrl plane/data plane peratin MPLS traffic engineering MPLS Supprt f IPVPN MPLS Supprt f Layer 2 VPNs 16
Access and WAN technlgies Access t the Internet fr cnsumers and businesses Layer 2 backbne technlgies High-speed data links Frmat ffered The WBT is a fur-hur, self-paced curse, which features animatin and interactin. At the end f the WBT, yu take a test t assess what yu have learned. Mre infrmatin If yu are interested, the curse datasheet discusses HP Internet and WAN Technlgies in mre detail. It is available at http://h17007.www1.hp.cm/us/en/training/certificatins/technical/ase-netwrkinfrastructure.aspx. HP Netwrk Infrastructure Security Technlgies The HP Netwrk Infrastructure Security Technlgies WBT cvers a wide variety f security technlgies. It intrduces netwrk technicians t the Defense in Depth strategy fr cnfrnting cntemprary threats t netwrk security. Specifically, it cvers the netwrk infrastructure security cmpnent f this strategy, explaining technlgies built int a trusted netwrk infrastructure as well as access cntrl and threat management technlgies. Tpics cvered The WBT teaches yu abut these cncepts: Types f threats Netwrk recnnaissance Unauthrized access Impersnatin Malware Defense in Depth Denial f Service (DS) Viruses and wrms Data privacy, integrity, and authenticity fr wired and wireless cmmunicatins Key management Digital certificates Public Key Infrastructure (PKI) Built-in prtectins against cmmn prtcl explits Access cntrl Firewalls STP prtectin DHCP snping ARP prtectin Virus Thrttle Static VLANs ACLs Traditinal firewall technlgies, including stateful-inspectin firewalls with Applicatin Level Gateways (ALGs) r Applicatin Specific Packet Filtering (ASPF) Next Generatin Firewalls (NGFWs) 17
Netwrk access cntrl technlgies Authenticatin prtcls such as Challenge Handshake Authenticatin Prtcl (CHAP) and Extended Authenticatin Prtcl (EAP) Authenticatin, Authrizatin, and Accunting (AAA) prtcls such as RADIUS and TACACS+ 802.1X Web authenticatin (captive prtal MAC authenticatin Directries Endpint integrity Persnal anti-virus and firewall slutins Web brwser security Patches Implementatin f endpint-integrity-based NAC Virtual Private Netwrk (VPN) technlgies IPsec with Internet Key Exchange versin 1 (IKEv1) Layer 2 Tunneling Prtcl (L2TP) Pint-t-Pint Tunneling Prtcl (PPTP) MACsec Threat management slutins Signature-based and anmaly-based systems Intrusin Detectin Systems (IDSs) Intrusin Preventin Systems (IPSs) Deplyment strategies Frmat ffered The WBT is a five-hur, self-paced curse, which features animatin and interactin. At the end f the WBT, yu take a test t assess what yu have learned. Mre infrmatin If yu are interested, the curse datasheet discusses HP Netwrk Infrastructure Security Technlgies in mre detail. It is available at http://h17007.www1.hp.cm/us/en/training/certificatins/technical/ase-netwrkinfrastructure.aspx. Refer t additinal materials Yu might want t refer t sme additinal materials, particularly if yu have nt cmpleted the recmmended training. HP prvides prduct dcumentatin, which explains hw t implement the technlgies cvered in the training. Visit http://www.hp.cm/netwrking/supprt t search fr the apprpriate manuals. Obtain hands-n experience If pssible, practice setting up technlgies n actual HP equipment (refer t the earlier lists f technlgies cvered in the recmmended training). Yu learn the mst by cnfiguring several switches that functin tgether as they wuld in the real-wrld, which is the advantage f the safe lab envirnment prvided in the ILTs. Hw t take the Implementing HP Netwrk Infrastructure Slutins (HP0-Y43) exam Table 4 prvides details abut the exam. Nte that this is a prctred exam, which yu must cmplete at a scheduled time and authrized lcatin. Yu will nt be allwed t take any reference materials with yu. 18
