Lab 8: Confi guring QoS

Similar documents
Firewall Stateful Inspection of ICMP

Lab Introduction to the Modular QoS Command-Line Interface

Lab 10: Confi guring Basic Border Gateway Protocol

Lab QoS Classification and Policing Using CAR

Lab 7-1 Configuring Switches for IP Telephony Support

Enabling Remote Access to the ACE

Chapter 7 Lab 7-1, Configuring Switches for IP Telephony Support

Firewall Stateful Inspection of ICMP

ICND1 Lab Guide Interconnecting Cisco Networking Devices Part 1 Version 2.0. Labs powered by

Lab Load Balancing Across Multiple Paths Instructor Version 2500

Table of Contents. Cisco Using the Cisco IOS Firewall to Allow Java Applets From Known Sites while Denying Others

Lab 3.3 Configuring QoS with SDM

Configuring Server Load Balancing

- QoS Classification and Marking -

IOS Zone Based Firewall Step-by-Step Basic Configuration

CCNA Exploration 4.0: ESwitching Basic Switching / Wireless PT Practice SBA. Switch S1 S1#sh ru Building configuration...

AlliedWare Plus OS How To. Configure QoS to prioritize SSH, Multicast, and VoIP Traffic. Introduction

Cisco - Catalyst 2950 Series Switches Quality of Service (QoS) FAQ

Network Scenarios Pagina 1 di 35

Felix Rohrer. PT Activity 7.5.3: Troubleshooting Wireless WRT300N. Topology Diagram

Lab Configure Cisco IOS Firewall CBAC on a Cisco Router

Firewall Technologies. Access Lists Firewalls

Lab Developing ACLs to Implement Firewall Rule Sets

Lab Configure Cisco IOS Firewall CBAC

Configure Policy-based Routing

Lab 5.5 Configuring Logging

Controlling Access to a Virtual Terminal Line

Geschreven door Administrator woensdag 13 februari :37 - Laatst aangepast woensdag 13 februari :05

Sample Configuration Using the ip nat outside source static

Routing. Static Routing. Fairness. Adaptive Routing. Shortest Path First. Flooding, Flow routing. Distance Vector

ICND1 Lab Guide Interconnecting Cisco Networking Devices Part 1 Version: Beta. Labs powered by

How To Lower Data Rate On A Network On A 2Ghz Network On An Ipnet 2 (Net 2) On A Pnet 2 On A Router On A Gbnet 2.5 (Net 1) On An Uniden Network On

Configuring Denial of Service Protection

Configuring the Firewall Management Interface

Easy Performance Monitor

Lab 3.5.1: Basic VLAN Configuration (Instructor Version)

Configuring Role-Based Access Control

QoS: Color-Aware Policer

Device Interface IP Address Subnet Mask Default Gateway

Cisco Configuring Commonly Used IP ACLs

Note: This case study utilizes Packet Tracer. Please see the Chapter 5 Packet Tracer file located in Supplemental Materials.

Configuring the Cisco Secure PIX Firewall with a Single Intern

Configuring Class Maps and Policy Maps

Configuring a Cisco 2509-RJ Terminal Router

Lab Creating a Network Map using CDP Instructor Version 2500

Sample Configuration Using the ip nat outside source list C

Troubleshooting the Firewall Services Module

Lab 5-5 Configuring the Cisco IOS DHCP Server

AutoQoS for Medianet

Lab Use Network Inspector to Observe STP Behavior

Enabling NetFlow and NetFlow Data Export (NDE) on Cisco Catalyst Switches

Configuring Control Plane Policing

Lab 6.1 Configuring a Cisco IOS Firewall Using SDM

Network Data Encryption Commands

Lab Load Balancing Across Multiple Paths

LAN-Cell to Cisco Tunneling

Lab Introductory Lab 1 - Getting Started and Building Start.txt

Remote Access VPN Business Scenarios

WhatsUpGold. v14.4. Flow Monitor User Guide

Easy Performance Monitor

Configuring Network Address Translation

Lab Exercise Configure the PIX Firewall and a Cisco Router

Configuring MPLS QoS

Easy Performance Monitor

Virtual Fragmentation Reassembly

Configuring the MNLB Forwarding Agent

Firewall Authentication Proxy for FTP and Telnet Sessions

The Cisco IOS Firewall feature set is supported on the following platforms: Cisco 2600 series Cisco 3600 series

