428
http://www.gratisexam.com/ JNCIP-SP JN0-661 Number : JN0-661 Passing Score : 800 Time Limit : 120 min File Version : 1.0 This is a combination of all dumps that I was able to find for the Juniper JN0-661 exam. This include the previous dumps contained within Exam Collection Testking, Lead2pass, Pass4sure, and many others. I have tried to remove any duplicate questions and to verify as many answers as possible. If you have already taken this exam some of these questions should look familiar. I hope that this will help you as much that it has helped me Good luck! http://www.gratisexam.com/ Sections 1. OSPF 2. ISIS 3. BGP 4. CoS 5. IP Multicast 6. Advanced MPLS 7. Layer 3 VPNs 8. Layer 2 VPNs 9. Misc

JNCIP-SP JN0-661 · PDF file · 2017-07-29You must ensure that r1's IPv4 loopback address exists in r3 ... redistribute the VPN routes into OSPF. Correct Answer: D ... this route

Embed Size (px)

Citation preview

Page 1: JNCIP-SP JN0-661 · PDF file · 2017-07-29You must ensure that r1's IPv4 loopback address exists in r3 ... redistribute the VPN routes into OSPF. Correct Answer: D ... this route

http://www.gratisexam.com/

JNCIP-SP JN0-661

Number: JN0-661Passing Score: 800Time Limit: 120 minFile Version: 1.0

This is a combination of all dumps that I was able to find for the Juniper JN0-661 exam. This include the previous dumps contained within Exam Collection Testking,Lead2pass, Pass4sure, and many others.

I have tried to remove any duplicate questions and to verify as many answers as possible.

If you have already taken this exam some of these questions should look familiar.

I hope that this will help you as much that it has helped me

Good luck!

http://www.gratisexam.com/

Sections1. OSPF2. ISIS3. BGP4. CoS5. IP Multicast6. Advanced MPLS7. Layer 3 VPNs8. Layer 2 VPNs9. Misc

Page 2: JNCIP-SP JN0-661 · PDF file · 2017-07-29You must ensure that r1's IPv4 loopback address exists in r3 ... redistribute the VPN routes into OSPF. Correct Answer: D ... this route

http://www.gratisexam.com/

OSPF

QUESTION 1Click the Exhibit button.

[edit protocols ospf area 0.0.0.2] user@router# show area-range 0.0.0.0/1 restrict; interface ge-0/0/1.0;

You have an OSPF area configured as shown in the exhibit. Which two statements are true? (Choose two.)

A. The 30.0.0.0/8 prefix will not be advertised to Area 0 as a Type 3 LSA.

B. The 200.0.0.0/8 prefix will not be advertised to Area 0 as a Type 3 LSA.

C. To be effective, the configuration must be used on an ASBR router.

D. To be effective, the configuration must be used on an ABR router.

Correct Answer: ADSection: OSPFExplanation

Explanation/Reference:(Area border routers only) For an area, summarize a range of IP addresses when sending summary link advertisements (within an area). To summarize multipleranges, include multiple area-range statements.

restrict - (Optional) Do not advertise the configured summary. This hides all routes that are contained within the summary, effectively creating a route filter.

Reference: https://www.juniper.net/documentation/en_US/junos/topics/reference/configuration-statement/area-range-edit-protocols-ospf.html

QUESTION 2Which OSPFv3 router ID is valid?

http://www.gratisexam.com

A. 192.168.1.1

B. ::192.168.1.1

Page 3: JNCIP-SP JN0-661 · PDF file · 2017-07-29You must ensure that r1's IPv4 loopback address exists in r3 ... redistribute the VPN routes into OSPF. Correct Answer: D ... this route

http://www.gratisexam.com/

C. 0.0.0.0

D. 2008:db8::1

Correct Answer: ASection: OSPFExplanation

Explanation/Reference:OSPFv3 Router IDs, Area IDs, and LSA link-state IDs remain at the OSPFv2 IPv4 size of 32 bits.

Reference: https://www.juniper.net/documentation/en_US/release-independent/nce/information-products/pathway-pages/nce/feature-guide-ospf-v3-for-ipv6-tc.html

QUESTION 3user@R1> show ospf interface detail Interface State Area DR ID BDR ID Nbcs xe-0/0/1.0 BDR 0.0.0.0 2.169.37.12 11.244.245.215 1 Type LAN, address 192.161.27.11, Mask 255.255.255.248, MTU 4460, Cost 40 DR addr 192.161.37.12, BDR addr 192.168.37.11, Adj count 1, Priority 128 Hello 10, Dead 40, ReXmit 5, Not Stub fe-0/2/1.0 PtToPt 0.0.0.0 0.0.0.0 0.0.0.0 Type P2P, Address 0.0.0.0, Mask 0.0.0.0, MTU 1500, Cost 2604 Adj count 0 Hello 10, Dead 40, ReXmit 5, Not stub Auth type: MDS, Active key ID 3, Start time 2013 Jul 19 10:00:00 PST IPsec SA Name: sa

user@R2> show ospf interface detail Interface State Area DR ID BDR ID Nbcs xe-1/1/1.0 BDR 0.0.0.0 192.168.37.12 11.244.245.216 1 Type LAN, address 192.161.27.12, Mask 255.255.255.248, MTU 4460, Cost 40 DR addr 192.161.37.12, BDR addr 192.168.37.11, Adj count 1, Priority 128 Hello 3, Dead 9, ReXmit 5, Not stub fe-2/2/2.0 PtToPt 0.0.0.0 0.0.0.0 0.0.0.0 Type P2P, address 0.0.0.0, Mask 0.0.0.0, MTU 1500, Cost 2604 Adj count 0 Hello 10, Dead 40, ReXmit 5, Not Stub Auth type: MDS, Active key ID 3, Start time 2013 Jul 19 10:00:00 PST IPsec SA Name: sa

Which two statements are true about the OSPF adjacency displayed in the exhibit? (Choose two.)

Click the Exhibit button.

Page 4: JNCIP-SP JN0-661 · PDF file · 2017-07-29You must ensure that r1's IPv4 loopback address exists in r3 ... redistribute the VPN routes into OSPF. Correct Answer: D ... this route

http://www.gratisexam.com/

Exhibit:

A. There is a mismatch in the dead interval parameter between routers R1 and R2.

B. There is a mismatch in the hold timer parameter between routers R1 and R2.

C. There is a mismatch in the hello interval parameter between routers R1 and R2.

D. There is a mismatch in the poll interval parameter between routers R1 and R2.

Correct Answer: ACSection: OSPFExplanation

Explanation/Reference:If the timers are equal, which they are by default in JUNOS (for LAN/P2P the Hello = 10s and Dead = 40s), the neighbors will establish a relationship (at least on 1side).

There is a Hello and Dead parameter mismatch.

On R1 we see:DR addr 192.161.37.12, BDR addr 192.168.37.11, Adj count 1, Priority 128Hello 10, Dead 40, ReXmit 5, Not Stub

On R2 we see: DR addr 192.161.37.12, BDR addr 192.168.37.11, Adj count 1, Priority 128Hello 3, Dead 9, ReXmit 5, Not stub

Reference: https://inetzero.com/what-is-your-ospf-neighbor-doing-adjancency-problems-in-ospf/

QUESTION 4Click the Exhibit button.

[edit] [edit]lab@r1# show protocols lab@r2# show protocolsospf3 { ospf3 { area 0.0.0.0 { area 0.0.0.0 { interface 1o0.0; interface 1o0.0; interface ge-1/0/6.0; interface ge-1/0/7.0; }}

lo0 = 172.16.100.1/32 [edit]

Page 5: JNCIP-SP JN0-661 · PDF file · 2017-07-29You must ensure that r1's IPv4 loopback address exists in r3 ... redistribute the VPN routes into OSPF. Correct Answer: D ... this route

http://www.gratisexam.com/

fc00:1000::1/128 lab@r2# show protocols ospf3 { area 0.0.0.0 { interface 1o0.0; interface ge-1/1/7.0; interface ge-1/1/6.0; } }

You must ensure that r1's IPv4 loopback address exists in r3's inet 0 routing table.

Referring to the exhibit, which statement is true?

A. An IPv4 unicast realm can be enabled on each router.

B. A policy can be configured on r1 to redistribute 172.16.100.1/32 into OSPFv2, which would cause r3 to eventually learn the route and place it into inet 0.

C. A RIB group can be configured on r3 to copy that route into inet 0 because 172.16.100.1/32 exists in r3's inet6.0 table.

D. A policy can be configured on r1 to redistribute 172.16.100.1/32 into OSPFv3, which would cause r3 to eventually learn the route and place it into inet 0.

Correct Answer: ASection: OSPFExplanation

Explanation/Reference:A RIB group is a way to have a routing protocol, in most cases, place information in multiple route tables.

Each RIB group is named and told where to place and retrieve route information. An example of a RIB group is:

routing-options { rib-groups { test { import-rib [ inet.0 test.inet.0 ]; } } }

Reference: https://kb.juniper.net/InfoCenter/index?page=content&id=kb16133&actp=search

QUESTION 5You have configured an OSPF stub area. The routes in the stub area require external reachability.

Which statement explains how OSPF meets this requirement?

Page 6: JNCIP-SP JN0-661 · PDF file · 2017-07-29You must ensure that r1's IPv4 loopback address exists in r3 ... redistribute the VPN routes into OSPF. Correct Answer: D ... this route

http://www.gratisexam.com/

A. The ABR will generate a 0.0.0.0/0 martian route in the area.

B. The ABR will flood Type 5 LSAs into the area.

C. The ABR will flood Type 7 LSAs into the area.

D. The ABR will generate a 0.0.0.0/0 default route in the area.

Correct Answer: DSection: OSPFExplanation

Explanation/Reference:Reachability for routes external to OSPF is achieved via a 0/0 default route injected by the ABR.

Reference: https://forums.juniper.net/jnet/attachments/jnet/Learning/58/2/AJNR_Module02_OSPF-Stub_5-1-0_Alpha.ppt

QUESTION 6You are connecting your OSPF router to your customer's RIP router and redistributing the customer's routes into your OSPF domain. Your OSPF routes is part of anNSSA and the ABR is injecting an OSPF default route, which you have advertised to your customer. After committing the configuration, you notice a routing loopbetween your OSPF router and the customer's RIP router.

Which action must you perform on your OSPF router to solve this problem?

A. Enable Type 7-to-Type 5 LSA conversion.

B. Set the customer-facing interface to passive.

C. Convert the area to a stub area.

D. Change the OSPF external route preference.

Correct Answer: DSection: OSPFExplanation

Explanation/Reference:Avoid routing loops by changing the OSPF external route preference.

Incorrect Answers:A: If multiple NSSA ABR routers are present, it is recommended that not all ABRs perform Type 7-to-5 translation to avoid routing loops.

B: We would have to make the interface on the RIP router, the customer router, passive, not the customer-facing interface on the OSPF router.

Note: By default RIP broadcasts are sent from all interfaces. RIP allows us to control this behavior. We can configure which interface should send RIP broadcast or

Page 7: JNCIP-SP JN0-661 · PDF file · 2017-07-29You must ensure that r1's IPv4 loopback address exists in r3 ... redistribute the VPN routes into OSPF. Correct Answer: D ... this route

http://www.gratisexam.com/

which not. Once we mark any interface as passive interface, RIP will stop sending updates from that interface.

Reference: https://www.juniper.net/documentation/en_US/junos15.1/topics/topic-map/ospf-stub-and-not-so-stubby-areas.html

QUESTION 7Click the Exhibit button.

Referring to the exhibit, you have recently configured a Layer 3 VPN between Site 1, Site 2, and Site 3. The CE2 device has all routes from Site 1 and Site 3. TheCE3 device has all the routes from Site 1 and Site 3. CE1 is not receiving any routes from either Site 2 or Site 3.

Which statement is correct?

A. PE2 must redistribute the routes into OSPF using a VRF export policy.

B. You must configure a sham link between all three sites.

C. OSPF is not a supported PE to CE routing protocol.

D. You must create an export policy on PE1 to redistribute the VPN routes into OSPF.

Correct Answer: DSection: OSPFExplanation

Explanation/Reference:For all PE routers, an export policy must distribute VPN routes to and from the connected CE routers in accordance with the type of routing protocol that youconfigure between the CE and PE routers within the routing instance.

To define an export policy, include the policy-statement statement. An export policy must always include the policy-statement statement, at a minimum:

Page 8: JNCIP-SP JN0-661 · PDF file · 2017-07-29You must ensure that r1's IPv4 loopback address exists in r3 ... redistribute the VPN routes into OSPF. Correct Answer: D ... this route

http://www.gratisexam.com/

policy-statement export-policy-name { term export-term-name { from protocol (bgp | ospf | rip | static); then { community add community-id; accept; } } term term-name { then reject; }}

References:

Configuring Routing Between PE and CE Routers in Layer 3 VPNshttps://www.juniper.net/documentation/en_US/junos/topics/usage-guidelines/vpns-configuring-routing-between-pe-and-ce-routers-in-layer-3-vpns.html

Configuring Policies for the VRF Table on PE Routers in VPNshttps://www.juniper.net/documentation/en_US/junos/topics/usage-guidelines/vpns-configuring-policies-for-the-vrf-table-on-pe-routers-in-vpns.html

Understanding Virtual Routing and Forwarding Tableshttps://www.juniper.net/documentation/en_US/junos/topics/concept/vpn-routing-tables-vpn-forwarding-tables.html

Understanding IPv4 Route Distribution in a Layer 3 VPNhttps://www.juniper.net/documentation/en_US/junos/topics/concept/vpn-route-distribution-within-a-layer-3-vpn.html

QUESTION 8Referring to the exhibit, your network contains eight devices participating in OSPF Area 0, and they are all in a full IBGP mesh. R7 is learning the 172.27.0.0/24network and is injecting this route into OSPF and BGP. You must ensure that on R2, all traffic destined to the 172.27.0.0/24 network from R1 uses the R2-to-R7RSVP LSP through your core network.

How should you accomplish this behavior?

Click the Exhibit button.

Exhibit:

A. Use the install active feature on R2.

B. Use the install feature on R2.

C. Use OSPF and BGP import policies on R2.

D. Use OSPF and BGP export policies on R2.

Page 9: JNCIP-SP JN0-661 · PDF file · 2017-07-29You must ensure that r1's IPv4 loopback address exists in r3 ... redistribute the VPN routes into OSPF. Correct Answer: D ... this route

http://www.gratisexam.com/

Correct Answer: ASection: OSPFExplanation

Explanation/Reference:By default, a host route toward the egress router is installed in the inet.3 or inet6.3 routing table. (The host route address is the one you configure inthe to statement.) Installing the host route allows BGP to perform next-hop resolution. It also prevents the host route from interfering with prefixes learned fromdynamic routing protocols and stored in the inet.0 or inet6.0 routing table.

Unlike the routes in the inet.0 or inet6.0 table, routes in the inet.3 or inet6.3 table are not copied to the Packet Forwarding Engine, and hence they cause no changesin the system forwarding table directly. You cannot use the ping or traceroute command through these routes. The only use for inet.3 or inet6.3 is to permit BGP toperform next-hop resolution. To examine the inet.3 or inet6.3 table, use the show route table inet.3 or show route table inet6.3 command.

To inject additional routes into the inet.3 or inet6.3 routing table, include the install statement:

install { destination-prefix active;}

Reference: https://www.juniper.net/documentation/en_US/junos/topics/usage-guidelines/mpls-adding-lsp-related-routes-to-the-inet-3-routing-table.html

QUESTION 9Click the Exhibit button.

Page 10: JNCIP-SP JN0-661 · PDF file · 2017-07-29You must ensure that r1's IPv4 loopback address exists in r3 ... redistribute the VPN routes into OSPF. Correct Answer: D ... this route

http://www.gratisexam.com/

In the exhibit, an OSPF virtual link is established between R2 and R3. However, R4 cannot reach any external destinations.

What must you do you allow R4 to reach external destinations?

http://www.gratisexam.com

A. Area 1 must be configured as a stub area.

B. Area 1 must be configured as a standard OSPF area.

C. Area 1 must be configured to use the Type 3 LSAs as the default LSA.

D. The virtual link must be configured under Area 1.

Page 11: JNCIP-SP JN0-661 · PDF file · 2017-07-29You must ensure that r1's IPv4 loopback address exists in r3 ... redistribute the VPN routes into OSPF. Correct Answer: D ... this route

http://www.gratisexam.com/

Correct Answer: BSection: OSPFExplanation

Explanation/Reference:Virtual links use a transit area that contains two or more area border routers (ABRs) to pass network traffic from one adjacent area to another. The transit area musthave full routing information and it cannot be a stub area.

Reference: https://www.juniper.net/documentation/en_US/junos/topics/concept/ospf-virtual-links-understanding.html

QUESTION 10Click the Exhibit button.

In the exhibit, you must configure an OSPF virtual link between R2 and R3 to facilitate communication between Area 0 and Area 2.

Which two addresses should you use as the neighbor IDs of the virtual link endpoints? (Choose two.)

A. The address that is associated with R2's router ID.

B. The address that is associated with R2's ge-0/0/0 interface.

C. The address that is associated with R3's router ID.

D. The address that is associated with R3's ge-0/0/1 interface.

Correct Answer: ACSection: OSPF

Page 12: JNCIP-SP JN0-661 · PDF file · 2017-07-29You must ensure that r1's IPv4 loopback address exists in r3 ... redistribute the VPN routes into OSPF. Correct Answer: D ... this route

http://www.gratisexam.com/

Explanation

Explanation/Reference:Configuration Example and Explanation

CLI Quick Configuration1. To quickly configure an OSPF virtual link on the local routing device (Device R1), copy the following commands and paste them into the CLI. Note: You must

configure both routing devices that are part of the virtual link and specify the applicable neighbor ID on each routing device.[edit]set routing-options router-id192.168.0.5 set protocols ospf area 0.0.0.0 virtual-link neighbor-id 192.168.0.3 transit-area 0.0.0.2

2. To quickly configure an OSPF virtual link on the remote routing device (Device R2), copy the following commands and paste them into the CLI.[edit]set routing-options router-id 192.168.0.3 set protocols ospf area 0.0.0.0 virtual-link neighbor-id 192.168.0.5 transit-area 0.0.0.2

Step-by-Step Procedure on R1To configure an OSPF virtual link on the local routing device (Device R1):1. Configure the router ID.

[edit]user@R1# set routing-options router-id 192.168.0.5

2. Enter OSPF configuration mode and specify OSPF area 0.0.0.0.Note: For an OSPFv3 virtual link, include the ospf3 statement at the [edit protocols] hierarchylevel.

[edit]user@R1# edit protocols ospf area 0.0.0.0

3. Configure an OSPF virtual link and specify the transit area 0.0.0.2. This routing device must be an ABR that is physically connected to the backbone.

[edit protocols ospf area 0.0.0.0]user@R1# set virtual-link neighbor-id 192.168.0.3 transit-area 0.0.0.2

4. If you are done configuring the device, commit the configuration.

[edit protocols ospf area 0.0.0.0]user@R1# commit

Step-by-Step Procedure on R2To configure an OSPF virtual link on the remote ABR (Device R2, the routing device at the other end of the link):1. Configure the router ID.

[edit]user@R2# set routing-options router-id 192.168.0.3

Page 13: JNCIP-SP JN0-661 · PDF file · 2017-07-29You must ensure that r1's IPv4 loopback address exists in r3 ... redistribute the VPN routes into OSPF. Correct Answer: D ... this route

http://www.gratisexam.com/

2. Enter OSPF configuration mode and specify OSPF area 0.0.0.0.Note: For an OSPFv3 virtual link, include the ospf3 statement at the [edit protocols] hierarchylevel.

[edit]user@R2# edit protocols ospf area 0.0.0.0

3. Configure an OSPF virtual link on the remote ABR and specify the transit area 0.0.0.2. This routing device is not physically connected to the backbone.

[edit protocols ospf area 0.0.0.0]user@R2# set virtual-link neighbor-id 192.168.0.5 transit-area 0.0.0.2

4. If you are done configuring the device, commit the configuration.

[edit protocols ospf area 0.0.0.0]user@R2# commit

Reference: http://www.juniper.net/documentation/en_US/junos12.1x46/topics/example/ospf-virtual-links-configuring.html

QUESTION 11You are deploying OSPFv2 and OSPFv3 in your network. You must enable authentication to secure OSPF communication. Which authentication method issupported?

A. MD5

B. Simple

C. IPsec

D. RSA

Correct Answer: CSection: OSPFExplanation

Explanation/Reference:OSPFv3 does not have a built-in authentication method and relies on the IP Security (IPsec) suite to provide this functionality. IPsec provides such functionality asauthentication of origin, data integrity, confidentiality, replay protection, and nonrepudiation of source. You can use IPsec to secure specific OSPFv3 interfaces andprotect OSPFv3 virtual links.

The following restrictions apply to IPsec authentication for OSPFv3:1. Dynamic Internet Key Exchange (IKE) security associations (SAs) are not supported.2. Only IPsec transport mode is supported. In transport mode, only the payload (the data you transfer) of the IP packet is encrypted and/or authenticated. Tunnel

mode is not supported.3. Because only bidirectional manual SAs are supported, all OSPFv3 peers must be configured with the same IPsec SA. You configure a manual bidirectional SA at

Page 14: JNCIP-SP JN0-661 · PDF file · 2017-07-29You must ensure that r1's IPv4 loopback address exists in r3 ... redistribute the VPN routes into OSPF. Correct Answer: D ... this route

http://www.gratisexam.com/

the [edit security ipsec] hierarchy level.4. You must configure the same IPsec SA for all virtual links with the same remote endpoint address.

With OSPFv2 can enable the following authentication types:1. Simple authentication—Authenticates by using a plain-text password that is included in the transmitted packet. The receiving routing device uses an

authentication key (password) to verify the packet.2. MD5 authentication—Authenticates by using an encoded MD5 checksum that is included in the transmitted packet. The receiving routing device uses an

authentication key (password) to verify the packet.You define an MD5 key for each interface. If MD5 is enabled on an interface, that interface accepts routingupdates only if MD5 authentication succeeds. Otherwise, updates are rejected. The routing device only accepts OSPFv2 packets sent using the same keyidentifier (ID) that is defined for that interface.