Table 4: HP0-Y43 exam details Parameter Descriptin Number f items 62 Item types Exam time Passing scre Additinal guidelines Multiple chice (single respnse) Multiple chice (multiple respnses) Matching 2 hurs (120 minutes) 74 percent (46 crrect answers) N nline r hard cpy reference material will be allwed at the testing site. Exam cntent The fllwing testing bjectives represent the specific areas f cntent cvered in the exam. Use this utline t guide yur study and t check yur readiness fr the exam. The exam measures yur understanding f these areas. Table 5: HP0-Y43 exam cntent HP0-Y43 Sectins/Objectives 15 % Netwrking Architecture and Technlgy Identify and describe netwrking architecture and technlgy. Apply Quality f Service cncepts. 31% Slutin Implementatin (Install, cnfigure, startup, and upgrade the netwrk slutin as per planned design.) Install and cnfigure multicast prtcls. Install and cnfigure IPv4 and IPv6. Install and cnfigure ruting. Implement advanced VLAN types (MAC-based, prtcl-based, IP subnet-based, vice, islate user VLAN, r super VLAN). Install and cnfigure the management and administratin slutin. 6% Slutin Planning and Design 32% Slutin Optimizatin Plan and design t achieve a deplyable slutin. Tune advanced Layer 3 ruting prtcls. Secure wired/wireless devices in small t medium sized netwrks and mitigate basic security threats. Manage netwrk assets using HP tls. Optimize L3 ruting prtcl cnvergence and scalability (OSPF, RIP, OSPFv3, RIPng, static rutes, ISIS, ECMP). Assess hw t ptimize netwrk availability. Assess sensitive traffic and determine apprpriate tls fr ptimizing traffic flw (QS, DiffServ, Multicast/IGMP/PIM, IRF, bandwidth limitatins, rate limiting, trunks, MSTP, multipath ruting). 11% Slutin Trubleshting Secure the netwrk and mitigate security threats. 5% Slutin Management Perfrm netwrk management. 19
Cmments n the exam During the exam, participants can make specific cmments abut the items (i.e., accuracy, apprpriateness t audience, etc.). HP welcmes these cmments as part f ur cntinuus imprvement prcess. Tips fr taking HP exams Rather than emphasize simple memrizatin, HP exams attempt t assess whether yu have the knwledge and skills that a netwrking prfessinal requires n the jb. Therefre, sme questins feature exhibits r scenaris. As yu see, yu will have an average f just less than tw minutes per questin. Sme questins will take much less time, and sme will require a bit mre. If allwed by the systems, yu might want t answer the questins abut which yu are sure first and then mve back t the thers. Befre yu d answer a questin, take the time t read the questin and all f the ptins carefully. If the questin indicates that it features an exhibit, study the exhibit and reread the questin. Make sure t select the answer that crrectly respnds t the questin that is asked nt simply an answer that includes sme crrect infrmatin. If the questin asks fr mre than ne answer, remember t select each crrect answer. Yu d nt receive partial credit fr a partially crrect answer. Register T register fr this exam, visit the PearsnVUE website at: http://www.pearsnvue.cm/hp Yu will need an HP Learner ID and a PearsnVUE ID. Yu can als access links t register fr this exam when yu view infrmatin abut them n The Learning Center: http://www.hp.cm/g/expertne Sample questins Use these questins t help t assess whether yu are ready t take the exam. An appendix at the end f this guide prvides answers and explanatins. 1. Yur netwrk is ruting multicast messages using Prtcl Independent Multicast-Sparse Mde (PIM-SM). A multicast surce begins t a new stream. What message des the default ruter fr the multicast surce send? a. a Jin message t the Btstrap Ruter (BSR) b. a Jin message t the Rendezvus Pint (RP) c. a Register message t the Btstrap Ruter (BSR) d. a Register message t the Rendezvus Pint (RP) 2. Examine the exhibit. While cnfiguring the HP E8212 zl switch t be an ABR fr OSPF areas 0 and 2, yu entered this cmmand in the switch s CLI: E5406(spf)# area 2 stub 2 n-summary 20