Configuring QoS and Per Port Per VLAN QoS

Using a Sierra Wireless AirLink Raven X or Raven-E with a Cisco Router Application Note

Best Practice Recommendations for VLANs and QoS with ShoreTel

Configuring QoS CHAPTER

Configuring NetFlow Secure Event Logging (NSEL)

Lab Introductory Lab 1 Getting Started and Building Start.txt

Internetwork Expert s CCNA Security Bootcamp. IOS Firewall Feature Set. Firewall Design Overview

QoS Queuing on Cisco Nexus 1000V Class-Based Weighted Fair Queuing for Virtualized Data Centers and Cloud Environments

Network Diagram Scalability Testbed and Configuration Files

Lab Configure Basic AP Security through IOS CLI

Configuring NetFlow Secure Event Logging (NSEL)

Configuring Auto-QoS

How To Configure InterVLAN Routing on Layer 3 Switches

Authentication with 802.1x and EAP Across Congested WAN Links

Cisco CCNA Optional Semester 4 Labs Wide Area Networking LAB 1 T1 TSU WAN LINK OVERVIEW - Instructor Guide (Estimated time: 30 minutes)

Central America Workshop - Guatemala City Guatemala 30 January - 1 February 07. IPv6 Security

Skills Assessment Student Training Exam

Reverse Proxy Caching

SolarWinds Technical Reference

Configuring NetFlow-lite

Flow Monitor for WhatsUp Gold v16.2 User Guide

Ethernet Overhead Accounting

SolarWinds Technical Reference

Configuring Static and Dynamic NAT Simultaneously

Chapter 4: Lab A: Configuring CBAC and Zone-Based Firewalls

Lab 7: Firewalls Stateful Firewalls and Edge Router Filtering

Troubleshooting the Firewall Services Module

PIX/ASA 7.x and above : Mail (SMTP) Server Access on Inside Network Configuration Example

LAB THREE STATIC ROUTING

AutoQoS. Prerequisites for AutoQoS CHAPTER

Brocade to Cisco Comparisons

Transcription:

Lab 8: Objective Implement QoS, mark traffi c, and display and interpret QoS output. Lab Topology For this lab, your network design will include two pods of devices. You will be responsible for confi guring the devices in both pods. The devices on the left side of the topology are in Pod 1. The devices on the right side of the topology are in Pod 2. P1PC1 and P2PC2 are PC workstations. P1ASW1 and P2ASW2 are access-layer switches. P1DSW1 and P2DSW2 are distribution-layer switches. The access and distribution layers are two of the three layers in the Cisco three-layer hierarchical network model, which also includes the core layer. The Topology diagram below represents the NetMap in the Simulator. To access each of the devices from within the Simulator, select the device name from the appropriate menu in the Simulator. For example, to access P1ASW1, click the eswitches button and select P1ASW1 from the drop-down menu. 168 Boson NetSim for CCNP Lab Manual

Command Summary Command confi gure terminal enable exit end interface fastethernet slot/port ping ip_address shutdown; no shutdown access-list access_list_number [dynamic dynamic_name [timeout minutes] ] {deny permit} protocol source source_wildcard destination destination_wildcard [precedence precedence] [tos tos] [log log-input] mls qos show mls qos class-map [match-all match-any] class_map_ name match {access-group acl_index_or_name ip dscp dscp_list ip precedence ip_precedence_list} show class-map policy-map policy_map_name class class_map_name set {cos new_cos ip dscp new_dscp ip precedence new_precedence} show policy-map [policy_map_name [class class_name]] service-policy {input policy_map_name output policy_map_name} Description enters global confi guration mode enters privileged EXEC mode exits from current mode returns to privileged EXEC mode enters interface confi guration mode for the specifi ed Fast Ethernet interface sends an ICMP echo request disables; enables an interface creates an IP extended ACL enables QoS globally verifi es MLS QoS confi guration creates a class map, and changes to class map confi guratoin mode defi nes matching criteria for class map verifi es class map creates a policy map, and changes to policy map confi guration mode defi nes a traffi c classifi cation, and enters policy map class confi guration mode classifi es IP traffi c by setting a new value in the packet verifi es policy map applies a policy map to an interface Boson NetSim for CCNP Lab Manual 169