3. IPsec authentication (beginning with Junos OS Release 8.3)—Authenticates OSPFv2 interfaces, the remote endpoint of a sham link, and the OSPFv2 virtual linkby using manual security associations (SAs) to ensure that a packet’s contents are secure between the routing devices. You configure the actual IPsecauthentication separately

References:

Understanding OSPFv2 Authenticationhttps://www.juniper.net/documentation/en_US/junos/topics/concept/ospfv2-authentication-overview.html

Understanding OSPFv3 Authenticationhttps://www.juniper.net/documentation/en_US/junos/topics/concept/ospfv3-authentication-overview.html

QUESTION 12Click the Exhibit button.

Which statement is true?

Page 15: JNCIP-SP JN0-661 · PDF file · 2017-07-29You must ensure that r1's IPv4 loopback address exists in r3 ... redistribute the VPN routes into OSPF. Correct Answer: D ... this route

http://www.gratisexam.com/

A. OSPF neighbor 192.168.158.103 is least likely to be selected as the designated router.

B. OSPF neighbor 192.168.158.103 is most likely to be selected as the designated router.

C. OSPF neighbor 192.168.158.103 is ineligible to be selected as the designated router.

D. OSPF neighbor 192.168.158.103 is second most likely to be selected as the designated router.

Correct Answer: ASection: OSPFExplanation

Explanation/Reference:OSPF uses the router identifier for two main purposes: to elect a designated router, unless you manually specify a priority value, and to identify the routing devicefrom which a packet is originated. At designated router election, the router priorities are evaluated first, and the routing device with the highest priority is electeddesignated router. If router priorities tie, the routing device with the highest router identifier, which is typically the routing device’s IP address, is chosen as thedesignated router. If you do not configure a router identifier, the IP address of the first interface to come online is used. This is usually the loopback interface.Otherwise, the first hardware interface with an IP address is used.

Reference: https://www.juniper.net/documentation/en_US/junos/topics/topic-map/ospf-router-designated-router.html

QUESTION 13Click the Exhibit button.

Page 16: JNCIP-SP JN0-661 · PDF file · 2017-07-29You must ensure that r1's IPv4 loopback address exists in r3 ... redistribute the VPN routes into OSPF. Correct Answer: D ... this route

http://www.gratisexam.com/

Page 17: JNCIP-SP JN0-661 · PDF file · 2017-07-29You must ensure that r1's IPv4 loopback address exists in r3 ... redistribute the VPN routes into OSPF. Correct Answer: D ... this route

http://www.gratisexam.com/

In the exhibit, R2 is receiving the 10.100.100.0/24 prefix from R1 and R4. R1 uses the 1.1.1.1 router ID and R4 uses the 4.4.4.4 router ID to advertise the prefix toR2. Why is R2 preferring the version of the route that R1 is advertising?

A. The version of the route that R4 is advertising has a higher metric value.

B. The version of the route that R4 is advertising has an external Type 2 LSA value.

C. The version of the route that R1 is advertising has a lower associated router ID value.

D. The version of the route that R1 is advertising has a lower age value.

Correct Answer: BSection: OSPFExplanation

Explanation/Reference:When OSPF exports route information from external autonomous systems (ASs), it includes a cost, or external metric, in the route. OSPF supports two types ofexternal metrics: Type 1 and Type 2. The difference between the two metrics is how OSPF calculates the cost of the route.1. Type 1 external metrics are equivalent to the link-state metric, where the cost is equal to the sum of the internal costs plus the external cost. This means that

Type 1 external metrics include the external cost to the destination as well as the cost (metric) to reach the AS boundary router.2. Type 2 external metrics are greater than the cost of any path internal to the AS. Type 2 external metrics use only the external cost to the destination and ignore

the cost (metric) to reach the AS boundary router.By default, OSPF uses the Type 2 external metric.Both Type 1 and Type 2 external metrics can be present in the AS at the same time. In that event, Type 1 external metrics always takes the precedence.Type 1 external paths are always preferred over Type 2 external paths. When all paths are Type 2 external paths, the paths with the smallest advertised Type 2metric are always preferred.

References:

Understanding OSPF External Metricshttps://www.juniper.net/documentation/en_US/junos/topics/concept/ospf-routing-external-metrics-overview.html

show ospf databasehttps://www.juniper.net/documentation/en_US/junos/topics/reference/command-summary/show-ospf-database.html#jd0e794

QUESTION 14Which two statements regarding OSPFv2 or OSPFv3 authentication are correct? (Choose two.)

A. OSPFv2 supports MD5 authentication.

B. OSPFv2 supports MD5 or SHA authentication.

C. OSPFv2 relies on the native security stack that uses IPsec.

Page 18: JNCIP-SP JN0-661 · PDF file · 2017-07-29You must ensure that r1's IPv4 loopback address exists in r3 ... redistribute the VPN routes into OSPF. Correct Answer: D ... this route

http://www.gratisexam.com/

D. OSPFv3 relies on the native security stack that uses IPsec.

Correct Answer: ADSection: OSPFExplanation

Explanation/Reference:OSPFv3 does not have a built-in authentication method and relies on the IP Security (IPsec) suite to provide this functionality. IPsec provides such functionality asauthentication of origin, data integrity, confidentiality, replay protection, and nonrepudiation of source. You can use IPsec to secure specific OSPFv3 interfaces andprotect OSPFv3 virtual links.

The following restrictions apply to IPsec authentication for OSPFv3:1. Dynamic Internet Key Exchange (IKE) security associations (SAs) are not supported.2. Only IPsec transport mode is supported. In transport mode, only the payload (the data you transfer) of the IP packet is encrypted and/or authenticated. Tunnel

mode is not supported.3. Because only bidirectional manual SAs are supported, all OSPFv3 peers must be configured with the same IPsec SA. You configure a manual bidirectional SA at

the [edit security ipsec] hierarchy level.4. You must configure the same IPsec SA for all virtual links with the same remote endpoint address.

With OSPFv2 can enable the following authentication types:1. Simple authentication—Authenticates by using a plain-text password that is included in the transmitted packet. The receiving routing device uses an

authentication key (password) to verify the packet.2. MD5 authentication—Authenticates by using an encoded MD5 checksum that is included in the transmitted packet. The receiving routing device uses an

authentication key (password) to verify the packet.You define an MD5 key for each interface. If MD5 is enabled on an interface, that interface accepts routingupdates only if MD5 authentication succeeds. Otherwise, updates are rejected. The routing device only accepts OSPFv2 packets sent using the same keyidentifier (ID) that is defined for that interface.

3. IPsec authentication (beginning with Junos OS Release 8.3)—Authenticates OSPFv2 interfaces, the remote endpoint of a sham link, and the OSPFv2 virtual linkby using manual security associations (SAs) to ensure that a packet’s contents are secure between the routing devices. You configure the actual IPsecauthentication separately

References:

Understanding OSPFv2 Authenticationhttps://www.juniper.net/documentation/en_US/junos/topics/concept/ospfv2-authentication-overview.html

Understanding OSPFv3 Authenticationhttps://www.juniper.net/documentation/en_US/junos/topics/concept/ospfv3-authentication-overview.html

QUESTION 15You want to copy only OSPF prefixes from site.inet.0 to company.inet.0.

[edit routing-options]

Page 19: JNCIP-SP JN0-661 · PDF file · 2017-07-29You must ensure that r1's IPv4 loopback address exists in r3 ... redistribute the VPN routes into OSPF. Correct Answer: D ... this route

http://www.gratisexam.com/

user@router# showinterface-routes { rib-group inet-to-company;}rib-groups { site-to-company { import-rib [site.inet.0 company.inet.0]; import-policy site-to-company; }}

What is the proper configuration syntax you must use to accomplish this task?

A. [edit]user@router# show policy-options policy-statement site-to-companyterm ospf { from protocol ospf; then accept;}term default { then reject;}

[edit routing-options]user@router# showinterface-routes { rib-group inet site-to-company;}rib groups { site-to-company { export-rib [site.inet.0 company.inet.0]; import-policy site-to-company; }}

B. [edit]user@router# show policy-options policy-statement site-to-companyterm ospf { from protocol ospf; then accept;}term default {

Page 20: JNCIP-SP JN0-661 · PDF file · 2017-07-29You must ensure that r1's IPv4 loopback address exists in r3 ... redistribute the VPN routes into OSPF. Correct Answer: D ... this route

http://www.gratisexam.com/

then reject;}

[edit routing-options]user@router# showinterface-routes { rib-group inet site-to-company;}rib groups { site-to-company { import rib [company.inet.0 site.inet.0]; import-policy site-to-company; }}

C. [edit]user@router# show policy-options policy-statement site-to-companyterm ospf { from protocol ospf; then accept;}term default { then reject;}

[edit routing-options]user@router# showinterface-routes { rib-group inet site-to-company;}rib groups { site-to-company { import-rib [site.inet.0 company.inet.0]; export-policy site-to-company; }}

D. [edit]user@router# show policy-options policy-statement site-to-companyterm ospf { from protocol ospf; then accept;}term default {

Page 21: JNCIP-SP JN0-661 · PDF file · 2017-07-29You must ensure that r1's IPv4 loopback address exists in r3 ... redistribute the VPN routes into OSPF. Correct Answer: D ... this route

http://www.gratisexam.com/

then reject;}

[edit routing-options]user@router# showinterface-routes { rib-group inet site-to-company;}rib groups { site-to-company { export rib [company.inet.0 site.inet.0]; export-policy site-to-company; }}

Correct Answer: CSection: OSPFExplanation

Explanation/Reference:References:

Understanding RIB Groupshttps://www.juniper.net/documentation/en_US/release-independent/solutions/information-products/pathway-pages/rg-understanding-tn.pdf

rib-groupshttps://www.juniper.net/documentation/en_US/junos/topics/reference/configuration-statement/rib-groups-edit-routing-options.html

Example: Configuring Multiple Routing Instances of OSPFhttps://www.juniper.net/documentation/en_US/junos/topics/example/ospf-multiple-routing-instances-configuring.html

QUESTION 16Click the Exhibit button.

[edit protocols ospf]user@router# showoverload timeout 1800;preference 25;reference-bandwidth 1g;area 0.0.0.0 { interface ge-1/4/2.0 { metric 10;

Page 22: JNCIP-SP JN0-661 · PDF file · 2017-07-29You must ensure that r1's IPv4 loopback address exists in r3 ... redistribute the VPN routes into OSPF. Correct Answer: D ... this route

http://www.gratisexam.com/

priority 255; } interface ge-1/4/4.0 { metric 15; priority 100; }}area 0.0.0.1 { interface xe-1/2/3/0 { metric 12; priority 125; } interface xe-1/2/1.0 { metric 16; priority 99; }}

OSPF was configured 15 minutes ago and all databases are synchronized. However, the router is not receiving any transit traffic.What is a reason for this behavior?

A. The reference bandwidth has been set incorrectly.

B. The hold-time attribute is set too low.

C. The overload timeout threshold has not been reached.

D. The preference attribute has been set too high.

Correct Answer: CSection: OSPFExplanation

Explanation/Reference:OSPF Was configured 15 minutes ago but you have the overload timeout configured for 20 minutes

You can configure the local routing device so that it appears to be overloaded. An overloaded routing device determines it is unable to handle any more OSPFtransit traffic, which results in sending OSPF transit traffic to other routing devices. OSPF traffic to directly attached interfaces continues to reach the routing device.You might configure overload mode for many reasons, including:1. If you want the routing device to participate in OSPF routing, but do not want it to be used for transit traffic. This could include a routing device that is connected

to the network for analysis purposes, but is not considered part of the production network, such as network management routing devices.2. If you are performing maintenance on a routing device in a production network. You can move traffic off that routing device so network services are not

interrupted during your maintenance window.

Reference: https://www.juniper.net/documentation/en_US/junos/topics/concept/ospf-overload-function-overview.html

Page 23: JNCIP-SP JN0-661 · PDF file · 2017-07-29You must ensure that r1's IPv4 loopback address exists in r3 ... redistribute the VPN routes into OSPF. Correct Answer: D ... this route

http://www.gratisexam.com/

QUESTION 17Click the Exhibit button.

[edit]user@R1# show interfaces so-0/0/0unit 0 { family inet { address 192.168.8.45/30; }}

[edit] user@R1# show protocols ospfarea 0.0.0.1 { interface so-0/0/0.0;}

[edit]user@R2# show interfaces so-1/0/0unit 0 { family inet { address 192.168.8.45.30; }}

[edit]user@R2# show routing options router-idrouter-id 10.255.0.1;

[edit]user@R2# show protocols ospfarea 0.0.0.1 { interface so-1/0/0.0;}

You are creating an OSPF multiarea adjacency with a link between two ABRs.

Referring to the exhibit, which configuration setting must be added to the routers to allow the second adjacency to form?

A. You must add the second area under [edit protocols ospf] and add a policy statement exporting the respective router-id into OSPF.

B. You must add the second area under [edit protocols ospf] and add a static route with the destination of the other ABR's router-id in the area.

Page 24: JNCIP-SP JN0-661 · PDF file · 2017-07-29You must ensure that r1's IPv4 loopback address exists in r3 ... redistribute the VPN routes into OSPF. Correct Answer: D ... this route

http://www.gratisexam.com/

C. You must add the second area under [edit protocols ospf] and configure the respective interface as secondary in the area.

D. You must add the second area under [edit protocols ospf] and add the respective interfaces

Correct Answer: CSection: OSPFExplanation

Explanation/Reference:All of the OSPF interfaces shown in the exhibit above are currently configured for OSPF Area 0.0.0.1

Reference:

Example: Configuring a Multiarea OSPF Networkhttps://www.juniper.net/documentation/en_US/junos/topics/example/ospf-multiarea-configuring.html

QUESTION 18You have an AS boundary router which is also an area border router with an NSSA attached.

Which two LSA types are exported into the NSSA by default? (Choose two.)

A. Type 3

B. Type 5

C. Type 7

D. Type 9

Correct Answer: ACSection: OSPFExplanation

Explanation/Reference:The possible LSA type codes include:

Type 1 - Router LSA Type 2- LSA Type 3 - summary LSA Type 4 - summary LSAType 5 - external LSA Type 6 - membership LSA Type 7 - external LSA Type 8 - attributes LSA Type 9 - Opaque LSA (link-local scope) Type 10 - Opaque LSA (area scope)

Page 25: JNCIP-SP JN0-661 · PDF file · 2017-07-29You must ensure that r1's IPv4 loopback address exists in r3 ... redistribute the VPN routes into OSPF. Correct Answer: D ... this route

http://www.gratisexam.com/

Type 11 - Opaque LSA (AS scope) Link-Stat

NSSAs are defined in much the same manner as existing stub areas. To support NSSAs, a new option bit (the "N" bit) and a new type of LSA (type-7) area defined. The "N" bit ensures that routers belonging to an NSSA agree on its configuration. Similar to the stub area's use of the "E" bit, both NSSA neighbors must agree on

the setting of the "N" bit or the OSPF neighbor adjacency will not form

It should also be noted that unlike stub areas, all OSPF summary routes (type-3 LSAs) must be imported into NSSAs. This is to ensure that OSPF internal routesare always chosen over OSPF external(type-7) routes.

Therefore, NSSA routers use LSA Types 1, 2, 3, & 7

Reference:

RFC 1587http://www.ietf.org/rfc/rfc1587.txt

QUESTION 19Click the Exhibit button.

You are receiving the OSPF link state advertisement shown in the exhibit. What are two reasons for the displayed metric value? (Choose two.)

Page 26: JNCIP-SP JN0-661 · PDF file · 2017-07-29You must ensure that r1's IPv4 loopback address exists in r3 ... redistribute the VPN routes into OSPF. Correct Answer: D ... this route

http://www.gratisexam.com/

A. The neighboring router has the overload option configured.

B. The local router has the overload option configured.

C. The neighboring router has exceeded its configured prefix export limit.

D. The local router has exceeded its configured prefix import limit.

Correct Answer: ACSection: OSPFExplanation

Explanation/Reference:You can configure a local routing device running OSPF to appear to be overloaded, which allows the local routing device to participate in OSPF routing, but not fortransit traffic. When configured, the transit interface metrics are set to the maximum value of 65535.

Reference: https://www.juniper.net/documentation/en_US/junos/topics/topic-map/ospf-overload-mode.html

QUESTION 20What are three reasons an OSPF neighborship would be stuck in ExStart? (Choose three.)

A. The LSA database exchange is not yet completed.

B. There is an MTU mismatch between the OSPF routers.

C. There is an interface-type mismatch between the OSPF routers.

D. There is a unicast communication problem between the OSPF routers.

E. Both OSPF routers are using the same router ID.

Correct Answer: BDESection: OSPFExplanation

Explanation/Reference:After two OSPF neighboring routers establish bi-directional communication and complete DR/BDR election (on multi-access networks), the routers transition to theexstart state. In this state, the neighboring routers establish a master/slave relationship and determine the initial database descriptor (DBD) sequence number touse while exchanging DBD packets.

Reasons why an OSPF neighbor stuck in Two-Way State:Priority 0 configured on all routers.OSPF neighbor stuck in Exstart/Exchange.Mismatched interface maximum transmission unit (MTU).Duplicate router IDs on routers.Broken unicast connectivity.

Page 27: JNCIP-SP JN0-661 · PDF file · 2017-07-29You must ensure that r1's IPv4 loopback address exists in r3 ... redistribute the VPN routes into OSPF. Correct Answer: D ... this route

http://www.gratisexam.com/

The most common reason for a router to be stuck in ExStart is due to an MTU Mismatch

Reference: https://kb.juniper.net/InfoCenter/index?page=content&id=KB19382

QUESTION 21Click the Exhibit button.

What does 192.168.1.2 represent?

A. The address of the Area 0 virtual link

B. The address of the vltunnel interface

C. The router ID of the local virtual ABR

D. The router ID of the remote router

Correct Answer: DSection: OSPFExplanation

Explanation/Reference:Virtual Link as an InterfaceOnce the two ends of the link can communicate, the virtual link becomes an operational OSPF interface. It appears in showcommands and within the OSPF link-state database (LSDB). It is always noted in a format of vl-neighbor-id, where vldenotes it as a virtual link, and the neighbor-id is the RID of the far-end router.

Virtual Link ConfigurationThe configuration of a virtual link takes place within the Area 0.0.0.0 portion of the OSPF hierarchy. The virtual-linkcommand itself requires both a transit area and a neighbor ID to be configured. The transit area is the OSPF area throughwhich you configure the virtual link. The neighbor ID is the 32-bit router ID (RID) of the router on the far end of the virtual link.Once each side completes this configuration, each router begins to send unicast OSPF traffic towards the far-end router tocomplete the link setup and form an adjacency.

QUESTION 22You want to add a new OSPF area to your existing OSPF network; however, this area will not be directly connected to Area 0. Which feature would you use to

Page 28: JNCIP-SP JN0-661 · PDF file · 2017-07-29You must ensure that r1's IPv4 loopback address exists in r3 ... redistribute the VPN routes into OSPF. Correct Answer: D ... this route

http://www.gratisexam.com/

complete this task?

http://www.gratisexam.com

A. Routing policy

B. Not-so-stubby area

C. Virtual link

D. Type 10 LSA

Correct Answer: CSection: OSPFExplanation

Explanation/Reference:

Virtual TunnelsOne solution to the connectivity problem is to create a virtual tunnel between the two backbone areas of the companies. This feature, known as a virtual link,provides a logical connection between areas. Essentially, OSPF packets are tunneled through a transit area to establish an OSPF adjacency and logically connectthe two areas together. This establishes full connectivity between the two companies.

Remember that a virtual tunnel is a control plane feature only. Shortest path first (SPF) will still calculate the shortest physical path between two points, which mightnot be the same path as the virtual tunnel. This calculation could create some confusion when troubleshooting, which is one of the primary reasons virtual tunnelsare not considered long-termsolutions.

QUESTION 23Which two LSA types are permitted in an OSPF stub area? (Choose two.)

A. Type 1

B. Type 2

C. Type 4

D. Type 5

Correct Answer: ABSection: OSPFExplanation

Page 29: JNCIP-SP JN0-661 · PDF file · 2017-07-29You must ensure that r1's IPv4 loopback address exists in r3 ... redistribute the VPN routes into OSPF. Correct Answer: D ... this route

http://www.gratisexam.com/

Explanation/Reference:Stub areas can contain type 1, 2, and 3 LSAs. A default route is substituted for external routes.

Stub areas are areas through which, or into which, AS external advertisements are not flooded (LSA Type 4 and Type 5). You might want to create stub areas whenmuch of the topological database consists of AS external advertisements. Doing so reduces the size of the topological databases and, therefore, the amount ofmemory required on the internal routers in the stub area.

A stub area with no-summaries is a stub area that receives only the default route from the backbone. ABRs do not flood LSA Type 3, Type 4, or Type 5 into totallystubby areas.

An OSPF stub area has no external routes in it, so you cannot redistribute routes from another protocol into a stub area. A not-so-stubby-area (NSSA) allowsexternal routes to be flooded within the area with a Type 7 LSA. These routes are then leaked into other areas. However, external routes from other areas still donot enter the NSSA. (ABR does not flood LSA Type 4 and Type 5 into an attached NSSA.)

QUESTION 24Click the Exhibit button.

In the exhibit, the RIP network 192.168.0.0/24 is redistributed into OSPF on R8

Which two statements are true? (Choose two.)