Figure 1: Exhibit fr questin 2 If yu assume that all the cnnectins are up and the OSPF ruters have achieved adjacency, which rutes culd yu see n the E5412 zl switch in area 2? The ruting tables assciated with each ptin are listed n the next pages. a. A b. B c. C d. D Optin A IP Rute Entries Destinatin Gateway VLAN Type Sub-Type Metric Dist. ------------------ --------------- ---- --------- ---------- ---------- ----- 10.0.0.0/16 10.2.0.1 20 spf InterArea 2 110 10.1.0.0/16 10.2.0.1 20 spf InterArea 2 110 10.2.0.0/29 VLAN20 20 cnnected 1 0 10.2.1.0/24 VLAN21 21 cnnected 1 0 10.2.2.0/24 VLAN22 22 cnnected 1 0 10.2.0.0/16 10.2.0.2 10 spf InterArea 1 110 10.3.0.0/16 10.2.0.1 10 spf InterArea 2 110 127.0.0.0/8 reject static 0 0 127.0.0.1/32 l0 cnnected 1 0 Optin B IP Rute Entries Destinatin Gateway VLAN Type Sub-Type Metric Dist. ------------------ --------------- ---- --------- ---------- ---------- ----- 0.0.0.0/0 10.2.0.1 20 spf InterArea 2 110 10.2.0.0/29 VLAN20 20 cnnected 1 0 10.2.1.0/24 VLAN21 21 cnnected 1 0 10.2.2.0/24 VLAN22 22 cnnected 1 0 127.0.0.0/8 reject static 0 0 127.0.0.1/32 l0 cnnected 1 0 21
Optin C IP Rute Entries Destinatin Gateway VLAN Type Sub-Type Metric Dist. ------------------ --------------- ---- --------- ---------- ---------- ----- 10.0.0.0/16 10.2.0.1 20 spf InterArea 2 110 10.1.0.0/16 10.2.0.1 20 spf InterArea 2 110 10.2.0.0/29 VLAN20 20 cnnected 1 0 10.2.1.0/24 VLAN21 21 cnnected 1 0 10.2.2.0/24 VLAN22 22 cnnected 1 0 10.3.0.0/16 10.2.0.1 20 spf InterArea 2 110 127.0.0.0/8 reject static 0 0 127.0.0.1/32 l0 cnnected 1 0 Optin D IP Rute Entries Destinatin Gateway VLAN Type Sub-Type Metric Dist. ------------------ --------------- ---- --------- ---------- ---------- ----- 10.2.0.0/29 VLAN20 20 cnnected 1 0 10.2.1.0/24 VLAN21 21 cnnected 1 0 10.2.2.0/24 VLAN22 12 cnnected 1 0 127.0.0.0/8 reject static 0 0 127.0.0.1/32 l0 cnnected 1 0 3. The LAN shwn in the exhibit is being designed as a single DiffServ dmain. On which prts shuld packets be marked (r remarked) t cmply with the DiffServ Mdel? (Select tw.) a. inter-switch prts between the distributin layer switches b. the prts that cnnect the edge switches t the distributin switches c. the prts that cnnect the distributin prts t the edge switches d. client access prts e. server access prts Figure 2: Exhibit fr questin 3 22
4. An HP A5800 switch enfrces an ACL, which is shwn in the cnfiguratin under the exhibit. Yu want t allw the client shwn in the exhibit t access FTP services n the server. Which is true? a. Yu d nt need t enter a cmmand because the current cnfiguratin permits this traffic. b. Yu culd permit the traffic with this cmmand: permit tcp surce 10.1.7.0 0.0.0.255 destinatin 10.1.4.12 0 destinatin-prt range 20-21 c. Yu culd permit the traffic with this cmmand: permit tcp surce 10.1.7.201 0 destinatin 10.1.4.12 0 destinatin-prt range 20-21 d. Yu culd permit the traffic with this cmmand: rule 8 permit surce 10.1.7.0 0.0.0.255 destinatin 10.1.4.12 0 destinatin-prt range 20-21 e. Yu culd permit the traffic with this cmmand: rule 3 permit surce 10.1.7.0 0 destinatin 10.1.4.12 0 destinatin-prt range 20-21 Figure 3: Exhibit 1 fr questin 4 A5800 ACL cnfiguratin [A5800] display acl 3003 Advanced ACL 3003, named lab, 6 rules ACL s step is 5 rule 0 permit tcp surce 10.1.0.0 0.0.0.255 destinatin 10.1.4.12 0 destinatinprt range 20-21 rule 5 permit tcp surce 10.1.7.0 0.0.0.255 destinatin 10.1.4.12 0 destinatinprt eq www rule 6 