Lab Tasks Task 1: Enable QoS and Mark Traffi c 1. Enable QoS globally on each DSW. Use the mls qos command to accomplish this task. 2. Verify that QoS is globally enabled. Use the show mls qos command to accomplish this task. 3. Separate traffi c into two classes, one for ICMP traffi c and one for TFTP traffi c. First, select these types of traffi c with an Access Control List (ACL). Create Access List 101 to permit all TFTP traffi c. Create Access List 102 to permit all ICMP echo traffi c and echo reply traffi c. 4. Classify these types of traffi c by mapping the Access Lists to a Class Map. Create a Class Map named TFTP; match Access List 101 to this class. Create a Class Map named ICMP; match Access List 102 to this class. 5. Once the traffi c has been classifi ed, change the IP precedence values for the traffi c so that it can be queued later. Create a Policy Map named Precedence. For the TFTP class, change the IP precedence to 5. For the ICMP class, change the IP precedence to 1. 6. Apply the policy map to the inbound interfaces of the traffi c. In the Lab Topology, these are the trunks that connect to the ASWs. Use the service-policy command to accomplish this task. Task 2: Display and Interpret QoS Output 1. Use the show mls qos command to verify that QoS is enabled. 2. Verify that the Access Lists are correct. Use the show access-lists command. 3. Verify the Class Map confi guration. Use the show class-map command. 4. Verify the Policy Map confi guration. Use the show policy-map command. 5. Verify the application of the policy to the interface. Use the show run command. Lab Solutions BCMSN LAB 8 Task 1: Enable QoS and Mark Traffi c 1. mls qos 2. show mls qos 3. access-list 101 permit udp any any eq tftp access-list 102 permit icmp any any echo access-list 102 permit icmp any any echo-reply 4. class-map tftp match access-group 101 class-map icmp match access-group 102 5. policy-map precedence class tftp set ip precedence 5 class icmp set ip precedence 1 6. interface range fastethernet 0/1-4 170 Boson NetSim for CCNP Lab Manual

Task 2: Display and Interpret QoS Output 1. P1DSW1#show mls qos QoS is enabled 2. P1DSW1#show access-lists Extended IP access list 101 permit udp any any eq tftp Extended IP access list 102 permit icmp any any echo permit icmp any any echo-reply 3. P1DSW1#show class-map Class Map match-all tftp (id2) Match access-group 101 Class Map match-all icmp (id 3) Match access-group 102 Class Map match-any class-default (id 0) Match any 4. 5. P1DSW1#show policy-map Policy Map precedence class tftp set ip precedence 5 class icmp set ip precedence 1 P1DSW1#show run interface FastEthernet0/1 interface FastEthernet0/2 Boson NetSim for CCNP Lab Manual 171

interface FastEthernet0/3 interface FastEthernet0/4 172 Boson NetSim for CCNP Lab Manual

Sample Initial Confi guration Scripts P1DSW1 Version 12.1 service timestamps debug uptime service timestamps log uptime no service password-encryption hostname P1DSW1 ip subnet-zero ip routing mls qos spanning-tree extend system-id class map match-all tftp Match access-group 101 class map match-all icmp Match access-group 102 policy map precedence Class tftp set ip precedence 5 Class icmp set ip precedence 1 interface FastEthernet0/1 interface FastEthernet0/2 interface FastEthernet0/3 interface FastEthernet0/4 interface FastEthernet0/5 switchport mode access interface FastEthernet0/6 BCMSN LAB 8 P1DSW1 (continued) interface FastEthernet0/7 interface FastEthernet0/8 interface FastEthernet0/9 interface FastEthernet0/10 interface FastEthernet0/11 description P1DSW1 to P2DSW2 interface FastEthernet0/12 description P1DSW1 to P2DSW2 interface GigabitEthernet0/1 interface GigabitEthernet0/2 vtp Server vtp domain bigdomain interface Vlan 1 ip address 172.16.1.100 255.255.255.0 no ip route-cache no shutdown interface Vlan0011 ip address 172.16.11.100 255.255.255.0 no ip route-cache no shutdown router eigrp 100 network 172.16.0.0 ip classless no ip http server access-list 101 permit udp any any eq tftp access-list 102 permit icmp any any echo access-list 102 permit icmp any any echo-reply line con 0 transport input none line aux 0 line vty 0 4 no scheduler allocate end Boson NetSim for CCNP Lab Manual 173