Page 30: JNCIP-SP JN0-661 · PDF file · 2017-07-29You must ensure that r1's IPv4 loopback address exists in r3 ... redistribute the VPN routes into OSPF. Correct Answer: D ... this route

http://www.gratisexam.com/

A. R4 receives the RIP network in a Type 7 LSA from R8.

B. R7 receives the RIP network in a Type 5 LSA from R4.

C. R2 receives the RIP network in a Type 7 LSA from R4.

D. R3 receives the RIP network in a Type 5 LSA from R4.

Correct Answer: ADSection: OSPFExplanation

Explanation/Reference:As R8 is an OSPF ASBR Router within the NSSA for Area 2 and it will receive external RIP Routes as a Type 7 LSA. Type 7 LSA's are flooded within the NSSAarea and then converted to a Type 5 LSA from the ABR. R4 is the ABR within the NSSA area 2 so it will receive the Type 7 LSA and flood a Type 5 LSA to Area 0.R3 is an OSPF backbone router within Area 0 and it will receive the Type 5 LSA from R4 because this will LSA will be flooded through Area 0.

QUESTION 25Click the Exhibit button.

In the exhibit, a working Layer 3 VPN exists between all routers. No OSPF domain IDs are configured or attached in advertisements.

What can be configured on the PE routers to allow the internal OSPF routes in Area 3 to show up as summary (Type 3) LSAs in CE2?

A. Assign a domain ID of 1.1.1.1 to all routes injected into the Layer 3 VPN on PE1.

B. The routes will show up as summary LSAs by default.

Page 31: JNCIP-SP JN0-661 · PDF file · 2017-07-29You must ensure that r1's IPv4 loopback address exists in r3 ... redistribute the VPN routes into OSPF. Correct Answer: D ... this route

http://www.gratisexam.com/

C. Configure PE2 to have a different domain ID than PE1.

D. Configure a sham link between PE1 and CE1.

Correct Answer: BSection: OSPFExplanation

Explanation/Reference:Each ABR that transmits information from one OSPF area into another generates a Type 3 LSA to describe that information. This LSA is flooded to each router inthe OSPF area. This LSA has an area scope; therefore, it is not reflooded across the area boundary by another ABR. Instead, the receiving ABR generates a newType 3 LSA describing the link and floods it into the adjacent area.

CE1 is an ABR for Area 0 & 3. CE1 will create a Type 3 LSA and send this into Area 0. CE2 is a backbone router in area 0 so it will receive the Type 3 LSA

QUESTION 26Click the Exhibit button.

Page 32: JNCIP-SP JN0-661 · PDF file · 2017-07-29You must ensure that r1's IPv4 loopback address exists in r3 ... redistribute the VPN routes into OSPF. Correct Answer: D ... this route

http://www.gratisexam.com/

Based on the exhibit, why is the router not installing routes in the OSPF database into the routing table?

A. The neighbor is stuck in the ExStart state

B. The routes are going to a different table than inet.0

C. There is an interface type mismatch

D. There is an MTU mismatch

Page 33: JNCIP-SP JN0-661 · PDF file · 2017-07-29You must ensure that r1's IPv4 loopback address exists in r3 ... redistribute the VPN routes into OSPF. Correct Answer: D ... this route

http://www.gratisexam.com/

Correct Answer: ASection: OSPFExplanation

Explanation/Reference:The OSPF Neighbor 67.176.10.3 appears to be stuck in an ExStart state. You can see from the "show ospf interface ge-0/0/8.0 extensive" output that there is anadjacencies count of 2 when the "show ospf neighbor" output shows us that 3 adjacencies are configured.

"show ospf interface extensive" outputType of interface: LAN, NBMA, P2MP, P2P, or Virtual.State of the interface: BDR, Down, DR, DRother, Loop, PtToPt, or Waiting.

References:

show (ospf | ospf3) interfacehttps://www.juniper.net/documentation/en_US/junos/topics/reference/command-summary/show-ospf-ospf3-interface.html

show ospf interfacehttp://www.juniper.net/documentation/software/cable/junosg30/swcmdref30/html/ospf-monitor7.html

QUESTION 27A network uses IPv4 and IPv6 addressing. You must use only OSPFv3 as your IGP. Which configuration will advertise both IPv4 and IPv6 addresses to thenetwork?

A. [edit]user@router# show protocolsospf { area 0.0.0.0 { interface all; }}ospf3 { area 0.0.0.0 { interface all; }}

B. [edit]user@router# show protocolsospf3 { area 0.0.0.0 { family inet { interface all;

Page 34: JNCIP-SP JN0-661 · PDF file · 2017-07-29You must ensure that r1's IPv4 loopback address exists in r3 ... redistribute the VPN routes into OSPF. Correct Answer: D ... this route

http://www.gratisexam.com/

} family inet6 { interface all; }}

C. [edit]user@router# show protocolsospf3 { export ipv4-routes; area 0.0.0.0 { interface all; }}

[edit]user@router# show policy-optionspolicy-statemetn ipv4-routes { term get-ipv4 { from { family inet; protocols ospf; } then accept; }}

D. [edit]user@router# show protocolsospf3 { realm ipv4-unicast { area 0.0.0.0 { interface all; } } area 0.0.0.0 { interface all; }}

Correct Answer: DSection: OSPFExplanation

Page 35: JNCIP-SP JN0-661 · PDF file · 2017-07-29You must ensure that r1's IPv4 loopback address exists in r3 ... redistribute the VPN routes into OSPF. Correct Answer: D ... this route

http://www.gratisexam.com/

Explanation/Reference:By default, OSPFv3 supports only unicast IPv6 routes. In Junos OS Release 9.2 and later, you can configure OSPFv3 to support multiple address families, includingIPv4 unicast, IPv4 multicast, and IPv6 multicast. This mutliple address family support allows OSPFv3 to support both IPv6 and IPv4 nodes. Junos OS maps eachaddress family to a separate realm as defined in Internet draft draft-ietf-ospf-af-alt-06.txt, Support for Address Families in OSPFv3. Each realm maintains a separateset of neighbors and link-state database.

Configure OSPFv3 to advertise address families other than unicast IPv6. Junos OS maps each address family you configure to a separate realm with its own set ofneighbors and link-state database.

Optionsipv4-unicast—Configure a realm for IPv4 unicast routes.ipv4-multicast—Configure a realm for IPv4 multicast routes.ipv6-multicast—Configure a realm for IPv6 multicast routes.

Reference: https://www.juniper.net/documentation/en_US/junos/topics/reference/configuration-statement/realm-edit-protocols-ospf3.html

QUESTION 28Which configuration excerpt will advertise all local IPv4 and IPv6 destinations to the network?

A. protocols { ospf { area 0.0.0.0 { family inet { interface all; family inet6 { interface all; } } }}

B. protocols { ospf { export ipv6 routes; area 0.0.0.0 { interface all; } }}policy-options { policy-statement ipv6-routes { term get-ipv6 { from family inet6;

Page 36: JNCIP-SP JN0-661 · PDF file · 2017-07-29You must ensure that r1's IPv4 loopback address exists in r3 ... redistribute the VPN routes into OSPF. Correct Answer: D ... this route

http://www.gratisexam.com/

then accept; } }}

C. protocols { ospf { area 0.0.0.0 { interface all; } } ospf3 { area 0.0.0.0 { interface all; } }}

D. protocols { ospf3 { export ipv4-routes; area 0.0.0.0 { interface all; } }}policy-options { policy-statement ipv4-routes { term get-ipv4 { from family inet; then accept; } }}

Correct Answer: CSection: OSPFExplanation

Explanation/Reference:You can configure both the OSPF and OSPFv3 processes to run at the same time on a Juniper router; however, since OSPFv3 now supports the OSPFv2 addressfamily you can run one OSPF process with a separate address family for IPv4 and IPv6

QUESTION 29

Page 37: JNCIP-SP JN0-661 · PDF file · 2017-07-29You must ensure that r1's IPv4 loopback address exists in r3 ... redistribute the VPN routes into OSPF. Correct Answer: D ... this route

http://www.gratisexam.com/

Based on the topology shown in the exhibit, which two configuration statements must be applied on R2 so that it announces the 10.100/22 network to its OSPFneighbors? (Choose two.)

Click the Exhibit button.

Exhibit:

A. [edit policy-options policy-statement announce]user@router# set term 1 from route-filter 10.100.0.0/22 exact accept

B. [edit policy-options policy-statement announce]user@router# set term 1 from 10.100.0.0/22 exact accept

C. [edit]user@router# set protocols ospf export announce

D. [edit]user@router# set protocols ospf area 0 export announce

Correct Answer: ACSection: OSPFExplanation

Explanation/Reference:Answer D is incorrect

The "set protocols ospf area 0 export announce" command syntax is incorrect on a Juniper router as this parameter is not available.

A route filter is a collection of match prefixes. When specifying a match prefix, you can specify an exact match with a particular route or a less precise match. Youcan configure either a common action that applies to the entire list or an action associated with each prefix

It is also important to understand how a route filter is evaluated, particularly if the route filter includes multiple route-filter options in a from statement.

To configure a route filter, include one or more route-filter or source-address-filter statements:[edit policy-options policy-statement policy-name term term-name from]route-filter destination-prefix match-type { actions;}

The route-filter option is typically used to match an incoming route address to destination match prefixes of any type except for unicast source addresses.

Reference: https://www.juniper.net/documentation/en_US/junos/topics/usage-guidelines/policy-configuring-route-lists-for-use-in-routing-policy-match-conditions.html#id-10213710

QUESTION 30

Page 38: JNCIP-SP JN0-661 · PDF file · 2017-07-29You must ensure that r1's IPv4 loopback address exists in r3 ... redistribute the VPN routes into OSPF. Correct Answer: D ... this route

http://www.gratisexam.com/

You are asked to configure an OSPF network based on the topology shown in the exhibit. Area 1 must not receive Type 5 LSAs from the backbone, but must becapable of containing ASBRs. What will accomplish this?

Click the Exhibit button.

Exhibit:

A. Area 1 should be configured as a stub area, which by default meets the network's requirements.

B. R3 should be configured with no-externals for Area 1, which will suppress Type 5 announcements.

C. R3 should be configured with no-summaries for Area 1, which will suppress Type 5 announcements.

D. Area 1 should be configured as an NSSA, which by default meets the network's requirements.

Correct Answer: DSection: OSPFExplanation

Explanation/Reference:An NSSA area only allows LSA Types 1, 2, 3 & 7. It does not allow Type 5 LSAs but it does have an ASBR that injects Type 7 LSA's into the area. When the Type 7LSAs reach the ABR the are converted into Type 5 LSA's and then advertised into other areas.

QUESTION 31Which two statements are true when configuring OSPF authentication? (Choose two.)

A. An OSPF link can support both simple password and MD5 authentication at the same time.

B. An MD5 password requires a key ID.

C. You can configure multiple MD5 passwords simultaneously on the same link.

D. If the MD5 password negotiation fails, you can configure OSPF to automatically use a simple password as a backup.

Correct Answer: BCSection: OSPFExplanation

Explanation/Reference:MD5 authentication uses an encoded MD5 checksum that is included in the transmitted packet. The receiving routing device uses an authentication key (password)to verify the packet.

You define an MD5 key for each interface. If MD5 is enabled on an interface, that interface accepts routing updates only if MD5 authentication succeeds. Otherwise,updates are rejected. The routing device only accepts OSPFv2 packets sent using the same key identifier (ID) that is defined for that interface.

Because OSPF performs authentication at the area level, all routing devices within the area must have the same authentication and corresponding password (key)configured. For MD5 authentication to work, both the receiving and transmitting routing devices must have the same MD5 key. In addition, a simple password and

Page 39: JNCIP-SP JN0-661 · PDF file · 2017-07-29You must ensure that r1's IPv4 loopback address exists in r3 ... redistribute the VPN routes into OSPF. Correct Answer: D ... this route

http://www.gratisexam.com/

MD5 key are mutually exclusive. You can configure only one simple password, but multiple MD5 keys.

References:

https://www.juniper.net/documentation/en_US/junos/topics/example/ospfv2-md5-key-authentication-configuring.html

http://www.juniper.net/documentation/en_US/junos12.3/topics/topic-map/ospf-authentication.html

QUESTION 32An OSPF database contains two router LSAs with identical link information indicating that one LSA is not valid. Which action will immediately clear the invalid LSAfrom the network without waiting for the LSA to time out or resetting the OSPF sessions on the router?

A. user@router# deactivate protocols ospfuser@router# commituser@router# activate protocols ospfuser@router# commit

B. user@router> clear ospf database purge

C. user@router> clear ospf database

D. user@router> restart routing

Correct Answer: BSection: OSPFExplanation

Explanation/Reference:clear ospf database <purge>

purge—(Optional) Discard all entries in the link-state advertisement database; that is, all link-state advertisements are set to MAXAGE and are flooded. Thedatabase will be repopulated when the originators of the link-state advertisements receive the MAXAGE link-state advertisements and reissue them.

Reference: http://www.juniper.net/documentation/software/cable/junosg30/swcmdref30/html/ospf-monitor2.html

QUESTION 33Click the Exhibit button.

Page 40: JNCIP-SP JN0-661 · PDF file · 2017-07-29You must ensure that r1's IPv4 loopback address exists in r3 ... redistribute the VPN routes into OSPF. Correct Answer: D ... this route

http://www.gratisexam.com/

In the exhibit, R1 has a loopback address of 192.168.1.1. Its loopback interface is included in OSPF Area 1.Which two statements are true? (Choose two.)

A. R1 will advertise the loopback address in a Type 1 LSA.

B. R1 will advertise the loopback address in a Type 3 LSA.

C. Area 0 will see the loopback address in a Type 1 LSA.

D. Area 0 will see the loopback address in a Type 3 LSA.

Correct Answer: ADSection: OSPFExplanation

Explanation/Reference:Type 1 - Router LSA - the router announces its presence and lists the links to other routers or networks in the same area, together with the metrics to them. Type 1LSAs are flooded across their own area only. The link-state ID of the type 1 LSA is the originating router ID.

Type 3 - Summary LSA - an Area Border Router (ABR) takes information it has learned on one of its attached areas and summarizes it before sending it out onother areas it is connected to. This summarization helps provide scalability by removing detailed topology information for other areas, because their routinginformation is summarized into just an address prefix and metric. The summarization process can also be configured to remove a lot of detailed address prefixesand replace them with a single summary prefix, helping scalability.

References:

https://en.wikipedia.org/wiki/Link-state_advertisement

https://en.wikipedia.org/wiki/Open_Shortest_Path_First

QUESTION 34In the exhibit, R1 and R2 have a static default route configured that points toward the provider. Both routers redistribute the default route into OSPF. R2 is thepreferred gateway to reach the provider. R1 is the backup gateway. All link metrics are equal. Which two steps ensure that traffic to the provider flows through R2while the network is working properly? (Choose two.)

Page 41: JNCIP-SP JN0-661 · PDF file · 2017-07-29You must ensure that r1's IPv4 loopback address exists in r3 ... redistribute the VPN routes into OSPF. Correct Answer: D ... this route

http://www.gratisexam.com/

Click the Exhibit button.

Exhibit:

A. Redistribute the default route as a Type 1 external route on router R1 and a Type 2 external route on router R2.

B. Redistribute the default route as a Type 2 external route on router R1 and a Type 1 external route on router R2.

C. Modify the preference value of the default route on router R1 so that it is less preferred than OSPF external routes.

D. Modify the preference value of the default route on router R2 so that it is more preferred than OSPF external routes.

Correct Answer: BCSection: OSPFExplanation

Explanation/Reference:Route PreferenceThe Junos OS routing protocol process assigns a default preference value (also known as an administrative distance) to each route that the routing table receives.The default value depends on the source of the route. The preference value is a value from 0 through 4,294,967,295 (232 – 1), with a lower value indicating a morepreferred route.

Understanding OSPF External MetricsWhen OSPF exports route information from external autonomous systems (ASs), it includes a cost, or external metric, in the route. OSPF supports two types ofexternal metrics: Type 1 and Type 2. The difference between the two metrics is how OSPF calculates the cost of the route.

1. Type 1 external metrics are equivalent to the link-state metric, where the cost is equal to the sum of the internal costs plus the external cost. This means thatType 1 external metrics include the external cost to the destination as well as the cost (metric) to reach the AS boundary router.

2. Type 2 external metrics are greater than the cost of any path internal to the AS. Type 2 external metrics use only the external cost to the destination and ignorethe cost (metric) to reach the AS boundary router.

By default, OSPF uses the Type 2 external metric.

References:

https://www.juniper.net/documentation/en_US/junos/topics/reference/general/routing-protocols-default-route-preference-values.html

https://www.juniper.net/documentation/en_US/junos/topics/example/ospf-route-preference-configuring.html

https://www.juniper.net/documentation/en_US/junos/topics/concept/ospf-routing-external-metrics-overview.html

QUESTION 35An OSPF network has been designed with multiple areas to improve scalability. Which two statements are true? (Choose two.)

Page 42: JNCIP-SP JN0-661 · PDF file · 2017-07-29You must ensure that r1's IPv4 loopback address exists in r3 ... redistribute the VPN routes into OSPF. Correct Answer: D ... this route

http://www.gratisexam.com/

http://www.gratisexam.com

A. Each router in the OSPF network runs the shortest-path-first algorithm to determine paths

B. The Area Border Router for each area runs the shortest-path-first algorithm and floods its results through the area.

C. Each area must have at least one link connecting it to each of the other areas of the OSPF network.

D. OSPF provides loop-free routing within an OSPF routing domain, but does not guarantee symmetrical routing.

Correct Answer: ADSection: OSPFExplanation

Explanation/Reference:A router sends link-state advertisement (LSA) packets to advertise its state periodically and when the router's state changes. These packets include informationabout the router's adjacencies, which allows detection of nonoperational routers.

Using a reliable algorithm, the router floods LSAs throughout the area, which ensures that all routers in an area have exactly the same topological database. Eachrouter uses the information in its topological database to calculate a shortest-path tree, with itself as the root. The router then uses this tree to route network traffic.

After a router receives a new LSA and places it into the LSDB, the router runs an algorithm known as the Dijkstra algorithm (also called the SPF algorithm). Thiscomputation uses the database as a data source and results in a loop-free network topology using the best metric from the local router to all nodes in the network.

Reference: http://www.juniper.net/documentation/software/cable/junosg30/swconfig30-interfaces/html/ospf-overview5.html

QUESTION 36Click the Exhibit button.

Page 43: JNCIP-SP JN0-661 · PDF file · 2017-07-29You must ensure that r1's IPv4 loopback address exists in r3 ... redistribute the VPN routes into OSPF. Correct Answer: D ... this route

http://www.gratisexam.com/

Referring to the OSPF link metrics in the exhibit, which path will traffic from R6 take to reach R1?

A. R6, R3, R2, R4, R1

B. R6, R3, R2, R1

C. R6, R5, R4, R1

D. R6, R5, R3, R2, R4, R1

Correct Answer: BSection: OSPFExplanation

Explanation/Reference:All OSPF interfaces have a cost, which is a routing metric that is used in the link-state calculation. Routes with lower total path metrics are preferred to those withhigher path metrics. In this example, we explore how to control the cost of OSPF network segments.

Reference: https://www.juniper.net/documentation/en_US/junos12.1x47/topics/example/ospf-segment-cost-configuring.html

QUESTION 37Click the Exhibit button.

In the exhibit, Area 1 and Area 2 are configured as not-so-stubby areas. RIP network 192.168.100.0/24 is redistributed into OSPF in Area 1.Which three statementsare true? (Choose three.)

A. Network 192.168.100.0/24 is advertised in a Type 7 LSA in Area 1.

B. Network 192.168.100.0/24 is advertised in a Type 7 LSA in Area 0.

C. Network 192.168.100.0/24 is advertised in a Type 5 LSA in Area 0.

D. The area border router between Area 0 and Area 2 converts network 192.168.100.0/24 to a Type 7 LSA.

Page 44: JNCIP-SP JN0-661 · PDF file · 2017-07-29You must ensure that r1's IPv4 loopback address exists in r3 ... redistribute the VPN routes into OSPF. Correct Answer: D ... this route

http://www.gratisexam.com/

E. Area 2 does not see the network 192.168.100.0/24 in its link-state database.

Correct Answer: ACESection: OSPFExplanation

Explanation/Reference:The ASBR in area 1 will receive a RIP advertisement for 192.168.100.0/24, it will then convert this into a Type 7 advertisement and flood this into area 1. The ABR'sthat connects between area 1 and area 0 will then convert the Type 7 LSA into a Type 5 LSA and flood the Type 5 LSA into area 0. Since area 2 is an NSSA area itdoesn't allow Type 5 LSA's so no router in area 2 will receive the RIP advertisement.

QUESTION 38Router R5 has the overload parameter configured. Which statement is true?

A. R5 will purge its LSAs from the network until the overload condition is cleared.

B. R5 will increase its link metrics to 65535 and will stop forwarding transit traffic to OSPF destinations.

C. R5 will increase its link metrics to 65535 and will continue to forward transit traffic to OSPF destinations.

D. R5 will send an overload LSA to its neighbors to indicate it is in the overload state.

Correct Answer: CSection: OSPFExplanation

Explanation/Reference:You can configure a local routing device running OSPF to appear to be overloaded, which allows the local routing device to participate in OSPF routing, but not fortransit traffic. When configured, the transit interface metrics are set to the maximum value of 65535

Reference: https://www.juniper.net/documentation/en_US/junos/topics/topic-map/ospf-overload-mode.html

QUESTION 39Click the Exhibit button.

Page 45: JNCIP-SP JN0-661 · PDF file · 2017-07-29You must ensure that r1's IPv4 loopback address exists in r3 ... redistribute the VPN routes into OSPF. Correct Answer: D ... this route

http://www.gratisexam.com/

R2 and R4 advertise a default route into Area 1.Based on the configurations in the exhibit, which statement is true? (Choose two.)

A. Traffic from R1 to internal OSPF destinations in Area 0 will always transit R4.

B. Traffic from R1 to internal OSPF destinations in Area 0 will always transit R2.

C. Traffic from R1 to external OSPF destinations in Area 0 will always transit R2.

D. Traffic from R1 to external OSPF destinations in Area 0 will always transit R4.

Correct Answer: ACSection: OSPFExplanation

Explanation/Reference:OSPF Bandwidth Cost

100 Gbps = 140 Gbps = 110 Gbps= 11 Gbps = 1100 Mbps= 1

Page 46: JNCIP-SP JN0-661 · PDF file · 2017-07-29You must ensure that r1's IPv4 loopback address exists in r3 ... redistribute the VPN routes into OSPF. Correct Answer: D ... this route

http://www.gratisexam.com/

10 Mbps = 101.544 Mbps = 64768 Kbps = 133384 Kbps = 266128 Kbps = 781

Since all of the links are 1 Gbps links and OSPF will take the shortest Metric path both paths have an equal OSPF Metric cost from R1's perspective. However, R2is configured not to advertise summary routes into area 1 and R4 is configured to advertise summary routes into area 1. Therefore, R2 will only receive a defaultroute from R2 but will receive routes for specific subnets from R4. Which will mean that R1 will send traffic to R4 for internal routes but for all other routes traffic willbe sent to R2.