permit udp surce 10.1.7.0 0.0.0.255 destinatin 10.1.4.12 0 destinatinprt eq dns rule 7 permit icmp surce 10.1.7.0 0.0.0.255 destinatin 10.1.4.12 0 rule 10 deny ip surce 10.1.0.0 0.0.255.255 destinatin 10.1.0.0 0.0.255.255.0 lgging rule 15 permit ip Figure 4: Exhibit 2 fr questin 4 5. An endpint that supprts bth IPv4 and IPv6 is cnnected t yur HP A3610 switch. Yu want t assign t IPv4 traffic t VLAN 4 and the IPv6 traffic t VLAN 6. Hw d yu d s? Cnclusin a. Specify VLAN 6 as a prtcl-based VLAN that selects IPv6. Cnfigure the endpint s prt as a hybrid prt. Set VLAN 4 as the PVID and VLAN 6 as a prtcl VLAN. b. Cnfigure the endpint s prt as a trunk prt. Set VLAN 4 as the PVID and allw VLAN 6. c. Specify VLAN 6 as a prtcl-based VLAN that selects IPv6. Cnfigure the endpint s prt as a trunk prt. Allw bth VLAN 4 and 6, setting either VLAN as the PVID. d. Cnfigure the endpint s prt as an access prt set t VLAN 4. Then specify VLAN 6 as the access prt s prtcl-based VLAN setting. HP wishes yu success in the HP ExpertONE Prgram and in passing the exam fr which yu are preparing. 23
Appendix: Answers t the sample questins This sectin prvides answers and explanatins fr the sample questins. 1. Yur netwrk is ruting multicast messages using Prtcl Independent Multicast-Sparse Mde (PIM-SM). A multicast surce begins t a new stream. What message des the default ruter fr the multicast surce send? a. a Jin message t the Btstrap Ruter (BSR) b. a Jin message t the Rendezvus Pint (RP) c. a Register message t the Btstrap Ruter (BSR) d. a Register message t the Rendezvus Pint (RP) Explanatin: In PIM-SIM, a ruter sends a Jin message t indicate that it needs t jin the PIM-SM tree s that it can receive multicasts fr hsts cnnected t it r t a dwnstream ruter. It is a Register message that indicates that the ruter is the first-hp ruter fr a multicast surce. Therefre, the crrect answer must specify a Register message, and answers a and b are incrrect. The BSR is respnsible fr distributing RP-t-multicast address mappings. The RP is respnsible fr acting as the rt f the tree fr a particular multicast address, and Register messages are addressed t it. Answer d is crrect. 2. Examine the exhibit. While cnfiguring the HP E8212 zl switch t be an ABR fr OSPF areas 0 and 2, yu entered this cmmand in the switch s CLI: E5406(spf)# area 2 stub 2 n-summary Figure 1: Exhibit fr questin 2 If yu assume that all the cnnectins are up and the OSPF ruters have achieved adjacency, which rutes culd yu see n the E5412 zl switch in area 2? The ruting tables assciated with each ptin are listed n the next pages. a. A b. B c. C d. D Explanatin: A stub area typically receives interarea rutes that summarize the netwrks in ther areas. Hwever, the cmmand shwn fr the E8212 zl ABR cnfigures the ruting switch t suppress thse summary rutes in its advertisements t ruters in area 2. The ABR will nly send an advertisement fr a default rute int area 2. 24
The ruting tables in answers a and c include OSPF interarea rutes summarizing ther areas, s these answers are incrrect. In additin, the table in answer a includes a summary rute fr this internal ruting switch s wn area, which is als incrrect. The ruting table in answer d des nt include interarea summary rutes, which is crrect, but it als lacks a default rute. The E8212 zl autmatically injects a default rute int stub areas withut summary rutes. Therefre, answer d is incrrect. The nly interarea OSPF rute shwn in answer b is the default rute. This answer is crrect. Optin A IP Rute Entries Destinatin Gateway VLAN Type Sub-Type Metric Dist. ------------------ --------------- ---- --------- ---------- ---------- ----- 10.0.0.0/16 10.2.0.1 20 spf InterArea 2 110 10.1.0.0/16 10.2.0.1 20 spf InterArea 2 110 10.2.0.0/29 VLAN20 20 