QUESTION 40Your OSPF network includes an NSSA. Which LSA type is injected into the NSSA by the ASBR?

A. Type 3

B. Type 5

C. Type 7

D. Type 9

Correct Answer: CSection: OSPFExplanation

Explanation/Reference:Type 7 – External LSA: also known as not-so-stubby-area (NSSA) LSA: As you can see area 1 is a NSSA (not-so-stubby-area) which doesn’t allow external LSAs(type 5). To overcome this issue we are generating type 7 LSAs instead.

Reference: https://networklessons.com/ospf/ospf-lsa-types-explained/

QUESTION 41You are asked to configure an OSPF network based on the topology shown in the exhibit. You must keep the link-state database in Area 1 as small as possible.What will accomplish this?

Click the Exhibit button.

Exhibit:

A. Area 0 should be configured as a stub area so that it will not announce routes into Area 1.

B. Area 1 should be configured as an NSSA to limit the size of the link-state database.

C. Area 1 should be configured as a stub area with no-summaries to limit the size of the link-state database.

D. Area 0 should be configured with a virtual link to R4 to limit the size of the Area 1 link-state database.

Page 47: JNCIP-SP JN0-661 · PDF file · 2017-07-29You must ensure that r1's IPv4 loopback address exists in r3 ... redistribute the VPN routes into OSPF. Correct Answer: D ... this route

http://www.gratisexam.com/

Correct Answer: CSection: OSPFExplanation

Explanation/Reference:In order to reduce the since of an OSPF Database you want to reduce the amount of routers in the area and reduce the Types of LSA's being sent. To reduce theLSA Database as much as possible it has to be configured as a Totally stubby area. You can change an area to become a totally stubby area by adding the no-summaries optional command to the ABR OSPF configuration

Reference: https://www.juniper.net/documentation/en_US/junos12.3/topics/example/ospf-stub-area-configuring.html

QUESTION 42Which two statements are true about OSPFv3? (Choose two.)

A. OSPFv3 uses a 32-bit router ID to uniquely identify a node in the network.

B. OSPFv3 uses a 128-bit router ID to uniquely identify a node in the network.

C. OSPFv3 routes are always preferred over OSPFv2 routes for all traffic.

D. OSPFv3 and OSPFv2 can be configured at the same time.

Correct Answer: ADSection: OSPFExplanation

Explanation/Reference:OSPFv3 Router IDs, Area IDs, and LSA link-state IDs remain at the OSPFv2 IPv4 size of 32 bits. Neighboring routers are always identified by the 32-bit router ID inOSPFv3.

Reference: https://www.juniper.net/documentation/en_US/release-independent/nce/information-products/pathway-pages/nce/feature-guide-ospf-v3-for-ipv6-tc.html

QUESTION 43Click the Exhibit button.

Page 48: JNCIP-SP JN0-661 · PDF file · 2017-07-29You must ensure that r1's IPv4 loopback address exists in r3 ... redistribute the VPN routes into OSPF. Correct Answer: D ... this route

http://www.gratisexam.com/

In the exhibit, Area 1 is a not-so-stubby area. Three networks are redistributed into Area 1 on R2. You must summarize the redistributed network addresses in Area1 so that only one network prefix is re-advertised into Area 0. You must also summarize the loopback addresses of R1 and R2 into a single address in Area 0.Whichconfiguration sample on R3 and R5 will complete this task?

A. [edit protocols ospf area 0.0.0.1]user@router# shownssa { area-range 192.168.0.0/16; area-range 192.168.1.0/30;}

B. [edit protocols ospf area 0.0.0.0]user@router# shownssa { area-range 192.168.0.0/16; area-range 192.168.1.0/30;}

C. [edit protocols ospf area 0.0.0.1]user@router# shownssa { area-range 192.168.0.0/16;}area-range 192.168.1.0/30;

D. [edit protocols ospf area 0.0.0.0]user@router# show

Page 49: JNCIP-SP JN0-661 · PDF file · 2017-07-29You must ensure that r1's IPv4 loopback address exists in r3 ... redistribute the VPN routes into OSPF. Correct Answer: D ... this route

http://www.gratisexam.com/

nssa { area-range 192.168.0.0/16;}area-range 192.168.1.0/30;

Correct Answer: CSection: OSPFExplanation

Explanation/Reference:External summary routes advertised into the NSSA area configured under the "set protocols ospf area 0.0.0.1 nssa area-range" stanza. Internal summary routesinjected from area 1 into the backbone (Area 0) are configured the "set protocols ospf area 0.0.0.1 area-range" stanza.

Reference: https://www.juniper.net/documentation/en_US/junos/topics/topic-map/ospf-route-summarization.html

QUESTION 44To reduce the size of OSPF Area 100, you configure the area with the no-summaries parameter. After committing this configuration change, you notice that anOSPF router in a remote area is no longer receiving Type 5 LSAs from an ASBR in Area 100.

Which statement is true in this scenario?

A. The ASBR in Area 100 generates Type 5 LSAs, and they are blocked by the ABR.

B. The ASBR in Area 100 generates Type 5 LSAs, and a virtual link is required for transport to other areas.

C. The ASBR in Area 100 generates Type 5 LSAs, and they are transported to Type 7 LSAs.

D. The ASBR in Area 100 generates Type 5 LSAs, and places them in its own database.

Correct Answer: ASection: OSPFExplanation

Explanation/Reference:The no-summaries setting prevents the ABR from advertising summary routes into the NSSA.

Reference: http://www.juniper.net/documentation/en_US/junos16.1/topics/example/ospf-not-so-stubby-area-configuring.html

QUESTION 45In the exhibit, Area 1 is configured as a stub area. What must be configured on R3 so that R4 and R5 can reach the external 10.100/22 network?

Click the Exhibit button.

Exhibit:

Page 50: JNCIP-SP JN0-661 · PDF file · 2017-07-29You must ensure that r1's IPv4 loopback address exists in r3 ... redistribute the VPN routes into OSPF. Correct Answer: D ... this route

http://www.gratisexam.com/

A. set protocols ospf area 1 stub default metric 10

B. set protocols ospf area 1 announce-default

C. set protocols ospf area 1 stub

D. set protocols ospf area 1 default

Correct Answer: ASection: OSPFExplanation

Explanation/Reference:You must explicitly configure the ABR to generate a default route when attached to a stub or not-so-stubby-area (NSSA). To inject a default route with a specifiedmetric value into the area, you must configure the default-metric option and specify a metric value.

Reference: https://www.juniper.net/documentation/en_US/junos/topics/topic-map/ospf-stub-and-not-so-stubby-areas.html

QUESTION 46Click the Exhibit button.

Referring to the exhibit, which two statements area true? (Choose two.)

A. Each area has an area-specific link-state database.

B. There is one link-state database for the entire network topology.

C. The link-state database must be identical in all areas.

D. The link-state databases in each area will be unique.

Correct Answer: ADSection: OSPFExplanation

Explanation/Reference:As each area will receive different routes based on the LSAs each LSDB will also be unique

Page 51: JNCIP-SP JN0-661 · PDF file · 2017-07-29You must ensure that r1's IPv4 loopback address exists in r3 ... redistribute the VPN routes into OSPF. Correct Answer: D ... this route

http://www.gratisexam.com/

QUESTION 47Click the Exhibit button.

In the exhibit, networks 192.168.1.0/24 and 192.168.2.0/24 are redistributed into OSPF on R5. You want the 192.168.1.0/24 prefix to be visible as an OSPF route onR1. You do not want the 192.168.2.0/24 prefix to be visible as an OSPF route on R1. What should you do?

A. Configure Area 1 as a not-so-stubby area

B. Use the "area-range 192.168.2.0/24 restrict" statement on R2 and R4 to block 192.168.2.0/24

C. Create an OSPF export policy on R2 and R4 that blocks the 192.168.2.0/24 prefix toward R1

D. Create an OSPF import policy on R1 that blocks the 192.168.2.0/24 prefix

Correct Answer: DSection: OSPFExplanation

Explanation/Reference:You can create an import policy to accept and reject the routes that you want in an area or on a router

Reference: https://www.juniper.net/documentation/en_US/junos/topics/example/ospf-import-routing-policy-configuring.html

QUESTION 48Which two statements are true about OSPF LSAs? (Choose two.)

Page 52: JNCIP-SP JN0-661 · PDF file · 2017-07-29You must ensure that r1's IPv4 loopback address exists in r3 ... redistribute the VPN routes into OSPF. Correct Answer: D ... this route

http://www.gratisexam.com/

http://www.gratisexam.com

A. Type 5 LSAs flood across area border routers.

B. Type 5 LSAs are regenerated at each area border router and can be filtered through configuration parameters.

C. Type 3 LSAs are regenerated at each area border router and can be filtered through configuration parameters.

D. Type 3 LSAs flood across area border routers.

Correct Answer: ACSection: OSPFExplanation

Explanation/Reference:Type 5 LSA's are flooded through all areas except stub area's. Type 3 LSA's are regenerated in each area by the ABR

Page 53: JNCIP-SP JN0-661 · PDF file · 2017-07-29You must ensure that r1's IPv4 loopback address exists in r3 ... redistribute the VPN routes into OSPF. Correct Answer: D ... this route

http://www.gratisexam.com/

ISIS

QUESTION 1Which two statements are true about IS-IS adjacency formation? (Choose two.)

A. Level 1 only routers never form an adjacency with Level 2 only routers.

B. Level 1 only routers always form an adjacency with Level 2 only routers.

C. For Level 1 adjacencies, area IDs must be the same.

D. For Level 2 adjacencies, area IDs must be the same.

Correct Answer: ACSection: ISISExplanation

Explanation/Reference:An L1 router does not form an adjacency with an L2 router, regardless of area.

L1 routers form L1 adjacencies with L1 and L1-L2 routers in their area.

L2 routers form L2 adjacencies with L2 and L1-L2 routers in their area or another area.

Reference: http://www.ciscopress.com/articles/article.asp?p=730191&seqNum=7

QUESTION 2An L1 router has formed an adjacency with an L1-L2 router.

Under which condition will the L1-L2 router set the attach bit in its Level 1 link-state PDUs?

http://www.gratisexam.com

A. when the L1-L2 router forms an adjacency with another L1 router in the same area

B. when the L1-L2 router forms an adjacency with an L2 router in the same area

C. when the L1-L2 router forms an adjacency with an L2 router in a different area

D. when the L1-L2 router forms an adjacency with an L1 router in a different area

Correct Answer: C

Page 54: JNCIP-SP JN0-661 · PDF file · 2017-07-29You must ensure that r1's IPv4 loopback address exists in r3 ... redistribute the VPN routes into OSPF. Correct Answer: D ... this route

http://www.gratisexam.com/

Section: ISISExplanation

Explanation/Reference:L1 routers use L1/L2 routers as the next hop for the default route 0.0.0.0/0. The L1/L2 routers do not advertise a default route--instead, the L1/L2 routers set theattached bit, which is advertised to the L1 router and causes the L1 router to install a default route with the L1/L2 router as the next hop.

If an L1/L2 router does not have an L2 adjacency to a different area than its own, the L1/L2 router will not set the attach bit, resulting in the L1 routers not installing adefault route.

Reference: Network Scaling With BGP Labeled Unicast, Design and Configuration Guide, page 8

QUESTION 3A new service provider asked you to design its IS-IS network.

You determined that two distinct IS-IS areas will be required and you must now create an ISO addressing plan for the participating intermediate systems (routers).

In this scenario, which two statements are Correct? (Choose two.)

A. The NET addresses can be configured on any interface.

B. The NET addresses must be configured on the loopback interface.

C. The system ID within the NET address must match for all intermediate systems within the same area.

D. The system ID within the NET address must unique for all intermediate systems within the same area.

Correct Answer: ADSection: ISISExplanation

Explanation/Reference:IS-IS uses ISO network addresses. Each address identifies a point of connection to the network, such as a router interface, and is called a network service access point (NSAP).

The system identifier must be unique within the network.

Reference: http://www.juniper.net/documentation/en_US/junos15.1/topics/concept/is-is-routing-overview.html

QUESTION 4Which two statements are true about route leaking in a Level 1-Level 2 network environment? (Choose two.)

A. Level 1 internal routes can be leaked into Level 2, but require a policy.

Page 55: JNCIP-SP JN0-661 · PDF file · 2017-07-29You must ensure that r1's IPv4 loopback address exists in r3 ... redistribute the VPN routes into OSPF. Correct Answer: D ... this route

http://www.gratisexam.com/

B. Level 1 external routes are leaked into Level 2 without a policy if the wide-metrics parameter is configured.

C. Level 2 internal routes can be leaked into Level 1, but require a policy.

D. Level 2 external routes are leaked into Level 1 without a policy if the wide-metrics parameter is configured.

Correct Answer: BCSection: ISISExplanation

Explanation/Reference:B: Normally, IS-IS metrics can have values up to 63. The total cost to a destination is the sum of the metrics on all outgoing interfaces along a particular path fromthe source to the destination. By default, the total path metric is limited to 1023. This metric value is insufficient for large networks and provides too little granularityfor traffic engineering, especially with high-bandwidth links. A wider range of metrics is also required if route leaking is used.

C: By default, IS-IS protocol leaks routing information from a Level 1 area to a Level 2 area. However, to leak routing information from a Level 2 area to a Level 1area, an export policy must be explicitly configured.

References:

https://www.juniper.net/techpubs/en_US/junos16.1/topics/example/example-configuring-is-isroute-leaking-L2-to-L1.html

http://www.juniper.net/documentation/en_US/junos14.1/topics/topic-map/isis-wide-metrics.html

QUESTION 5Click the Exhibit button.

user@R1# show interfaces lo0

unit 0 { family inet { address 10.220.1.1/32; } family iso { address 49.0001.0010.0220.0101.00; } }

[edit protocols isis] user@R1# show

interface ge-1/0/1.0 { level 2 disable; }

Page 56: JNCIP-SP JN0-661 · PDF file · 2017-07-29You must ensure that r1's IPv4 loopback address exists in r3 ... redistribute the VPN routes into OSPF. Correct Answer: D ... this route

http://www.gratisexam.com/

interface ge-1/1/0.0 { level 1 disable; } interface ge-1/1/1.0 { level 2 disable; } interface lo0.0; user@R7# show interfaces lo0

unit 0 { family inet { address 10.220.1.7/32; } family iso { address 49.0002.0010.0220.0107.00; } }

[edit protocols isis] user@R7 show

interface ge-1/0/1.0 { level 2 disable; } interface lo0.0

You are trying to establish an IS-IS Level 1 adjacency over ge-1/0/1 between R1 and R7 without impacting the other IS-IS adjacencies on R1.

Which configuration change would satisfy this requirement?

A. Disable Level 2 globally on R7.

B. Change the area on R7 to match R1.

C. Disable Level 2 globally on R1.

D. Change the area on R1 to match R7.

Correct Answer: BSection: ISISExplanation

Page 57: JNCIP-SP JN0-661 · PDF file · 2017-07-29You must ensure that r1's IPv4 loopback address exists in r3 ... redistribute the VPN routes into OSPF. Correct Answer: D ... this route

http://www.gratisexam.com/

Explanation/Reference:Level 1 adjacencies can be formed between routers that share a common area number, while a Level 2 adjacency can be formed between routers that might ormight not share an area number.

Reference: https://www.juniper.net/techpubs/en_US/junos16.1/topics/example/isis-multi-level.html

QUESTION 6During a network migration window, an engineer issues the set protocols isis overload timeout 1200 command.

In this scenario, which effect does this have on the IS-IS operations of the router?

A. After the first IS-IS adjacency forms, the overload bit is set for 1200 seconds.

B. When the IS-IS protocol starts, the overload bit is set after the timer of 1200 seconds expires.

C. When the IS-IS protocol starts, the overload bit is set for 1200 seconds.

D. After the first IS-IS adjacency forms, the overload bit is set after the timer of 1200 seconds expires.

Correct Answer: CSection: ISISExplanation

Explanation/Reference:With a timeout, overload mode is set if the time elapsed since the IS-IS instance started is less than the specified timeout.

To specify the number of seconds at which overload is reset, include the timeout option when specifying the overload statement:

overload timeout seconds; The time can range from 60 through 1800 seconds.

Reference: http://www.juniper.net/documentation/en_US/junos12.1x47/topics/usage-guidelines/routing-configuring-is-is-to-make-routers-appear-overloaded.html

QUESTION 7Click the Exhibit button.

Page 58: JNCIP-SP JN0-661 · PDF file · 2017-07-29You must ensure that r1's IPv4 loopback address exists in r3 ... redistribute the VPN routes into OSPF. Correct Answer: D ... this route

http://www.gratisexam.com/

In the exhibit, R2 is receiving external routing information for the 192.168.16.0/24 prefix and is redistributing it into IS-IS. R1 has a policy that leaks the192.168.16.0/24 route into Area 49.1111. R3 has a policy that leaks the 192.168.16.0/24 route into Area 49.2222. However, the IS-IS version of the route does notappear in R2's routing table.

Why does R3's route leaking policy appear not to be working?

A. The Up/Down bit is set to down for the prefix.

B. The external flag is set for the prefix.

C. You can only leak routes from Level 2 to Level 1.

D. R2 already has better routing information for the prefix.

Correct Answer: D

Page 59: JNCIP-SP JN0-661 · PDF file · 2017-07-29You must ensure that r1's IPv4 loopback address exists in r3 ... redistribute the VPN routes into OSPF. Correct Answer: D ... this route

http://www.gratisexam.com/

Section: ISISExplanation

Explanation/Reference:By default, IS-IS protocol leaks routing information from a Level 1 area to a Level 2 area. However, to leak routing information from a Level 2 area to a Level 1 area,an export policy must be explicitly configured.

From operational mode on Device R3, run the show isis database detail command.

The Down keyword identifies the routes that have successfully leaked from the Level 2 area to the Level 1 area.

Junos OS uses the up/down bit for marking prefixes on the Level 2-to-Level 1 boundary as being propagated Down, such that any router in that area neverpropagates it Up on a Level 1-to-Level 2 boundary

ISIS preference:The default ISIS preferences are the following:1. Internal level 1 routes : 152. Internal level 2 routes : 183. External level 1 routes : 1604. External level 2 routes : 165External routes meant “redistributed Routes” when the old metric style was used. When you use the knob wide-metric-only all types of ISIS routes (native, leaked,redistributed) are managed as internal route

References:

http://www.juniper.net/documentation/en_US/junos/topics/example/example-configuring-is-is-route-leaking-L2-to-L1.html

https://www.juniper.net/documentation/en_US/junos/topics/reference/configuration-statement/clns-updown-compatibility-edit-protocols-isis.html

https://www.inetzero.com/isis-training-and-junos-configuratio/

QUESTION 8Click the Exhibit button.

Page 60: JNCIP-SP JN0-661 · PDF file · 2017-07-29You must ensure that r1's IPv4 loopback address exists in r3 ... redistribute the VPN routes into OSPF. Correct Answer: D ... this route

http://www.gratisexam.com/

The exhibit displays an IS-IS topology and IS-IS-related outputs for R1 and R2. The IS-IS adjacencies between R2 and R3 are in the Up state, but the IS-ISadjacency between R1 and R2 are in a Down state.

Which two actions will ensure that all IS-IS adjacencies (R1 to R2 and R2 to R3) reach and stay in the Up state? (Choose two.)

A. Change the area ID on R2 to 49.1111.

B. Enable Level 2 operations for all of R1's interfaces.

C. Enable Level 1 operations for all of R2's interfaces.

D. Change the selector value on R1 to 01.

Correct Answer: ABSection: ISISExplanation

Explanation/Reference:R1 is currently configured as a Level 1 router only. L1 IS-IS routers will only form an adjacency with L1 routers within the same area. R1 is in area 49.1111 and R2 is

Page 61: JNCIP-SP JN0-661 · PDF file · 2017-07-29You must ensure that r1's IPv4 loopback address exists in r3 ... redistribute the VPN routes into OSPF. Correct Answer: D ... this route

http://www.gratisexam.com/

in area 49.2222. Therefore an L1 adjacency will never form between R1 and R2 unless you change the area ID on R2 to 49.1111. You could form an L2 adjacencybetween R1 and R2 but to do so you would have to delete the statement "set protocols isis interface all level 2 disable"

QUESTION 9Click the Exhibit button.

The exhibit displays an IS-IS topology and IS-IS configuration for R1, R2, and R3. R3 is redistributing the 10.100.100.0/24 route into IS-IS as an external IS-IS route.However, the 10.100.100.0/24 route is automatically being leaked into Area 49.2222.

How do you stop the automatic route leaking of the 10.100.100.0/24 prefix?

A. Remove the level 1 wide-metrics-only statement from R3.

B. Remove the level 1 wide-metrics-only statement from R2.

C. Remove the level 2 wide-metrics-only statement from R2.

D. Remove the level 2 wide-metrics-only statement from R1.

Page 62: JNCIP-SP JN0-661 · PDF file · 2017-07-29You must ensure that r1's IPv4 loopback address exists in r3 ... redistribute the VPN routes into OSPF. Correct Answer: D ... this route

http://www.gratisexam.com/

Correct Answer: ASection: ISISExplanation

Explanation/Reference:

QUESTION 10Click the Exhibit button.

Each router in the exhibit is receiving three copies of the same IS-IS LSP from the other three routers in the topology. The additional copies of the IS-IS LSPs arecausing additional processing overhead on each router. You want to reduce the overhead required to process the additional copies of the same IS-IS LSP.

Which feature accomplishes this task?

A. Configure traffic engineering.

B. Configure mesh groups.

C. Lower the CSNP interval.

D. Increase the SPF delay.

Correct Answer: BSection: ISIS

Page 63: JNCIP-SP JN0-661 · PDF file · 2017-07-29You must ensure that r1's IPv4 loopback address exists in r3 ... redistribute the VPN routes into OSPF. Correct Answer: D ... this route

http://www.gratisexam.com/

Explanation

Explanation/Reference:

QUESTION 11Which authentication method secures IS-IS hello, link-state, and sequence number PDUs?

http://www.gratisexam.com

A. Level authentication

B. Interface authentication

C. Area authentication

D. Domain authentication

Correct Answer: ASection: ISISExplanation

Explanation/Reference:

QUESTION 12You want to use IS-IS on a GRE interface where the underlying Layer 3 MTU is 1500. Which statement is correct?

A. IS-IS can be used because every IS-IS interface must be capable of transmitting packets at least as large as 1476 bytes, and the GRE header is 24 bytes.

B. IS-IS cannot be used because the IS-IS hello is not allowed to be fragmented and has the DF bit set.

C. IS-IS can be used, but the networking device directly attached to the circuit must be capable of fragmentation.

D. IS-IS cannot be used, but the router can enable a GRE key that serves the same function as IS-IS.

Correct Answer: CSection: ISISExplanation

Explanation/Reference:

Page 64: JNCIP-SP JN0-661 · PDF file · 2017-07-29You must ensure that r1's IPv4 loopback address exists in r3 ... redistribute the VPN routes into OSPF. Correct Answer: D ... this route

http://www.gratisexam.com/

QUESTION 13Click the Exhibit button.

Page 65: JNCIP-SP JN0-661 · PDF file · 2017-07-29You must ensure that r1's IPv4 loopback address exists in r3 ... redistribute the VPN routes into OSPF. Correct Answer: D ... this route

http://www.gratisexam.com/

Referring to the exhibit, what are two reasons why R2 and R4 show a different hello interval than R1 and R3? (Choose two.)

Page 66: JNCIP-SP JN0-661 · PDF file · 2017-07-29You must ensure that r1's IPv4 loopback address exists in r3 ... redistribute the VPN routes into OSPF. Correct Answer: D ... this route

http://www.gratisexam.com/

A. R4 is the DIS.

B. R2 is the DIS.

C. R4 has explicit configuration to set the hello interval to 3 seconds.

D. R2 has explicit configuration to set the hello interval to 3 seconds.

Correct Answer: BCSection: ISISExplanation

Explanation/Reference:

QUESTION 14Click the Exhibit button.

[edit protocols isis]user@router# showinterface so-0/0/0.0 { level 2 disable;}interface fe-1/0/0.0;interface fe-2/0/0.0; passive;}

You have implemented the IS-IS configuration shown in the exhibit. Which two statements are true? (Choose two.)

A. An IS-IS adjacency can establish on the fe-2/1/0.0 interface.

B. The SONET interface configuration allows the sharing of only Level 2 routes.

C. The fe-1/0/0.0 interface configuration allows sharing of Level 1 and Level 2 routes.

D. The fe-2/0/0.0 interface configuration allows advertising of its IP address into the LSPs.

Correct Answer: CDSection: ISISExplanation

Explanation/Reference:

QUESTION 15

Page 67: JNCIP-SP JN0-661 · PDF file · 2017-07-29You must ensure that r1's IPv4 loopback address exists in r3 ... redistribute the VPN routes into OSPF. Correct Answer: D ... this route

http://www.gratisexam.com/

Click the Exhibit button.

[edit]user@router# show protocols isisexport tag-lo0;traffic-engineering disable;interface all;

[edit]user@router#show policy-optionspolicy-statement tag-lo0{ from interface [lo0.0 fe-0/0/1.0 fe-0/0/2]; then { tag 200; accept; }}

You have configured your Junos device to tag routes; however, you are not seeing the routes being tagged. What is causing the problem?

A. You must configure the tagging on the physical interfaces, not on the loopback.

B. Route tagging does not work when IS-IS traffic engineering is disabled.

C. You must import the policy into IS-IS, not export it.

D. The policy-statement should have only a then tag 200; the acceptis accepting the route and ignoring the tag.

Correct Answer: BSection: ISISExplanation

Explanation/Reference:

QUESTION 16Click the Exhibit button.

The configuration excerpts shown below are applied to R1 and R2:

Page 68: JNCIP-SP JN0-661 · PDF file · 2017-07-29You must ensure that r1's IPv4 loopback address exists in r3 ... redistribute the VPN routes into OSPF. Correct Answer: D ... this route

http://www.gratisexam.com/

[edit protocols isis]user@R1# showlevel 2 disable;interface all

[edit protocols isis]user@R2# showinterface all;

Based on the exhibit and the configurations above, what combination of IS-IS adjacencies are created between R1 and R2?

A. No adjacency is created

B. Both L1 and L2

C. L1 only

D. L2 only

Correct Answer: ASection: ISISExplanation

Explanation/Reference:E

QUESTION 17Click the Exhibit button.

Page 69: JNCIP-SP JN0-661 · PDF file · 2017-07-29You must ensure that r1's IPv4 loopback address exists in r3 ... redistribute the VPN routes into OSPF. Correct Answer: D ... this route

http://www.gratisexam.com/

The 10.200/16 network is announced as an IS-IS route by R2 to its IS-IS neighbors. R3 and R4 are configured with an IS-IS export policy, which announces thisroute to R5 and R6.

Which statement is true?

A. When viewed on R5 the 10.200/16 route will be marked down.

B. When viewed on R5 the 10.200/16 route will be marked up.

C. The 10.200/16 route will not be visible on R5.

D. The 10.200/16 route will be marked with the overload bit.

Correct Answer: ASection: ISISExplanation

Explanation/Reference:Explanation:

QUESTION 18Click the Exhibit button.

Page 70: JNCIP-SP JN0-661 · PDF file · 2017-07-29You must ensure that r1's IPv4 loopback address exists in r3 ... redistribute the VPN routes into OSPF. Correct Answer: D ... this route

http://www.gratisexam.com/

Based on the output shown in the exhibit, what does up signify?

A. Prefixes are up if the interface on the local router toward the destination is functioning correctly.

B. Prefixes are up if their unfragmented-packets value is flagged in the LSP.

C. Prefixes are up if their LSP has not crossed an area boundary from level 2 to level 1.

D. Prefixes are up if their unusable-path value is flagged in the LSP.

Correct Answer: CSection: ISISExplanation

Explanation/Reference:

QUESTION 19Click the Exhibit button.

Page 71: JNCIP-SP JN0-661 · PDF file · 2017-07-29You must ensure that r1's IPv4 loopback address exists in r3 ... redistribute the VPN routes into OSPF. Correct Answer: D ... this route

http://www.gratisexam.com/

Based on the output in the exhibit, which statement is correct?

A. R4 has been configured with an IS-IS export policy and is announcing external routing information.

B. R3 and R4 have an adjacency at both level 1 and level 2.

C. R3 has been configured so that it is not used for transit traffic.

D. R3 and R4 have only a level 2 adjacency.

Correct Answer: BSection: ISISExplanation

Explanation/Reference:

QUESTION 20Click the Exhibit button.

Page 72: JNCIP-SP JN0-661 · PDF file · 2017-07-29You must ensure that r1's IPv4 loopback address exists in r3 ... redistribute the VPN routes into OSPF. Correct Answer: D ... this route

http://www.gratisexam.com/

The IGP is IS-IS. R2 has configured its loopback interface in Level 2 only. Referring to the exhibit, which statement is true?

A. R2 advertises its loopback address to all L1 adjacencies.

B. R1 cannot reach R2's loopback address.

C. R1 uses a default route to reach R2's loopback address.

D. R1 automatically selects R2 as the default gateway to reach R2's loopback address.

Correct Answer: CSection: ISISExplanation

Explanation/Reference:

QUESTION 21You are monitoring the control plane traffic using a network analyzer on an Ethernet network segment with all routers configured with IS-IS routing. Which twostatements are true? (Choose two.)

http://www.gratisexam.com

A. DIS will send hellos more frequently than other IS-IS devices.

B. L1 and L2 hellos are combined in a single hello packet.

C. PSNPs are sent periodically.

Page 73: JNCIP-SP JN0-661 · PDF file · 2017-07-29You must ensure that r1's IPv4 loopback address exists in r3 ... redistribute the VPN routes into OSPF. Correct Answer: D ... this route

http://www.gratisexam.com/

D. Only the DIS will send CSNPs periodically.

Correct Answer: ADSection: ISISExplanation

Explanation/Reference:

QUESTION 22An IS-IS level 1-only router is configured within a larger multilevel hierarchy. Which OSPF area type resembles the routing information in the L1 router's table?

A. OSPF default area

B. OSPF stub area

C. OSPF NSSA

D. OSPF NSSA with no summaries

Correct Answer: DSection: ISISExplanation

Explanation/Reference:

QUESTION 23Click the Exhibit button.

Page 74: JNCIP-SP JN0-661 · PDF file · 2017-07-29You must ensure that r1's IPv4 loopback address exists in r3 ... redistribute the VPN routes into OSPF. Correct Answer: D ... this route

http://www.gratisexam.com/

Page 75: JNCIP-SP JN0-661 · PDF file · 2017-07-29You must ensure that r1's IPv4 loopback address exists in r3 ... redistribute the VPN routes into OSPF. Correct Answer: D ... this route

http://www.gratisexam.com/

R1 and R2 are directly connected using the interfaces shown in the exhibit. R1 can ping R2's interface, and R2 can ping R1's interface. The IS-IS adjacency will notcome up. What is causing the adjacency to fail?

A. The correct levels are not configured under protocols isis.

B. The link MTU is too small to support IS-IS.

C. Authentication is not properly configured for the adjacency.

D. Both routers are configured as the DR, causing a conflict.

Correct Answer: BSection: ISISExplanation

Page 76: JNCIP-SP JN0-661 · PDF file · 2017-07-29You must ensure that r1's IPv4 loopback address exists in r3 ... redistribute the VPN routes into OSPF. Correct Answer: D ... this route

http://www.gratisexam.com/

Explanation/Reference:

QUESTION 24Click the Exhibit button.

Based on the output in the exhibit, which statement is correct?

A. R4 has been configured with an IS-IS export policy and is announcing external routing information.

B. R3 and R4 have an adjacency at both level 1 and level 2.

C. R3 has been configured so that it is not used for transit traffic.

D. R3 and R4 have only a level 2 adjacency.

Correct Answer: DSection: ISISExplanation

Explanation/Reference:

QUESTION 25Click the Exhibit button.

Page 77: JNCIP-SP JN0-661 · PDF file · 2017-07-29You must ensure that r1's IPv4 loopback address exists in r3 ... redistribute the VPN routes into OSPF. Correct Answer: D ... this route

http://www.gratisexam.com/

In the exhibit, network 172.16.0.0/16 is redistributed into IS-IS in Area 49.0002. R1 must use R2 to access 172.16.0.0/16. All other traffic leaving Area 49.0001 mustuse R4.Which three steps will accomplish this task? (Choose three.)

A. Configure R1 to ignore the attached bit.

B. Disable the attached bit on R4 in Area 49.0001.

C. Enable an L2 adjacency on the link between R1 and R2.

D. Leak network 172.16.0.0/16 into L1 on R2.

E. Redistribute a static default route into L1 on R4.

Correct Answer: ACDSection: ISISExplanation

Explanation/Reference:

QUESTION 26Which statement is true about IS-IS?

A. IS-IS level 1 internal routes are announced to level 2 by default.

B. All IS-IS level 1 routes are announced to level 2 by default.

C. IS-IS level 2 internal routes are announced to level 1 by default.

D. IS-IS does not share routes between level 1 and level 2 by default.

Correct Answer: ASection: ISISExplanation

Page 78: JNCIP-SP JN0-661 · PDF file · 2017-07-29You must ensure that r1's IPv4 loopback address exists in r3 ... redistribute the VPN routes into OSPF. Correct Answer: D ... this route

http://www.gratisexam.com/

Explanation/Reference:

QUESTION 27Click the Exhibit button.

The IGP is IS-IS. Routes from R1 need to be present on R6. Referring to the exhibit, what will accomplish this task?

http://www.gratisexam.com

A. Create an L1 adjacency between R2 and R3 to allow the routes to pass through to R6.

B. Use policy on R3 to leak R1's routes from L2 to L1.

C. Change the area address from 49.0003 to 49.0001 on R6 to allow R6 to accept routes from R1.

D. Use policy on R2 to leak R1's routes from L1 to L2.

Correct Answer: BSection: ISISExplanation

Explanation/Reference:

QUESTION 28

Page 79: JNCIP-SP JN0-661 · PDF file · 2017-07-29You must ensure that r1's IPv4 loopback address exists in r3 ... redistribute the VPN routes into OSPF. Correct Answer: D ... this route

http://www.gratisexam.com/

Click the Exhibit button.

R2 is announcing the 10.200/16 network to its IS-IS neighbors. No routing policies have been applied to R3. Referring to the exhibit, will R5 have 10.200/16 as anIS-IS route?

A. Yes; IS-IS level 2 externals are passed from level 2 to level 1 by default.

B. No; IS-IS level 2 externals are only passed to level 1 if wide-metrics-only is configured on all routers.

C. Yes; all level 2 routing information is shared throughout an IS-IS domain by default.

D. No; IS-IS does not announce routes from level 2 to level 1 unless a routing policy is applied.

Correct Answer: DSection: ISISExplanation

Explanation/Reference:

QUESTION 29Click the Exhibit button.

Page 80: JNCIP-SP JN0-661 · PDF file · 2017-07-29You must ensure that r1's IPv4 loopback address exists in r3 ... redistribute the VPN routes into OSPF. Correct Answer: D ... this route

http://www.gratisexam.com/

Based on the output in the exhibit, which statement is correct?

A. R4 has been configured with an IS-IS export policy and is announcing external routing information.

B. R3 and R4 have an adjacency at both level 1 and level 2.

C. R3 has been configured so that it is not used for transit traffic.

D. R3 and R4 are both attached to other IS-IS areas.

Correct Answer: CSection: ISISExplanation

Explanation/Reference:

QUESTION 30Click the Exhibit button.

Page 81: JNCIP-SP JN0-661 · PDF file · 2017-07-29You must ensure that r1's IPv4 loopback address exists in r3 ... redistribute the VPN routes into OSPF. Correct Answer: D ... this route

http://www.gratisexam.com/

The output in the exhibit was captured on an interface. Which three statements are true about the configuration on the router with hostname SaoPaulo? (Choosethree.)

A. Wide metrics is not in use.

Page 82: JNCIP-SP JN0-661 · PDF file · 2017-07-29You must ensure that r1's IPv4 loopback address exists in r3 ... redistribute the VPN routes into OSPF. Correct Answer: D ... this route

http://www.gratisexam.com/

B. The router has the overload bit set to "on".

C. Authentication is enabled.

D. System ID is 1921.6805.2001.

E. Level 2 routing is enabled.

Correct Answer: ACESection: ISISExplanation

Explanation/Reference:

QUESTION 31Click the Exhibit button.

Based on the output shown in the exhibit, which statement is correct?

A. R3 is the designated intermediate system.

B. R3 is the backup designated intermediate system.

C. R3 has been configured with an export policy and is announcing external routes to IS-IS neighbors.

D. R3 is using both IPv4 and IPv6 resulting in two pseudonodes.

Page 83: JNCIP-SP JN0-661 · PDF file · 2017-07-29You must ensure that r1's IPv4 loopback address exists in r3 ... redistribute the VPN routes into OSPF. Correct Answer: D ... this route

http://www.gratisexam.com/

Correct Answer: ASection: ISISExplanation

Explanation/Reference:

QUESTION 32IS-IS is configured to support both IPv4 and IPv6 routing. Which statement is true?

A. Separate IPv4 and IPv6 hellos will be sent.

B. IPv6 will have a separate link-state database.

C. IS-IS v6 support must be enabled under protocols isis.

D. IS-IS sends IPv6 topology information as new TLVs in existing LSPs.

Correct Answer: DSection: ISISExplanation

Explanation/Reference:

QUESTION 33Click the Exhibit button.

Page 84: JNCIP-SP JN0-661 · PDF file · 2017-07-29You must ensure that r1's IPv4 loopback address exists in r3 ... redistribute the VPN routes into OSPF. Correct Answer: D ... this route

http://www.gratisexam.com/

Based on the exhibit, what do you expect to find in the configuration on R1 and R4?

A. a policy leaking level 1 routes into level 2

B. a policy leaking level 2 routes into level 1

C. a policy setting the attached bit on level 2 routes

D. a policy setting the attached bit on level 1 routes

Correct Answer: BSection: ISISExplanation

Explanation/Reference:

QUESTION 34Click the Exhibit button.

Page 85: JNCIP-SP JN0-661 · PDF file · 2017-07-29You must ensure that r1's IPv4 loopback address exists in r3 ... redistribute the VPN routes into OSPF. Correct Answer: D ... this route

http://www.gratisexam.com/

All routers in the exhibit are running IS-IS level 2 routing. The wide-metrics-only parameter is configured on all routers. Which metric does R1 see for the path toR4?

A. 136

B. 138

C. 310

D. 320

Correct Answer: DSection: ISISExplanation

Explanation/Reference:

QUESTION 35Your are the administrator for a network that uses IS-IS as its IGP. As the network grows, you find that the protocol's default capabilities for setting metrics is limitingyour options. Which feature can you implement to provide a larger range of metric configuration capabilities?

A. extended metrics

B. wide metrics

C. expanded metrics

D. full metrics

Correct Answer: BSection: ISISExplanation

Explanation/Reference:

QUESTION 36Click the Exhibit button.

user@R1# show interfaces lo0unit 0 { family inet { address 10.220.1.1/32; } family iso {

Page 86: JNCIP-SP JN0-661 · PDF file · 2017-07-29You must ensure that r1's IPv4 loopback address exists in r3 ... redistribute the VPN routes into OSPF. Correct Answer: D ... this route

http://www.gratisexam.com/

address 49.0001.0010.0220.0101.00; }}

{edit protocols isis}user@R1# showinterface ge-1/0/1.0 { level 2 disable;}interface ge-1/1/0.0 { level 1 disable;}interface ge-1/1/1.0 { level 2 disable;}interface lo0.0;

user@R7# show interfaces lo0unit 0 { family inet { address 10.220.1.7/32; } family iso { address 49.0002.0010.0220.0107.00; }}

{edit protocols isis]user@R7 showinterface ge-1/0/1.0 { level 2 disable;}interface lo0.0

You are trying to establish an IS-IS Level 1 adjacency over ge-1/0/1 between R1 and R7 without impacting the other IS-IS adjacencies on R1.

Which configuration change would satisfy this requirement?

A. Disable Level 2 globally on R7.

B. Change the area on R7 to match R1.

C. Disable Level 2 globally on R1.

Page 87: JNCIP-SP JN0-661 · PDF file · 2017-07-29You must ensure that r1's IPv4 loopback address exists in r3 ... redistribute the VPN routes into OSPF. Correct Answer: D ... this route

http://www.gratisexam.com/

D. Change the area on R1 to match R7.

Correct Answer: BSection: ISISExplanation

Explanation/Reference:Level 1 adjacencies can be formed between routers that share a common area number, while a Level 2 adjacency can be formed between routers that might ormight not share an area number.

References: https://www.juniper.net/techpubs/en_US/junos16.1/topics/example/isis-multi-level.html

QUESTION 37Click the Exhibit button.

What is the relevance of "ignore-attached-bit" on R3 in the exhibit?

http://www.gratisexam.com

A. R3 will not install a default route

B. R3 will filter LSPs with the attached bit set

Page 88: JNCIP-SP JN0-661 · PDF file · 2017-07-29You must ensure that r1's IPv4 loopback address exists in r3 ... redistribute the VPN routes into OSPF. Correct Answer: D ... this route

http://www.gratisexam.com/

C. R3 will ignore routes from attached areas

D. R3 is not attached to another area

Correct Answer: ASection: ISISExplanation

Explanation/Reference:

QUESTION 38Click the Exhibit button.

You manage the IS-IS network shown in the exhibit. You do not want the level 1 routers to create a default route toward R3. What must you configure to accomplishthis?

A. An IS-IS export policy should be applied to R3, which rejects the 0/0 route.

B. An IS-IS import policy should be applied to R4 and R5, which rejects the 0/0 route.

C. R4 and R5 should be configured with the "disable-attached-bit" parameter.

D. R4 and R5 should be configured with the "ignore-attached-bit" parameter.

Correct Answer: D

Page 89: JNCIP-SP JN0-661 · PDF file · 2017-07-29You must ensure that r1's IPv4 loopback address exists in r3 ... redistribute the VPN routes into OSPF. Correct Answer: D ... this route

http://www.gratisexam.com/

Section: ISISExplanation

Explanation/Reference:

QUESTION 39Click the Exhibit button.

Which two statements are true about the IS-IS network? (Choose two)

A. Routers not shown must be level 1 only.

B. Pseudo node election is not complete.

C. R5 is the DIS for Level 1.

D. R6 is a level 1 and level 2 router.

Correct Answer: CDSection: ISISExplanation

Explanation/Reference:

QUESTION 40Click the Exhibit button.

Page 90: JNCIP-SP JN0-661 · PDF file · 2017-07-29You must ensure that r1's IPv4 loopback address exists in r3 ... redistribute the VPN routes into OSPF. Correct Answer: D ... this route

http://www.gratisexam.com/

The exhibit displays an IS-IS topology and an IS-IS configuration for R3 and R4. R4 cannot reach any external destinations or addresses located in Area 49.1111.

How would you ensure that R4 can reach external destinations and addresses located in area 49.1111?