cnnected 1 0 10.2.1.0/24 VLAN21 21 cnnected 1 0 10.2.2.0/24 VLAN22 22 cnnected 1 0 10.2.0.0/16 10.2.0.2 10 spf InterArea 1 110 10.3.0.0/16 10.2.0.1 10 spf InterArea 2 110 127.0.0.0/8 reject static 0 0 127.0.0.1/32 l0 cnnected 1 0 Optin B IP Rute Entries Destinatin Gateway VLAN Type Sub-Type Metric Dist. ------------------ --------------- ---- --------- ---------- ---------- ----- 0.0.0.0/0 10.2.0.1 20 spf InterArea 2 110 10.2.0.0/29 VLAN20 20 cnnected 1 0 10.2.1.0/24 VLAN21 21 cnnected 1 0 10.2.2.0/24 VLAN22 22 cnnected 1 0 127.0.0.0/8 reject static 0 0 127.0.0.1/32 l0 cnnected 1 0 Optin C IP Rute Entries Destinatin Gateway VLAN Type Sub-Type Metric Dist. ------------------ --------------- ---- --------- ---------- ---------- ----- 10.0.0.0/16 10.2.0.1 20 spf InterArea 2 110 10.1.0.0/16 10.2.0.1 20 spf InterArea 2 110 10.2.0.0/29 VLAN20 20 cnnected 1 0 10.2.1.0/24 VLAN21 21 cnnected 1 0 10.2.2.0/24 VLAN22 22 cnnected 1 0 10.3.0.0/16 10.2.0.1 20 spf InterArea 2 110 127.0.0.0/8 reject static 0 0 127.0.0.1/32 l0 cnnected 1 0 Optin D IP Rute Entries Destinatin Gateway VLAN Type Sub-Type Metric Dist. ------------------ --------------- ---- --------- ---------- ---------- ----- 10.2.0.0/29 VLAN20 20 cnnected 1 0 10.2.1.0/24 VLAN21 21 cnnected 1 0 10.2.2.0/24 VLAN22 12 cnnected 1 0 127.0.0.0/8 reject static 0 0 127.0.0.1/32 l0 cnnected 1 0 3. The LAN shwn in the exhibit is being designed as a single DiffServ dmain. On which prts shuld packets be marked (r remarked) t cmply with the DiffServ Mdel? Select tw. a. inter-switch prts between the distributin layer switches b. the prts that cnnect the edge switches t the distributin switches c. the prts that cnnect the distributin prts t the edge switches 25
d. client access prts IRF Member 3 remains Master. e. server access prts Figure 2: Exhibit fr questin 3 Explanatin: The DiffServ mdel specifies that yu mark traffic (r remark already marked traffic) with a DSCP as clse t the surce as pssible. Fr traffic destined t servers, the clsest prts are the client access prts, s answer d is ne crrect answer. Fr return traffic frm the servers t the clients, the clsest prts as the server access prts, s answer e is anther crrect answer. In a LAN that is a single DiffServ dmain, the inter-switch prts shuld trust the DSCP marks placed by the client r server edge switches. Hwever, they d nt need t remark thse values; therefre, answers a, b, and c are incrrect. 4. An HP A5800 switch enfrces an ACL, which is shwn in the cnfiguratin under the exhibit. Yu want t allw the client shwn in the exhibit t access FTP services n the server. Which is true? a. Yu d nt need t enter a cmmand because the current cnfiguratin permits this traffic. b. Yu culd permit the traffic with this cmmand: permit tcp surce 10.1.7.0 0.0.0.255 destinatin 10.1.4.12 0 destinatin-prt range 20-21 c. Yu culd permit the traffic with this cmmand: permit tcp surce 10.1.7.201 0 destinatin 10.1.4.12 0 destinatin-prt range 20-21 d. Yu culd permit the traffic with this cmmand: rule 8 permit surce 10.1.7.0 0.0.0.255 destinatin 10.1.4.12 0 destinatin-prt range 20-21 e. Yu culd permit the traffic with this cmmand: rule 3 permit surce 10.1.7.0 0 destinatin 10.1.4.12 0 destinatin-prt range 20-21 Explanatin: First examine the ACL t determine whether it already permits the desired traffic: Rule 0 permits FTP traffic t the server (destinatin-prt range 20 21); hwever, it nly permits this traffic frm surces in 10.1.0.0/24, and the client is in 10.1.7.0/24. Therefre, this rule des nt permit the desired traffic. Rule 5 deals with HTTP traffic (destinatin-prt eq www). Therefre, it des nt affect the traffic in questin. Similarly, rules 6 and 7 relate t DNS and ICMP traffic and d nt affect the traffic in questin. Rule 10 denies all ther IP traffic between endpints in 10.1.0.0/16. This rule affects the traffic in questin, which is between 10.1.7.201 and 10.1.4.12. Therefre, the ACL as it is will drp the desired traffic, and answer a is incrrect. Next, yu must determine a valid cmmand fr altering the ACL t permit the desired traffic. 26