A. Configure an export policy on R3 that leaks all IS-IS routes from Level 2 to Level 1.

B. Configure R3's authentication key to match R4's authentication key.

C. Remove the overload statement on R4.

D. Remove the ignore-attached-bit statement on R4.

Correct Answer: DSection: ISISExplanation

Explanation/Reference:

Page 91: JNCIP-SP JN0-661 · PDF file · 2017-07-29You must ensure that r1's IPv4 loopback address exists in r3 ... redistribute the VPN routes into OSPF. Correct Answer: D ... this route

http://www.gratisexam.com/

QUESTION 41You are trying to establish an IS-IS Level 1 adjacency over ge-1/0/1 between R1 and R7 without impacting the other IS-IS adjacencies on R1.

Which configuration change would satisfy this requirement?

http://www.gratisexam.com

Exhibit:

Page 92: JNCIP-SP JN0-661 · PDF file · 2017-07-29You must ensure that r1's IPv4 loopback address exists in r3 ... redistribute the VPN routes into OSPF. Correct Answer: D ... this route

http://www.gratisexam.com/

A. Disable Level 2 globally on R7

B. Change the area on R7 to match R1

C. Disable Level 2 globally on R1

D. Change the area on R1 to match R7

Correct Answer: BSection: (none)

Page 93: JNCIP-SP JN0-661 · PDF file · 2017-07-29You must ensure that r1's IPv4 loopback address exists in r3 ... redistribute the VPN routes into OSPF. Correct Answer: D ... this route

http://www.gratisexam.com/

Explanation

Explanation/Reference:

Page 94: JNCIP-SP JN0-661 · PDF file · 2017-07-29You must ensure that r1's IPv4 loopback address exists in r3 ... redistribute the VPN routes into OSPF. Correct Answer: D ... this route

http://www.gratisexam.com/

BGP

QUESTION 1Click the Exhibit button.

The Client 1 router forwards a route learned from its EBGP peer to the route reflector RR1. The route reflector forwards the route to the Client 2 router.

However, the Client 2 router uses suboptimal routing to reach the EBGP route destination.

What would cause this behavior?

A. The route reflector becomes the default forwarding path for packets sent from Client 2 towards the EBGP route destination.

B. The route reflector is using the no-client-reflect parameter.

C. The route reflector has a next-hop self policy for EBGP-learned routes.

D. The route reflector is applying the originator ID attribute to the route.

Correct Answer: CSection: BGPExplanation

Explanation/Reference:

QUESTION 2Click the Exhibit button.

Page 95: JNCIP-SP JN0-661 · PDF file · 2017-07-29You must ensure that r1's IPv4 loopback address exists in r3 ... redistribute the VPN routes into OSPF. Correct Answer: D ... this route

http://www.gratisexam.com/

Referring to the exhibit, what are three operations performed by the service provider's PE routers? (Choose three.)

http://www.gratisexam.com

A. Modify the VRF label assigned using MP-BGP.

B. Maintain the customer's /32 loopback internal routes.

C. Use MP-EBGP to send Customer Site 2's internal routes to CE-1.

D. Maintain the customer's external routes.

E. Maintain routes internal to the provider's network.

Correct Answer: BCESection: BGPExplanation

Explanation/Reference:

QUESTION 3Click the Exhibit button.

[edit]user@router# show protocols bgpexport nhs;group INT { type internal;

Page 96: JNCIP-SP JN0-661 · PDF file · 2017-07-29You must ensure that r1's IPv4 loopback address exists in r3 ... redistribute the VPN routes into OSPF. Correct Answer: D ... this route

http://www.gratisexam.com/

local-address 172.16.12.205; cluster 172.16.12.205; neighbor 172.16.12.237; neighbor 172.16.12.210;}group EXT { type external; local-address 23.56.83.210; peer-as 200; neighbor 23.56.83.209}

[edit]user@router# show policy-optionspolicy-statement nhs { term one { from protocol bgp; then { next-hop self; } } term two { then accept; }}

You implemented the configuration shown in the exhibit on your route reflector device. However, you notice traffic is transiting the route reflector rather than takingthe optimum path.

Which two actions would solve the problem? (Choose two.)

A. Change the policy to match on the external BGP neighbor.

B. Change the policy to match on the internal BGP neighbor.

C. Change a direct peering session between both internal neighbors and use the multihop parameter.

D. Change a direct peering session between both internal neighbors and use the no-client-reflect parameter.

Correct Answer: ADSection: BGPExplanation

Explanation/Reference:

Page 97: JNCIP-SP JN0-661 · PDF file · 2017-07-29You must ensure that r1's IPv4 loopback address exists in r3 ... redistribute the VPN routes into OSPF. Correct Answer: D ... this route

http://www.gratisexam.com/

The no-client-reflect command disables intracluster route redistribution by the system acting as the route reflector. Include this statement when the client cluster isfully meshed to prevent the sending of redundant route advertisements. Route reflection provides a way to decrease BGP control traffic and minimizing the numberof update messages sent within the AS.

Reference: https://www.juniper.net/documentation/en_US/junos16.1/topics/concept/routing-protocol-bgpsecurity-route-reflector-understanding.html

QUESTION 4Your company has multiple upstream BGP connections to the Internet ISP-A, ISP-B, and ISP-C. You want to ensure that all traffic coming into your network usesISP-A.

How would you accomplish this task?

A. Change the route preference to be higher on routes being advertised to ISP-B and ISP-C.

B. Prepend your AS number on routes being advertised to ISP-B and ISP-C.

C. Change the local preference to be higher on routes being advertised to ISP-A.

D. Prepend your AS number on routes being advertised to ISP-A.

Correct Answer: ASection: BGPExplanation

Explanation/Reference:Understanding BGP Path Selection

For each prefix in the routing table, the routing protocol process selects a single best path.

After the best path is selected, the route is installed in the routing table.

The best path becomes the active route if the same prefix is not learned by a protocol with a lower (more preferred) global preference value, also known as theadministrative distance.

The algorithm for determining the active route is as follows:

1. Verify that the next hop can be resolved. 2. Choose the path with the lowest preference value (routing protocol process preference).

Routes that are not eligible to be used for forwarding (for example, because they were rejected by routing policy or because a next hop is inaccessible) have apreference of ? and are never chosen. Etc.

Reference: https://www.juniper.net/documentation/en_US/junos12.3/topics/reference/general/routing-ptotocols-address-representation.html

Page 98: JNCIP-SP JN0-661 · PDF file · 2017-07-29You must ensure that r1's IPv4 loopback address exists in r3 ... redistribute the VPN routes into OSPF. Correct Answer: D ... this route

http://www.gratisexam.com/

QUESTION 5Click the Exhibit button.

RR:

protocols { bgp { group ebgd { type external; peer-as 100; neighbor 172.16.1.1 { description R1; } } } group ibgp { type internal; neighbor 172.16.1.2 { description R2;

Page 99: JNCIP-SP JN0-661 · PDF file · 2017-07-29You must ensure that r1's IPv4 loopback address exists in r3 ... redistribute the VPN routes into OSPF. Correct Answer: D ... this route

http://www.gratisexam.com/

} } group cluster { type internal; neighbor 172.16.1.3 { description R3; } neighbor 172.16.1.4 { description R4; } neighbor 172.16.1.5 { description R5; } cluster 0.0.0.1; no-client-reflect; } } }

Router RR is receiving routes from R1, R2, R3, and R4 as shown in the exhibit.

Which routes will RR advertise to R5? (Choose two.)

A. routes from R4

B. routes from R1

C. routes from R2

D. routes from R3

Correct Answer: BCSection: BGPExplanation

Explanation/Reference:

QUESTION 6Click the Exhibit button.

user@router# run show route 2.0.0.0/8

Page 100: JNCIP-SP JN0-661 · PDF file · 2017-07-29You must ensure that r1's IPv4 loopback address exists in r3 ... redistribute the VPN routes into OSPF. Correct Answer: D ... this route

http://www.gratisexam.com/

inet.0: 101 destinations, 198 routes (100active, 0 holddown, 1 hidden)+ = Active Route, - = Last Active, * = Both

2.0.0.0/8 *[BGP/170] 00:12:06, MED1000, Localpref 100, from 10.220.1.2 As path: 2000 I,validation-state: unverified > to 10.220.15.2 via ge-1/0/0.0, label-switched-path r1-to-r3 to 10.220.12.2 via ge-1/1/0.0, label-switched-path r1-to-r3 [BGP/170] 0010, MED1000, localpref 100, from 10.220.1.5 AS path: 2000 I,validation-state: unverified > to 10.220.15.2 via ge-1/0/0.0, label-switched-path r1-to-r3 to 10.220.12.2 via ge-1/1/0.0, label-switched-path r1-to-r32.6.6.6/32 *[BGP/170] 00:12:06, MED1000, localpref 100, from 10.220.1.2 AS path: 2000 I,validation-state: unverified > to 10.220.15.2 via ge-1/0/0.0, label-switched-path r1-tor3 to 10.220.12.2 via ge-1/1/0.0, label-switched-path r1-to-r3 [BGP/170] 00:12:10, MED1000, localpref 100, from 10.220.1.5 AS path: 2000 I,validation-state: unverified > to 10.220.15.2 via ge-1/0/0.0, label-switched-path r1-to-r3 to 10.220.12.2 via ge-1/1/0.0, label-switched-path r1-to-r3

user@router# run show route advertising-protocolbgp 192.168.11.0

inet.0: 101 destinations, 198 routes (100active, 0 holddown, 1 hidden)

Page 101: JNCIP-SP JN0-661 · PDF file · 2017-07-29You must ensure that r1's IPv4 loopback address exists in r3 ... redistribute the VPN routes into OSPF. Correct Answer: D ... this route

http://www.gratisexam.com/

Prefix Nexthop MED Lclpref AS path* 2.6.6.6/32 Self 2000 I

[edit protocols bgp] user@router# show

export reject; group peer { export as1000; neighbor 192.168.11.0 { family inet { unicast; } peer-as 1000; } } }

[edit policy-options] user@router# show

policy-statement as1000 { term 1 { from { route-filter 2.0.0.0/8 longer; } then accept; } term 2 { then reject; } } policy-statement reject { term 1 { from { route-filter 2.0.0.0/8 exact; } then reject } }

Page 102: JNCIP-SP JN0-661 · PDF file · 2017-07-29You must ensure that r1's IPv4 loopback address exists in r3 ... redistribute the VPN routes into OSPF. Correct Answer: D ... this route

http://www.gratisexam.com/

You want to advertise routes 2.0.0.0/8 and 2.6.6.6/32 to BGP peer 192.168.11.0.

Referring to the exhibit, which configuration change would satisfy this requirement?

A. Delete the as1000 export policy.

B. Change the as1000 policy to orlonger.

C. Delete the reject export policy.

D. Change the reject policy to longer.

Correct Answer: BSection: BGPExplanation

Explanation/Reference:We must change the match type from longer to orlonger in the as1000 policy. The match type Orlonger matches if the prefix-length is equal to or greater than theroute's prefix length, while the Longer match type only matches if the prefix-length is greater than the route's prefix length.

Reference: http://www.juniper.net/documentation/en_US/junos15.1/topics/example/policy-prefix-list.html

QUESTION 7Which statements are true about NG MVPNs? (Choose two.)

A. NG MVPN membership is signaled between PEs using PIM?

B. Every NG MVPN PE router builds a selective provider multicast service interface tunnel to every other router in the same NG MVPN

C. NG MVPN membership is signaled between PEs using MP-BGP.

D. Customer multicast traffic can be transported over the provider network using point-to-multipoint MPLS LSPs.

Correct Answer: BDSection: BGPExplanation

Explanation/Reference:Inter-AS MVPN Membership Discovery (Type 2 Routes), via BGP MCAST-VPN address family, are used for membership discovery between PE routers that belongto different autonomous systems (ASs).

The service provider uses RSVP-TE point-to-multipoint LSPs for transmitting VPN multicast data across the network.

Technology Overview, Understanding Junos OS Next-Generation Multicast VPN, pages 2, 8 https://www.juniper.net/techpubs/en_US/release-independent/nce/

Page 103: JNCIP-SP JN0-661 · PDF file · 2017-07-29You must ensure that r1's IPv4 loopback address exists in r3 ... redistribute the VPN routes into OSPF. Correct Answer: D ... this route

http://www.gratisexam.com/

information-products/topiccollections/nce/nce0090-ng-mvpn-understanding/ng-mvpn-understanding.pdf

QUESTION 8Which command will match communities 101:111, 111:1, and 999:1111?

A. set policy-options community COMMUNITY members ''^... :1?''

B. set policy-options community COMMUNITY members ''^1.*:1+''

C. set policy-options community COMMUNITY members [''^1.1:1?'' 999:1111]

D. set policy-options community COMMUNITY members ''^... :1+''

Correct Answer: DSection: BGPExplanation

Explanation/Reference:Period (.)—A wildcard character that matches any single digit in an AS number.+ stands for one or more repetitions of term.? stands for zero or one repetition of term.

References: http://www.juniper.net/documentation/en_US/junos15.1/topics/usage-guidelines/policy-defining-bgp-communities-and-extended-communities-for-use-in-routing-policy-match-conditions.html#id-10243437

QUESTION 9You are asked to implement route damping on a BGP router. There are two specific requirements for your implementation:

1. damp all prefixes with a mask length equal to or greater than /24 more aggressively than routes with a mask length between /17 and /23;

2. damp prefixes with a mask length between /0 and /16 less than routes with a mask length greater than /16.

Which policy configuration meets the requirement?

A. [edit policy-options] user@router# show policy-statement damping { term 1 { from { route-filter 0.0.0.0/0 prefix-length-range /0-/16 damping minor; route-filter 0.0.0.0/0 prefix-length-range /24-/32 damping major; } then accept }

Page 104: JNCIP-SP JN0-661 · PDF file · 2017-07-29You must ensure that r1's IPv4 loopback address exists in r3 ... redistribute the VPN routes into OSPF. Correct Answer: D ... this route

http://www.gratisexam.com/

} damping major { half-life 30; suppress 2500; } damping minor { half-life 5; }

B. [edit policy-options] user@router# show policy-statement damping { term 1 { from { route-filter 0.0.0.0/0 prefix-length-range /0-/23 damping minor; route-filter 0.0.0.0/0 prefix-length-range /24-/32 damping major; } then accept } } damping major { half-life 30; suppress 2500; } damping minor { half-life 5; }

C. [edit policy-options] user@router# show policy-statement damping { term 1 { from { route-filter 0.0.0.0/0 prefix-length-range /0-/23 damping minor; route-filter 0.0.0.0/0 prefix-length-range /24-/32 damping major; } then accept } } damping major { half-life 5; } damping minor { half-life 30; suppress 2500;

Page 105: JNCIP-SP JN0-661 · PDF file · 2017-07-29You must ensure that r1's IPv4 loopback address exists in r3 ... redistribute the VPN routes into OSPF. Correct Answer: D ... this route

http://www.gratisexam.com/

}

D. user@router# show policy-statement damping { term 1 { from { route-filter 0.0.0.0/0 prefix-length-range /0-/16 damping minor; route-filter 0.0.0.0/0 prefix-length-range /24-/32 damping major; } then accept } } damping major { half-life 5; } damping minor { half-life 5; suppress 2500; }

Correct Answer: ASection: BGPExplanation

Explanation/Reference:The default half-life is 15 minutes.

The default value of suppress is 3000.

To aggressively damp prefixes we should increase half-life, to for example 30 minutes, and to decrease the damp we should lower the half-life, to for example 5.

Incorrect Answers:B, C: The intervals in the route filter should be /0-/16 and /24-/32, not /0-/23 and /24-/32.D: We should increase half-life, not decrease it to 5.

Reference: http://www.juniper.net/documentation/en_US/junos16.1/topics/usage-guidelines/policy-usingrouting-policies-to-damp-bgp-route-flapping.html

QUESTION 10An MX Series router has received a BGP prefix from its peer. There are multiple destination routes to the BGP prefix with the default BGP route preference.

In this scenario, what is the first tie-breaker used to select the destination route?

Page 106: JNCIP-SP JN0-661 · PDF file · 2017-07-29You must ensure that r1's IPv4 loopback address exists in r3 ... redistribute the VPN routes into OSPF. Correct Answer: D ... this route

http://www.gratisexam.com/

http://www.gratisexam.com

A. lowest MED

B. shortest cluster list length

C. highest local preference

D. lowest origin code

Correct Answer: CSection: BGPExplanation

Explanation/Reference:Understanding BGP Path Selection

For each prefix in the routing table, the routing protocol process selects a single best path. After the best path is selected, the route is installed in the routing table.The best path becomes the active route if the same prefix is not learned by a protocol with a lower (more preferred) global preference value, also known as theadministrative distance. The algorithm for determining the active route is as follows:

1. Verify that the next hop can be resolved.2. Choose the path with the lowest preference value (routing protocol process preference).

Routes that are not eligible to be used for forwarding (for example, because they were rejected by routing policy or because a next hop is inaccessible) have apreference of 1 and are never chosen. etc.

3. Prefer the path with higher local preference.For non-BGP paths, choose the path with the lowest preference value etc.

Reference: https://www.juniper.net/documentation/en_US/junos12.3/topics/reference/general/routing-ptotocols-address-representation.html

QUESTION 11Click the Exhibit button.

Page 107: JNCIP-SP JN0-661 · PDF file · 2017-07-29You must ensure that r1's IPv4 loopback address exists in r3 ... redistribute the VPN routes into OSPF. Correct Answer: D ... this route

http://www.gratisexam.com/

AS 100 is originating and sending EBGP routes to AS 200. AS 200 is acting as a transit provider and sending those routers to AS 300. AS 200 is using theconfederation topology shown in the exhibit.

What will the AS path of AS 100's routes be when they are received on the AS 300 router?

A. 200 100

B. 200 (65200 65100) 100

C. (65200 65100) 100

D. ({65200 65100}) 100

Correct Answer: ASection: BGPExplanation

Explanation/Reference:To avoid routing loops, a sub-AS uses a confederation sequence, which operates like an AS path but uses only the privately assigned sub-AS numbers.

The following applies to BGP Confederations:

Page 108: JNCIP-SP JN0-661 · PDF file · 2017-07-29You must ensure that r1's IPv4 loopback address exists in r3 ... redistribute the VPN routes into OSPF. Correct Answer: D ... this route

http://www.gratisexam.com/

Reference: https://jncie.files.wordpress.com/2008/09/350010_differences-between-bgp-route-reflectors-andconfederations.pdf

QUESTION 12Click the Exhibit button.

Both autonomous systems shown in the exhibit use BGP with a full-mesh

IBGP configuration within each autonomous system and EBGP between the two autonomous systems. A single route is generated on R1 and advertised into BGP.

Which two statements are true in this scenario? (Choose two.)

Page 109: JNCIP-SP JN0-661 · PDF file · 2017-07-29You must ensure that r1's IPv4 loopback address exists in r3 ... redistribute the VPN routes into OSPF. Correct Answer: D ... this route

http://www.gratisexam.com/

A. R4 will not automatically readvertise the route to R5.

B. R5 will automatically readvertise the route to other routers in AS 65512.

C. R5 will not automatically readvertise the route to other routers in AS 65512.

D. R4 will automatically readvertise the route to R5.

Correct Answer: BDSection: BGPExplanation

Explanation/Reference:In general, deployed BGP implementations do not advertise the external route with the highest local preference value to internal peers unless it is the best route.

QUESTION 13Click the Exhibit button.

Referring to the exhibit, you control AS 24652. You are asked to ensure that traffic destined to the 23.56.83.0/24 network from ISP 4 takes the most optimum paththrough ISP 3. ISP 1 should be used as a backup for this traffic flow.

Which two actions would accomplish this task? (Choose two.)

Page 110: JNCIP-SP JN0-661 · PDF file · 2017-07-29You must ensure that r1's IPv4 loopback address exists in r3 ... redistribute the VPN routes into OSPF. Correct Answer: D ... this route

http://www.gratisexam.com/

A. Set a higher local preference for the route advertised by ISP 3.

B. Advertise a longer AS path from R2 to ISP 4.

C. Set a lower local preference for the route advertised by ISP 3.

D. Advertise a longer AS path from R1 to ISP4.

Correct Answer: ADSection: BGPExplanation

Explanation/Reference:A: Internal BGP (IBGP) sessions use a metric called the local preference, which is carried in IBGP update packets in the path attribute LOCAL_PREF. When an autonomous system (AS) has multiple routes to another AS, the local preference indicates the degree of preference for one route over the other routes. The route with the highest local preference value is preferred.

D: BGP does not take bandwidth into consideration when determining the best path. By using AS path prepending, you can lengthen the AS path that routing devices advertise to neighbors to make the neighbors calculate the path to be longer than it actually is.

Reference:

https://www.juniper.net/documentation/en_US/junos15.1/topics/topic-map/bgp-local-preference.html

http://www.juniper.net/documentation/en_US/junos15.1/topics/example/routing-policy-security-routing-policy-to-prepend-to-as-path-configuring.html

QUESTION 14In a carrier-of-carrier VPN model, which type of network layer reachability information is used for the MP- BGP signaling between CE and PE routers?

A. inet-vpn

B. flow

C. labeled-unicast

D. unicast

Correct Answer: ASection: BGPExplanation

Explanation/Reference:In a Carrier-of-Carrier VPN environment, specify the inet-vpn address family and unicast traffic type to enable BGP to carry IPv4 network layer reachabilityinformation (NLRI) for VPN routes.

Page 111: JNCIP-SP JN0-661 · PDF file · 2017-07-29You must ensure that r1's IPv4 loopback address exists in r3 ... redistribute the VPN routes into OSPF. Correct Answer: D ... this route

http://www.gratisexam.com/

Reference: http://www.juniper.net/documentation/en_US/junos15.1/topics/example/mpls-vpn-option2-configuration.html

QUESTION 15R1:

interfaces { ge-0/0/1 { unit 1 { family inet { address 172.16.1.1/24; } family inet6 { address 2000:FEFE:89::1/64; address ::FEFE:172.16.1.1/120; } } }}protocols { bgp { group IPv6overIPv4 { type external; family inet6 { unicast; peer-as 2; neighbor 172.16.1.2; } }}

R2:

interfaces { ge-0/0/1 { unit 1 { family inet { address 172.16.1.2/24; } family inet6 { }

Page 112: JNCIP-SP JN0-661 · PDF file · 2017-07-29You must ensure that r1's IPv4 loopback address exists in r3 ... redistribute the VPN routes into OSPF. Correct Answer: D ... this route

http://www.gratisexam.com/

}}protocols { bgp { group IPv6overIPv4 { type external; family inet6 { unicast; peer-as 1; neighbor 172.16.1.1; } }}

R1 is exporting 2000:FEFE:100::/64 to R2 over the EBGP peering session as shown in the exhibit. What will R1 use for this route's protocol next hop whenadvertising it to R2?

Click the Exhibit button.

Exhibit:

A. 2000:FEFE:89::1

B. 172.16.1.1

C. 10.1.1.1

D. ::FFFF:172:16:1:1

Correct Answer: DSection: BGPExplanation

Explanation/Reference:When a BGP router reports itself as the next hop, whether because of an explicit neighbor nexthop-self configuration or implicitly as a result of participating in an EBGP session, BGP allocates

a new in label and adds an entry to the MPLS forwarding table, creating a label-to-next-hop mapping.

Note: When a BGP router does not report itself as the next hop, whether because of an explicit neighbor next-hop-unchanged configuration or implicitly as a result of a participating in an IBGP session, BGP does not allocate a new in label. Instead, if the route is advertised as a labeled route, BGP uses the existing out label. This feature is used mainly on route reflectors.

Page 113: JNCIP-SP JN0-661 · PDF file · 2017-07-29You must ensure that r1's IPv4 loopback address exists in r3 ... redistribute the VPN routes into OSPF. Correct Answer: D ... this route

http://www.gratisexam.com/

Reference: https://www.juniper.net/techpubs/en_US/junose16.1/topics/concept/mbgp-bgp-next-hop-self-overview.html

QUESTION 16Click the Exhibit button.

Referring to the exhibit, what are three operations performed by the service provider's PE routers? (Choose three.)

A. Modify the VRF label assigned using MP-BGP.

B. Maintain the customer's /32 loopback internal routes.

C. Use MP-EBGP to send Customer Site 2's internal routes to CE-1.

D. Maintain the customer's external routes.

E. Maintain routes internal to the provider's network.

Correct Answer: BCESection: BGPExplanation

Explanation/Reference:

QUESTION 17Click the Exhibit button.

Page 114: JNCIP-SP JN0-661 · PDF file · 2017-07-29You must ensure that r1's IPv4 loopback address exists in r3 ... redistribute the VPN routes into OSPF. Correct Answer: D ... this route

http://www.gratisexam.com/

Which configuration parameter would create a routing table as shown in the exhibit?

A. routing-options forwarding-table export load-balance-policy

B. multipath

C. protocols bgp export load-balance-policy

D. multihop

Correct Answer: BSection: BGPExplanation

Explanation/Reference:

QUESTION 18

Page 115: JNCIP-SP JN0-661 · PDF file · 2017-07-29You must ensure that r1's IPv4 loopback address exists in r3 ... redistribute the VPN routes into OSPF. Correct Answer: D ... this route

http://www.gratisexam.com/

Click the Exhibit button.

You are the administrator for AS 1111 and you want to inform the neighboring AS to use router A2 as the ingress path into your local AS.

Referring to the exhibit, which policy statement action for the export policy on A2 will perform this task?

A. set policy-options policy-statement export term 10 then metric 120

B. set policy-options policy-statement export term 10 then external

C. set policy-options policy-statement export term 10 then metric 25

D. set policy-options policy-statement export term 10 then priority low

Correct Answer: CSection: BGPExplanation

Explanation/Reference:

QUESTION 19Click the Exhibit button.

Page 116: JNCIP-SP JN0-661 · PDF file · 2017-07-29You must ensure that r1's IPv4 loopback address exists in r3 ... redistribute the VPN routes into OSPF. Correct Answer: D ... this route

http://www.gratisexam.com/

The Client 1 router forwards a route learned from its EBGP peer to the route reflector RR1. The route reflector forwards the route to the Client 2 router. However,the Client 2 router uses suboptimal routing to reach the EBGP route destination.

What would cause this behavior?

A. The route reflector becomes the default forwarding path for packets sent from Client 2 towards the EBGP route destination.

B. The route reflector is using the no-client-reflect parameter.

C. The route reflector has a next-hop self policy for EBGP-learned routes.

D. The route reflector is applying the originator ID attribute to the route.

Correct Answer: CSection: BGPExplanation

Explanation/Reference:

QUESTION 20Click the Exhibit button

Page 117: JNCIP-SP JN0-661 · PDF file · 2017-07-29You must ensure that r1's IPv4 loopback address exists in r3 ... redistribute the VPN routes into OSPF. Correct Answer: D ... this route

http://www.gratisexam.com/

Referring to the exhibit, routers R1 through R5 exist in a fully-meshed IBGP group. You want the

routes received through EBGP on R1 to be advertised to the EBGP peer connected to R5. You want the routes received through EBGP on R5 to be installed on R1;however, you do not want the those routes to be advertised to the EBGP peer connected to R1.

Which two actions will accomplish this task? (Choose two.)

A. Implement an export policy on R5 to add the well-known no-export community to the EBGP routes.

B. Implement an export policy on R5 to add the well-known no-advertise community to the EBGP routes.

C. Implement a route reflector group and configure the no-client-reflect parameter on the route reflector.

D. Implement an import policy on R1 to add the well-known no-export community to the EBGP routes.

Correct Answer: ABSection: BGPExplanation

Explanation/Reference:

QUESTION 21Click the Exhibit button.

Page 118: JNCIP-SP JN0-661 · PDF file · 2017-07-29You must ensure that r1's IPv4 loopback address exists in r3 ... redistribute the VPN routes into OSPF. Correct Answer: D ... this route

http://www.gratisexam.com/

Referring to the exhibit, you must advertise the 200.100.0.0/16 routes from Site 2 to Site 1, but R3

is not currently advertising any BGP routes to R2.

Why is this happening?

A. The IBGP routes are not active and EBGP will advertise only active routes.

B. The IBGP routes are not active because the next hop is not reachable.

C. The IBGP routes will not be advertised because the AS path shows incomplete.

D. The IBGP routes will not be advertised because you must use a policy to advertise IBGP routes.

Correct Answer: ASection: BGPExplanation

Explanation/Reference:

QUESTION 22Click the Exhibit button.

Page 119: JNCIP-SP JN0-661 · PDF file · 2017-07-29You must ensure that r1's IPv4 loopback address exists in r3 ... redistribute the VPN routes into OSPF. Correct Answer: D ... this route

http://www.gratisexam.com/

You administer the network shown in the exhibit. Routers R1, R3, and R4 are sending the same prefix to R2. All routers are using default local-preference values.You must make the prefix from R4 the most preferred.

Which two actions accomplish the task? (Choose two.)

http://www.gratisexam.com

A. Configure as-path-prepend on R1 and R3.

B. Configure local-preference 10 on R4.

C. Configure router-id 4.4.4.4 on R4.

D. Configure always-compare-med on R2.

Correct Answer: ADSection: BGPExplanation

Explanation/Reference:

QUESTION 23How would you copy the BGP prefix 192.168.42.0/24 from VRF-A.inet.0 to VRF-B.inet.0?

Page 120: JNCIP-SP JN0-661 · PDF file · 2017-07-29You must ensure that r1's IPv4 loopback address exists in r3 ... redistribute the VPN routes into OSPF. Correct Answer: D ... this route

http://www.gratisexam.com/

A. Use a VRF import policy on the destination VRF to match the desired prefix.

B. Use an import policy on the BGP neighbor configured with family inet-vpn to add a target community that VRF-B imports.

C. Use a VRF export policy in VRF-A to copy the route from the source VRF to the destination VRF.

D. Use a RIB group policy to copy the route from the bgp.l3vpn.0 table to the VRF-B.inet.0 table.

Correct Answer: BSection: BGPExplanation

Explanation/Reference:

QUESTION 24You are asked to provide redundancy to avoid a single point of failure for your route reflector cluster groups.

Which action will accomplish this task?

A. Configure unique cluster IDs for each client within a route reflector cluster group.

B. Configure two route reflectors for each route reflector cluster group.

C. Configure a full IBGP peer mesh between clients within the route reflector cluster group.

D. Configure the no-client-reflect parameter on the route reflector.

Correct Answer: BSection: BGPExplanation

Explanation/Reference:

QUESTION 25Refer to the exhibit.

user@router# show routing-instancesVRF { instance-type vrf; interface fe-1/2/3.0; route-distinguisher 65535:1; vrf-target target:65535:1;}

Page 121: JNCIP-SP JN0-661 · PDF file · 2017-07-29You must ensure that r1's IPv4 loopback address exists in r3 ... redistribute the VPN routes into OSPF. Correct Answer: D ... this route

http://www.gratisexam.com/

user@router# run show route advertising-protocol bgp 4.4.4.4 extensiveVRF.inet.0: 4 destinations, 4 routes (4 active, 0 holddown, 0 hidden)* 172.16.1.0/30 (1 entry, 1 announced)BGP group RR type Internal Route Distinguisher: 65535:1 BGP label allocation failure: Need a nexthop address on LAN Nexthop: Not advertised Flags: Nexthop Change Localpref: 100 AS path: I Communities: target: 65535:1

What are two ways to resolve the error BGP label allocation failure: Need a next hop address on LAN? (Choose two.)

A. Configure a /32 static route with the next hop as itself to any remote address on the network assigned to the CE-facing interface.

B. Resolve the MPLS issue between the PE routers.

C. Configure a static ARP entry on fe-l/#3.0.

D. Configure vrf-table-label in the routing-instance.

Correct Answer: ADSection: BGPExplanation

Explanation/Reference:

QUESTION 26Refer to the exhibit.

[edit]user@router# show protocols bgptraceoptions { file bgptrace files 5 world-readable flag bfd;}log-updown;group internal-peers { type internal; local-address 192.168.6.5; export send-direct; neighbor 192.163.6.4;

Page 122: JNCIP-SP JN0-661 · PDF file · 2017-07-29You must ensure that r1's IPv4 loopback address exists in r3 ... redistribute the VPN routes into OSPF. Correct Answer: D ... this route

http://www.gratisexam.com/

neighbor 192.168.40.4;}

[edit]user@router# show policy-optionspolicy-statement send-direct { term 2 { from protocol direct; then accept; }}

[edit]user@router# show routing-optionsbmp { station-address 192.168.44.100 station-port 12666;}router-id 192.168.6.5;autonomous-system;

Your network engineer reported that they lost BGP connectivity to the neighbor 192.163.6.4 one hour ago, for five to ten minutes.

What are two ways to determine what happened? (Choose two.)

A. Run the show bgp neighbor orf 192.163.6.4 detail command.

B. View the information on the BGP monitoring station at 192.168.44.100.

C. Run the show log bgptrace command and search for the time of the lost connectivity.

D. Run the show log messages command and search for the time of the lost connectivity.

Correct Answer: BDSection: BGPExplanation

Explanation/Reference:The BGP Monitoring Protocol (BMP) is a protocol to allow a monitoring station to receive routes from a BGP-enabled device. The monitoring station receives allroutes, not just the active routes. BMP uses route monitoring messages (which are essentially encapsulated BGP update messages) and a few other messagetypes for statistics and state changes. All messages flow from the router to the monitoring station.

The data is collected from the Adjacency-RIB-In routing tables. The Adjacency-RIB-In tables are the pre-policy tables, meaning that the routes in these tables havenot been filtered or modified by routing policies.

Page 123: JNCIP-SP JN0-661 · PDF file · 2017-07-29You must ensure that r1's IPv4 loopback address exists in r3 ... redistribute the VPN routes into OSPF. Correct Answer: D ... this route

http://www.gratisexam.com/

https://www.juniper.net/documentation/en_US/junos13.3/topics/topic-map/bgp-monitoring-protocol.html

QUESTION 27Which action is required for BGP confederations to function?

A. Remove the well-known private AS numbers.

B. Change the maximum number of times an AS can be in an AS path.

C. Replace the neighbor AS number with the local AS number.

D. Set the confederation autonomous system to include private AS number(s).

Correct Answer: DSection: BGPExplanation

Explanation/Reference:

QUESTION 28Given the following regular expression:

.* 14203+(21870110458)

Which two AS paths match? (Choose two.)

A. 27522 2187010458

B. 27522 14203 14203 14203 21870

C. 14203 21780 10458

D. 14203 21780 27522

Correct Answer: BCSection: BGPExplanation

Explanation/Reference:

QUESTION 29Given the following regular expression:

Page 124: JNCIP-SP JN0-661 · PDF file · 2017-07-29You must ensure that r1's IPv4 loopback address exists in r3 ... redistribute the VPN routes into OSPF. Correct Answer: D ... this route

http://www.gratisexam.com/

(14203121870)

Which two AS paths will match? (Choose two.)

A. 1045814203

B. 21870

C. 10458 21870 21870

D. 27522 14203 21870

Correct Answer: ABSection: BGPExplanation

Explanation/Reference:

QUESTION 30Refer to the exhibit.

Page 125: JNCIP-SP JN0-661 · PDF file · 2017-07-29You must ensure that r1's IPv4 loopback address exists in r3 ... redistribute the VPN routes into OSPF. Correct Answer: D ... this route

http://www.gratisexam.com/

You are implementing a Layer 3 VPN between Site 1 and Site 2. You notice that you are not sharing routes between PE1 and PE2. You have verified that MPLS andRSVP are functioning correctly. Referring to the exhibit, what is causing the problem?

A. The multihop feature is not enabled.

B. The next hop for the VPN routes is unusable.

C. The Layer 3 VPN NLRI has not been enabled on PE1.

D. The PE2 BGP session is restarting.

Correct Answer: CSection: BGP

Page 126: JNCIP-SP JN0-661 · PDF file · 2017-07-29You must ensure that r1's IPv4 loopback address exists in r3 ... redistribute the VPN routes into OSPF. Correct Answer: D ... this route

http://www.gratisexam.com/

Explanation

Explanation/Reference:

QUESTION 31You are asked to set up a route reflection cluster for a group of IBGP peers that are fully meshed. You want to only reflect routes that arrive outside the cluster to theIBGP peers.

Which route reflector configuration accomplishes this task?

A. [edit protocols bgp]user@router# showgroup int-peers { type internal; local-address 172.16.1.1; cluster 172.16.1.1; advertise-external; neighbor 172.16.2.2; neighbor 172.16.3.3;}

B. [edit protocols bgp]user@router# showgroup int-peers { type internal; local-address 172.16.1.1; cluster 172.16.1.1; export next-hop-self; neighbor 172.16.2.2; neighbor 172.16.3.3;}

C. [edit protocols bgp]user@router# showgroup int-peers { type internal; local-address 172.16.1.1; cluster 172.16.1.1; no-client-reflect; neighbor 172.16.2.2; neighbor 172.16.3.3;}

Page 127: JNCIP-SP JN0-661 · PDF file · 2017-07-29You must ensure that r1's IPv4 loopback address exists in r3 ... redistribute the VPN routes into OSPF. Correct Answer: D ... this route

http://www.gratisexam.com/

D. [edit protocols bgp]user@router# showgroup int-peers { type internal; local-address 172.16.1.1; cluster 172.16.1.1; damping; neighbor 172.16.2.2; neighbor 172.16.3.3;}

Correct Answer: CSection: BGPExplanation

Explanation/Reference:

QUESTION 32Refer to the exhibit.

[edit routing-options]user@router# showautonomous-system 1;

[edit protocols]user@router# showbgp { group peer-AS2 { type external; export policy-1; peer-as 2; neighbor 10.10.10.2; }}

[edit policy-options]user@router# showpolicy-statement policy-1 {then as-path-repend "1 1 1 1"}

Page 128: JNCIP-SP JN0-661 · PDF file · 2017-07-29You must ensure that r1's IPv4 loopback address exists in r3 ... redistribute the VPN routes into OSPF. Correct Answer: D ... this route

http://www.gratisexam.com/

What is the expected result based on the configuration shown in the exhibit?

A. To discourage IBGP routers from using the path through 10.10.10.2

B. To encourage IBGP routers to use the path through 10.10.10.2

C. To discourage EBGP routers from using the path through 10.10.10.2

D. To encourage EBGP routers to use the path through 10.10.10.2

Correct Answer: CSection: BGPExplanation

Explanation/Reference:

QUESTION 33Which set of BGP attribute values is most preferred by the Junos OS?

A. Origin?Local Preference 1AS Path 20 10 3 2 1

B. Origin ILocal Preference 100AS Path 10 3 2 1

C. Origin ILocal Preference 1AS Path 20 10 3 2 1

D. Origin ELocal Preference 100AS Path 10 3 2 1

Correct Answer: BSection: BGPExplanation

Explanation/Reference:

QUESTION 34How does a router use BGP to deflect a distributed denial-of-service attack against a prefix at all edge routers in the same AS?

Page 129: JNCIP-SP JN0-661 · PDF file · 2017-07-29You must ensure that r1's IPv4 loopback address exists in r3 ... redistribute the VPN routes into OSPF. Correct Answer: D ... this route

http://www.gratisexam.com/

http://www.gratisexam.com

A. It advertises the prefix with a local preference that is higher than any other node, and sets the next hop to a unicast route that has a discard next hop.

B. It advertises the prefix with a local preference that is higher than any other node and sets the next hop to self.

C. It advertises the prefix with a local preference that is lower than any other node and sets the next hop to a unicast route that has a discard next hop.

D. It advertises the prefix with a local preference that is lower than any other node and sets the next hop to self.

Correct Answer: ASection: BGPExplanation

Explanation/Reference:

QUESTION 35You are hired at an ISP and your new employer asks you to become familiar with the routing policy. The 42+.*[21112]$ regular expression is in one of the policies.Which three AS paths match the regex statement? (Choose three.)

A. 42 42 42 42 6

B. 42 42 42 27 21

C. 42 42 42 42 12

D. 42 69 2112 112

E. 42 69 212112

Correct Answer: BCESection: BGPExplanation

Explanation/Reference:

QUESTION 36Which neighbor state indicates that two BGP neighbors have full connectivity?

Page 130: JNCIP-SP JN0-661 · PDF file · 2017-07-29You must ensure that r1's IPv4 loopback address exists in r3 ... redistribute the VPN routes into OSPF. Correct Answer: D ... this route

http://www.gratisexam.com/

A. Idle

B. Connect

C. Open Confirm

D. Established

Correct Answer: DSection: BGPExplanation

Explanation/Reference:

QUESTION 37Your router is receiving four BGP route advertisements for the 192.168.100.0/24 network. By default, which route becomes active?

A. Route A, which is learned through EBGP with an AS path of 8001 and a MED of 175.

B. Route B, which is learned through IBGP with an AS path of 9900, a MED of 150, and an IGP cost of 15.

C. Route C, which is learned through IBGP with an AS path of 8001, a MED of 100, and an IGP cost of 10

D. Route D, which is learned through EBGP with an AS path of 9900 and a MED of 200.

Correct Answer: CSection: BGPExplanation

Explanation/Reference:

QUESTION 38You are trying to establish an EBGP peering with a neighbor that is not in the same subnet.

What configuration parameter, when accompanied with a supporting import policy, can you use to resolve the issue and maintain multipath functionality?

A. multihop

B. accept-remote-nexthop

C. multipath

D. include-mp-next-hop

Correct Answer: BSection: BGP

Page 131: JNCIP-SP JN0-661 · PDF file · 2017-07-29You must ensure that r1's IPv4 loopback address exists in r3 ... redistribute the VPN routes into OSPF. Correct Answer: D ... this route

http://www.gratisexam.com/

Explanation

Explanation/Reference:

QUESTION 39Click the Exhibit button.

R3 is announcing a route to R4 using EBGP, as shown in the exhibit. All routers in AS 65221 should learn this route, but it should not be announced to any other AS.What can be done to enforce this behavior?

A. R3 should add the community no-export to the route prior to announcing it.

B. R3 should add the community no-advertise to the route prior to announcing it.

C. R4 should add the community no-announce after receiving the route.

D. R4 should add the community no-advertise after receiving the route.

Correct Answer: ASection: BGPExplanation

Explanation/Reference:

Page 132: JNCIP-SP JN0-661 · PDF file · 2017-07-29You must ensure that r1's IPv4 loopback address exists in r3 ... redistribute the VPN routes into OSPF. Correct Answer: D ... this route

http://www.gratisexam.com/

QUESTION 40Click the Exhibit button.

A route is advertised from AS 65221 to AS 65432 using EBGP. The route is active and reachable on R3, but does not appear as an active route on R1 and R2. R3has an export policy applied to its IBGP group matching on routes from R4, but does not have a then criteria specified. Which policy action should router R3configure to make this route visible on routers R1 and R2?

A. then next-hop self

B. then accept

C. then announce

D. then resolve-recursive

Correct Answer: ASection: BGPExplanation

Explanation/Reference:

QUESTION 41Click the Exhibit button.

Page 133: JNCIP-SP JN0-661 · PDF file · 2017-07-29You must ensure that r1's IPv4 loopback address exists in r3 ... redistribute the VPN routes into OSPF. Correct Answer: D ... this route

http://www.gratisexam.com/

You work for ISP A, as shown in the exhibit, and must configure R1 to use load balancing across both available links for all routes to ISP B's network. You start byconfiguring this policy:

policy-statement load-balance { then { load-balance per-packet; }}

Which two commands do you use to finish the configuration? (Choose two.)

A. set protocols bgp group isp-b multihop

B. set routing-options forwarding-table export load-balance

C. set routing-options forwarding-table import load-balance

D. set protocols bgp group isp-b multipath

Correct Answer: BDSection: BGPExplanation

Explanation/Reference:

Page 134: JNCIP-SP JN0-661 · PDF file · 2017-07-29You must ensure that r1's IPv4 loopback address exists in r3 ... redistribute the VPN routes into OSPF. Correct Answer: D ... this route

http://www.gratisexam.com/

QUESTION 42Click the Exhibit button.

What is the significance of RIB groups, as shown in the exhibit?