Yu knw that yu must add the rule that permits the traffic befre the rule that currently drps it in ther wrds befre rule 10. The cmmands in answers b and c add the new rule at the end f the list, s they are incrrect. The cmmands in bth answers d and e add the rule in a valid rder. Hwever, the cmmand in answer e des nt select the crrect traffic. Entering 0 fr the wildcard bits (surce 10.1.7.0 0) frces an exact match with the listed IP address, which is nt a valid IP address in this instance. Yu want t match the exact IP address, 10.1.7.201, r the entire 10.1.7.0/24 subnet. Answer d includes the crrect wildcard bits fr the secnd ptin (surce 10.1.7.0 0.0.0.255). Answer d is crrect. Figure 3: Exhibit 1 fr questin 4 A5800 ACL cnfiguratin [A5800] display acl 3003 Advanced ACL 3003, named lab, 6 rules ACL s step is 5 rule 0 permit tcp surce 10.1.0.0 0.0.0.255 destinatin 10.1.4.12 0 destinatinprt range 20-21 rule 5 permit tcp surce 10.1.7.0 0.0.0.255 destinatin 10.1.4.12 0 destinatinprt eq www rule 6 permit udp surce 10.1.7.0 0.0.0.255 destinatin 10.1.4.12 0 destinatinprt eq dns rule 7 permit icmp surce 10.1.7.0 0.0.0.255 destinatin 10.1.4.12 0 rule 10 deny ip surce 10.1.0.0 0.0.255.255 destinatin 10.1.0.0 0.0.255.255.0 lgging rule 15 permit ip Figure 4: Exhibit 2 fr questin 4 5. An endpint that supprts bth IPv4 and IPv6 is cnnected t yur HP A3610 switch. Yu want t assign t IPv4 traffic t VLAN 4 and the IPv6 traffic t VLAN 6. Hw d yu d s? a. Specify VLAN 6 as a prtcl-based VLAN that selects IPv6. Cnfigure the endpint s prt as a hybrid prt. Set VLAN 4 as the PVID and VLAN 6 as a prtcl VLAN. b. Cnfigure the endpint s prt as a hybrid prt. Set VLAN 4 as the PVID and allw VLAN 6. c. Specify VLAN 6 as a prtcl-based VLAN that selects IPv6. Cnfigure the endpint s prt as a trunk prt. Allw bth VLAN 4 and 6, setting either VLAN as the PVID. d. Cnfigure the endpint s prt as an access prt set t VLAN 4. Then specify VLAN 6 as the prt s IPv6 prtcl-based VLAN setting. Explanatin: T assign IPv4 and IPv6 traffic received n the same prt t different VLANs, yu must cmplete several steps. Yu must create a prtcl-based VLAN that specifies the crrect VLAN ID and desired prtcl. In additin, the prt receiving the IPv4 and IPv6 traffic must be a hybrid prt with the VLAN fr IPv4 traffic as the PVID and the prtcl-specific VLAN als specified. Answer b crrectly includes specifying the prt as a hybrid prt, but it des nt crrectly describe hw t create the prtcl-based VLAN fr IPv6 traffic. Answer c includes the crrect methd fr creating the prtcl-based VLAN, but it specifies the prt as a trunk prt, which is incrrect. Answer d is entirely incrrect, with the wrng type f prt (access rather than hybrid) and an invalid way f 27
entirely incrrect, with the wrng type f prt (access rather than hybrid) and an invalid way f specifying the settings fr the prtcl-based VLAN. Only answer a includes all f the crrect steps. T learn mre abut HP netwrking, visit www.hp.cm/netwrking Cpyright 2011 Hewlett-Packard Develpment Cmpany, L.P. The infrmatin cntained herein is subject t change withut ntice. The nly warranties fr HP prducts and services are set frth in the express warranty statements accmpanying such prducts and services. Nthing herein shuld be cnstrued as cnstituting an additinal warranty. HP shall nt be liable fr technical r editrial errrs r missins cntained herein. HP0-Y43: Implementing HP Netwrk Infrastructure Slutins Exam Preparatin Guide / May 2011