A. RIB groups alter the multicast RPF check table to inet.0.

B. RIB groups alter the multicast RPF check table to inet.2.

C. RIB groups alter the multicast RPF check table to inet.4.

D. RIB groups alter the multicast RPF check table to inet.3.

Correct Answer: BSection: BGPExplanation

Explanation/Reference:

QUESTION 43Click the Exhibit button.

Page 135: JNCIP-SP JN0-661 · PDF file · 2017-07-29You must ensure that r1's IPv4 loopback address exists in r3 ... redistribute the VPN routes into OSPF. Correct Answer: D ... this route

http://www.gratisexam.com/

Customer A is complaining that routes advertised from the CE2 router are not being received on the CE1 router. The physical topology of the network is CE1-PE1-PE2-CE2. The CE1-PE1 subnet is 172.16.1.0/24. The CE2-PE2 subnet is 172.16.2.0/24. PE1's loopback is 192.168.3.1 and PE2's loopback is192.168.4.1.Referring to the output in the exhibit, what is the problem?

A. No LSP exists between PE1 and PE2.

Page 136: JNCIP-SP JN0-661 · PDF file · 2017-07-29You must ensure that r1's IPv4 loopback address exists in r3 ... redistribute the VPN routes into OSPF. Correct Answer: D ... this route

http://www.gratisexam.com/

B. Route targets are not properly configured.

C. as-override is not configured in the VRFs.

D. family inet-vpn is not configured on the PEs.

Correct Answer: CSection: BGPExplanation

Explanation/Reference:

QUESTION 44Click the Exhibit button.

Your employer is ISP A. Your customers must be able to reach customers of both ISP B and ISP C, but your network must not allow transit traffic between ISP Band ISP C at any time. Referring to the exhibit, what are two solutions? (Choose two.)

A. Use policy to filter routes on AS number.

Page 137: JNCIP-SP JN0-661 · PDF file · 2017-07-29You must ensure that r1's IPv4 loopback address exists in r3 ... redistribute the VPN routes into OSPF. Correct Answer: D ... this route

http://www.gratisexam.com/

B. Use the well-known no-export community.

C. Use the MED to prefer the proper routes.

D. Use communities to identify and filter routes.

Correct Answer: ADSection: BGPExplanation

Explanation/Reference:

QUESTION 45Click the Exhibit button.

The exhibit contains a sample trace file of a BGP update message. Which two statements are true? (Choose two.)

A. 10.10.56.0/30 is a route internal to the AS.

B. The router that sent this update is the BGP originator of 10.10.56.0/30.

C. The BGP session is EBGP.

D. The local preference has been changed from the default settings.

Correct Answer: ABSection: BGPExplanation

Explanation/Reference:

Page 138: JNCIP-SP JN0-661 · PDF file · 2017-07-29You must ensure that r1's IPv4 loopback address exists in r3 ... redistribute the VPN routes into OSPF. Correct Answer: D ... this route

http://www.gratisexam.com/

QUESTION 46Which three statements are true about the BGP community attribute? (Choose three.)

A. There are three well-known communities.

B. Communities can be used to signal local preference in other AS networks.

C. Only well-known communities can be passed between AS networks.

D. Routing policies can be simplified using BGP communities.

E. Communities are used in the route selection process.

Correct Answer: ABDSection: BGPExplanation

Explanation/Reference:

QUESTION 47Click the Exhibit button.

Page 139: JNCIP-SP JN0-661 · PDF file · 2017-07-29You must ensure that r1's IPv4 loopback address exists in r3 ... redistribute the VPN routes into OSPF. Correct Answer: D ... this route

http://www.gratisexam.com/

All ISP networks shown in the exhibit contain many BGP speaking routers. You are in charge of ISP A. You must ensure that customer Y sends their traffic to youover the directly connected link but customer Y is not used for transit into your network. What do you do to accomplish this?

A. Advertise routes to customer Y with a higher MED than routes advertised to customer X.

B. Advertise routes to customer Y with the well-known no-advertise community.

C. Advertise routes to customer Y with your AS number prepended four times.

D. Advertise routes to customer Y with the well-known no-export community.

Correct Answer: DSection: BGPExplanation

Explanation/Reference:

QUESTION 48Click the Exhibit button.

You are building an inter-provider VPN with ISP2 to support end-to-end connectivity for Customer A, as shown in the exhibit. For scalability reasons, the ASBRrouters cannot exchange VPN routes for Customer A. Which two configurations are needed to support this requirement? (Choose two.)

A. family inet-vpn on the ASBRs

B. labeled-unicast on the ASBRs

C. multihop EBGP between the PEs

D. one VRF on the ASBRs for Customer A

Correct Answer: BCSection: BGPExplanation

Page 140: JNCIP-SP JN0-661 · PDF file · 2017-07-29You must ensure that r1's IPv4 loopback address exists in r3 ... redistribute the VPN routes into OSPF. Correct Answer: D ... this route

http://www.gratisexam.com/

Explanation/Reference:

QUESTION 49Click the Exhibit button.

Referring to the exhibit, you work for ISP A and are asked to configure R1 to forward traffic for all routes across both available links, to both routers in ISP B'snetwork. Which three configuration commands do you use? (Choose three.)

A. set protocols bgp group isp-b multihop

B. set policy-options policy-statement load-balance then load-balance per-packet

C. set routing-options forwarding-table import load-balance

D. set protocols bgp group isp-b multipath

E. set routing-options forwarding-table export load-balance

Correct Answer: BDESection: BGPExplanation

Explanation/Reference:

Page 141: JNCIP-SP JN0-661 · PDF file · 2017-07-29You must ensure that r1's IPv4 loopback address exists in r3 ... redistribute the VPN routes into OSPF. Correct Answer: D ... this route

http://www.gratisexam.com/

QUESTION 50You are evaluating a routing policy for an ISP and you find the ^42+ .* (23|9)$ regular expression. Which three AS paths match the regular expression? (Choosethree.)

http://www.gratisexam.com

A. 42 42 42 42 9

B. 42 42 23 500

C. 42 42 42 60 9

D. 42 60 23 9 42

E. 42 69 500 23

Correct Answer: ACESection: BGPExplanation

Explanation/Reference:

QUESTION 51Click the Exhibit button.

Page 142: JNCIP-SP JN0-661 · PDF file · 2017-07-29You must ensure that r1's IPv4 loopback address exists in r3 ... redistribute the VPN routes into OSPF. Correct Answer: D ... this route

http://www.gratisexam.com/

R3 and R4 want to establish an EBGP session between each other's loopback addresses. Static routes have been configured for the loopback addresses and youcan ping from loopback to loopback. Their EBGP sessions are configured with multihop to allow for additional hops. The correct AS numbers have been specified atthe [routing-options] hierarchy as well. Considering the topology in the exhibit, which statement is true?

A. BGP's protocol preference must be adjusted to be lower than protocol static for the session to establish.

B. Each peer must configure a local-address of their own loopback for the session to establish.

C. Each peer must specify a local-as within their EBGP configuration for the session to establish.

D. Each peer must configure multipath for the session to establish.

Correct Answer: BSection: BGPExplanation

Explanation/Reference:

QUESTION 52Click the Exhibit button.

Page 143: JNCIP-SP JN0-661 · PDF file · 2017-07-29You must ensure that r1's IPv4 loopback address exists in r3 ... redistribute the VPN routes into OSPF. Correct Answer: D ... this route

http://www.gratisexam.com/

You are the administrator of AS 65000. There are four links between your network (AS 65000) and your upstream provider (AS 65001). You have an import policyon all of your routers. The routing table on the customer router has four routes to the Web server as follows:

Router A. Local Pref 110, IGP Cost 1000Router B. Local Pref 100, IGP Cost 200Router C. Local Pref 110, IGP Cost 900Router D. Local Pref 100, IGP Cost 1000

Through which link will traffic to the Web server leave your network (AS 65000) from the customer router?

A. Router A

B. Router B

C. Router C

D. Router D

Correct Answer: CSection: BGP

Page 144: JNCIP-SP JN0-661 · PDF file · 2017-07-29You must ensure that r1's IPv4 loopback address exists in r3 ... redistribute the VPN routes into OSPF. Correct Answer: D ... this route

http://www.gratisexam.com/

Explanation

Explanation/Reference:

QUESTION 53Click the Exhibit button.

You are an employee of ISP A. You must not allow traffic between ISP B and ISP C to cross your network, but customers of ISP B and ISP C must be able to reachyour customers. Referring to the exhibit, which two actions would do this? (Choose two.)

A. Use communities to identify and filter routes.

B. Use policy to filter routes on AS number.

C. Use origin code to identify and filter routes.

D. Use the well-known no-advertise community.

Correct Answer: ADSection: BGPExplanation

Page 145: JNCIP-SP JN0-661 · PDF file · 2017-07-29You must ensure that r1's IPv4 loopback address exists in r3 ... redistribute the VPN routes into OSPF. Correct Answer: D ... this route

http://www.gratisexam.com/

Explanation/Reference:

QUESTION 54Click the Exhibit button.

The routers shown in the exhibit are connected in a full BGP mesh. R1 is the route reflector and R2 through R5 are clients. R3 should only receive one copy of allroutes sent from R4.Which configuration is valid?

A. [edit protocols bgp]root@R2# showgroup AS65420 { type internal; local-address 2001:db8:fac1::a2; cluster 10.1.1.1; neighbor 2001:db8:fac1::a1; neighbor 2001:db8:fac1::a3; neighbor 2001:db8:fac1::a4; neighbor 2001:db8:fac1::a5;}

Page 146: JNCIP-SP JN0-661 · PDF file · 2017-07-29You must ensure that r1's IPv4 loopback address exists in r3 ... redistribute the VPN routes into OSPF. Correct Answer: D ... this route

http://www.gratisexam.com/

B. [edit protocols bgp]root@R2# showgroup AS65420 { type internal; local-address 2001:db8:fac1::a2; no-client-reflect; neighbor 2001:db8:fac1::a1; neighbor 2001:db8:fac1::a3; neighbor 2001:db8:fac1::a4; neighbor 2001:db8:fac1::a5;}

C. [edit protocols bgp]root@R2# showgroup AS65420 { type internal; local-address 2001:db8:fac1::a2; cluster 10.1.1.1; no-client-reflect; neighbor 2001:db8:fac1::a1; neighbor 2001:db8:fac1::a3; neighbor 2001:db8:fac1::a4; neighbor 2001:db8:fac1::a5;}

D. [edit protocols bgp]root@R2# showgroup AS65420 { type internal; local-address 2001:db8:fac1::a1; no-client-reflect; neighbor 2001:db8:fac1::a2; neighbor 2001:db8:fac1::a3; neighbor 2001:db8:fac1::a4; neighbor 2001:db8:fac1::a5;}

Correct Answer: CSection: BGPExplanation

Explanation/Reference:

Page 147: JNCIP-SP JN0-661 · PDF file · 2017-07-29You must ensure that r1's IPv4 loopback address exists in r3 ... redistribute the VPN routes into OSPF. Correct Answer: D ... this route

http://www.gratisexam.com/

QUESTION 55What does the Junos command advertise-inactive allow?

A. OSPF inactive routes to be advertised using BGP

B. inactive and hidden BGP routes to be redistributed into OSPF

C. the best BGP route to be re-advertised by BGP, even when it is not the best route

D. the second-best BGP route to be re-advertised by BGP, to back up the best BGP route

Correct Answer: CSection: BGPExplanation

Explanation/Reference:

QUESTION 56Click the Exhibit button.

Customer A is complaining that routes advertised from the CE2 router are not being received on the CE1 router. The physical topology of the network is CE1-PE1-PE2-CE2. The CE1-PE1 subnet is 172.16.1.0/24. The CE2-PE2 subnet is 172.16.2.0/24. PE1's loopback is 192.168.3.1 and PE2's loopback is192.168.4.1.Referring to the output in the exhibit, what is the problem?

A. No LSP exists between PE1 and PE2.

Page 148: JNCIP-SP JN0-661 · PDF file · 2017-07-29You must ensure that r1's IPv4 loopback address exists in r3 ... redistribute the VPN routes into OSPF. Correct Answer: D ... this route

http://www.gratisexam.com/

B. Route targets are not properly configured.

C. as-override is not configured in the VRFs.

D. family inet-vpn is not configured on the PEs.

Correct Answer: BSection: BGPExplanation

Explanation/Reference:

QUESTION 57Click the Exhibit button.

Referring to the exhibit, PE2 requires the loopback of PE1 to appear in the inet.3 routing table as a labeled route. Which configuration parameter is specificallyrequired to support this?

A. resolve-vpn

B. family inet-vpn

C. traffic-engineering bgp-igp

D. traffic-engineering mpls-forwarding

Correct Answer: ASection: BGPExplanation

Explanation/Reference:

Page 149: JNCIP-SP JN0-661 · PDF file · 2017-07-29You must ensure that r1's IPv4 loopback address exists in r3 ... redistribute the VPN routes into OSPF. Correct Answer: D ... this route

http://www.gratisexam.com/

QUESTION 58Click the Exhibit button.

R3 and R4 want to establish an EBGP session between each other's loopback addresses. They have each configured static routes to the other's loopback addressand can ping from loopback to loopback. Their EBGP session is configured with correct neighbor and local addresses. The

correct AS numbers have been specified at the [routing-options] hierarchy as well. Considering the topology in the exhibit, which statement is true?

A. BGP's protocol preference must be adjusted to be lower than protocol static for the session to establish.

B. Each side must configure multipath for the session to establish.

C. Each peer must specify a local-as within their EBGP configuration for the session to establish.

D. Each peer must configure multihop for the session to establish.

Correct Answer: DSection: BGPExplanation

Explanation/Reference:

Page 150: JNCIP-SP JN0-661 · PDF file · 2017-07-29You must ensure that r1's IPv4 loopback address exists in r3 ... redistribute the VPN routes into OSPF. Correct Answer: D ... this route

http://www.gratisexam.com/

QUESTION 59Click the Exhibit button.

The exhibit shows the output of a Junos show bgp neighbor command. Which two statements are true? (Choose two.)

A. IPv4 routes will be exchanged over this session.

B. IPv6 routes will be exchanged over this session.

Page 151: JNCIP-SP JN0-661 · PDF file · 2017-07-29You must ensure that r1's IPv4 loopback address exists in r3 ... redistribute the VPN routes into OSPF. Correct Answer: D ... this route

http://www.gratisexam.com/

C. The local router initiated the BGP session.

D. BFD keepalive is configured to 30 seconds.

Correct Answer: ACSection: BGPExplanation

Explanation/Reference:

QUESTION 60Click the Exhibit button.

You work for ISP A, as shown in the exhibit, and must configure R1 to use load balancing across both available links to ISP B's network. Which command do youuse to finish the configuration?

A. set protocols bgp group isp-b multipath

B. set routing-options forwarding-table export per-packet

C. set protocols bgp group isp-b multihop

D. set routing-options forwarding-table load-balance

Page 152: JNCIP-SP JN0-661 · PDF file · 2017-07-29You must ensure that r1's IPv4 loopback address exists in r3 ... redistribute the VPN routes into OSPF. Correct Answer: D ... this route

http://www.gratisexam.com/

Correct Answer: ASection: BGPExplanation

Explanation/Reference:

QUESTION 61Click the Exhibit button.

customer-vpn { instance-type vrf; interface ge-0/0/0.0; route-distinguisher 172.16.1.1:1; vrf-target target:65000:100;}

You are configuring a new PE router in your Layer 3 VPN. A remote PE router is using the configuration shown in the exhibit. Which configuration is needed toreceive customer-vpn routes from the remote PE?

A. customer-vpn { instance-type vrf; interface ge-0/0/1.0; route-distinguisher 172.16.1.2:1; vrf-target { export target:65000:100; import target:65000:200; }}

B. customer-vpn { instance-type vrf; interface ge-0/0/1.0; route-distinguisher 172.16.1.2:1; vrf-target { export target:65000:200; import target:65000:200; }}

C. customer-vpn { instance-type vrf; interface ge-0/0/1.0; route-distinguisher 172.16.1.2:1;

Page 153: JNCIP-SP JN0-661 · PDF file · 2017-07-29You must ensure that r1's IPv4 loopback address exists in r3 ... redistribute the VPN routes into OSPF. Correct Answer: D ... this route

http://www.gratisexam.com/

vrf-target target:65000:100;}

D. customer-vpn { instance-type vrf; interface ge-0/0/1.0; route-distinguisher 172.16.1.2:1; vrf-target target:65000:200;}

Correct Answer: CSection: BGPExplanation

Explanation/Reference:

QUESTION 62Click the Exhibit button.

Page 154: JNCIP-SP JN0-661 · PDF file · 2017-07-29You must ensure that r1's IPv4 loopback address exists in r3 ... redistribute the VPN routes into OSPF. Correct Answer: D ... this route

http://www.gratisexam.com/

You work for ISP A. Customers of both ISP B and ISP C must be able to reach all of your customers, but your network must not allow transit traffic between ISP Band ISP C.

Referring to the exhibit, which two methods could you use? (Choose two.)

A. Use local preference to prefer the proper routes.

B. Use the well-known no-transit community.

C. Use policy to filter routes on AS number.

D. Use communities to identify and filter routes.

Correct Answer: CDSection: BGPExplanation

Explanation/Reference:

QUESTION 63Click the Exhibit button.

The exhibit contains a BGP topology. R1 and R2 are peering using IBGP. R2 and R3 are peering with EBGP. R1 is not installing any routes from R3 due to next-hopresolution issues. Which two configurations will resolve this issue? (Choose two.)

A. Use a policy to advertise the loopback on R2 into the IGP.

B. Advertise the R2-R3 subnet into the IGP.

C. Configure advertise-inactive on the IBGP peering session on R2.

D. Configure next-hop self on the IBGP peering session on R2.

Correct Answer: BD

Page 155: JNCIP-SP JN0-661 · PDF file · 2017-07-29You must ensure that r1's IPv4 loopback address exists in r3 ... redistribute the VPN routes into OSPF. Correct Answer: D ... this route

http://www.gratisexam.com/

Section: BGPExplanation

Explanation/Reference:

QUESTION 64Which two statements correctly describe BGP operation? (Choose two.)

A. IBGP does not advertise routes learned from other IBGP neighbors.

B. IBGP advertises routes learned from other IBGP neighbors.

C. EBGP advertises routes learned from other IBGP or EBGP neighbors.

D. EBGP does not advertise routes learned from other EBGP neighbors.

Correct Answer: ACSection: BGPExplanation

Explanation/Reference:

QUESTION 65Click the Exhibit button.

Page 156: JNCIP-SP JN0-661 · PDF file · 2017-07-29You must ensure that r1's IPv4 loopback address exists in r3 ... redistribute the VPN routes into OSPF. Correct Answer: D ... this route

http://www.gratisexam.com/

Two PE routers in your Layer 3 VPN are not advertising customer VPN routes to each other. Referring to the output in the exhibit, which configuration parameter ismissing?

http://www.gratisexam.com

A. family inet on PE1

B. family inet on PE2

C. family inet-vpn on PE1

D. family inet-vpn on PE2

Correct Answer: DSection: BGPExplanation

Explanation/Reference:

QUESTION 66Click the Exhibit button.

Page 157: JNCIP-SP JN0-661 · PDF file · 2017-07-29You must ensure that r1's IPv4 loopback address exists in r3 ... redistribute the VPN routes into OSPF. Correct Answer: D ... this route

http://www.gratisexam.com/

You are the administrator of AS 65000. In the exhibit, there are four links between your network (AS 65000) and your upstream provider (AS 65001).

You have an export policy on all of your routers to advertise your routes such that:

Router A. MED 100, AS Path (65000), Origin 1Router B. MED 100, AS Path (65000 65000), Origin 0Router C. MED 50, AS Path (65000 65000), Origin 1Router D. MED 50, AS Path (65000), Origin 0

Through which link will traffic from the Web server enter your network (AS 65000)?

A. Router A

B. Router B

C. Router C

D. Router D

Correct Answer: D

Page 158: JNCIP-SP JN0-661 · PDF file · 2017-07-29You must ensure that r1's IPv4 loopback address exists in r3 ... redistribute the VPN routes into OSPF. Correct Answer: D ... this route

http://www.gratisexam.com/

Section: BGPExplanation

Explanation/Reference:

QUESTION 67Click the Exhibit button.

All networks shown in the exhibit contain more than one BGP speaking router. You operate ISP A. You must ensure that customer Y sends their traffic to you overthe directly connected link but customer Y is not used for transit into your network. What do you do to accomplish this?

A. Advertise routes to customer Y with the well-known no-transit community.

B. Advertise routes to customer X with the well-known no-advertise community.

C. Advertise routes to customer Y with the well-known no-export community.

D. Advertise routes to customer X with the well-known as-transit community.

Correct Answer: CSection: BGPExplanation

Page 159: JNCIP-SP JN0-661 · PDF file · 2017-07-29You must ensure that r1's IPv4 loopback address exists in r3 ... redistribute the VPN routes into OSPF. Correct Answer: D ... this route

http://www.gratisexam.com/

Explanation/Reference:

QUESTION 68You are the administrator for a network that uses IBGP. As the network grows, you must examine options to support increased scale. Which two scaling optionsshould you consider? (Choose two.)

A. route reflection

B. areas

C. zones

D. confederations

Correct Answer: ADSection: BGPExplanation

Explanation/Reference:

QUESTION 69Click the Exhibit button.

Page 160: JNCIP-SP JN0-661 · PDF file · 2017-07-29You must ensure that r1's IPv4 loopback address exists in r3 ... redistribute the VPN routes into OSPF. Correct Answer: D ... this route

http://www.gratisexam.com/

In the exhibit, ISP A is charged a higher rate for traffic sent to R2. You are asked to lower costs for ISP A by configuring R1 to send traffic to R3 whenever possible.What are two ways to do this? (Choose two.)

A. set protocols bgp group isp-b neighbor 192.0.2.6 local-preference 120

B. set protocols bgp group isp-b neighbor 192.0.2.6 local-preference 80

C. set protocols bgp group isp-b neighbor 192.0.2.10 local-preference 120

D. set protocols bgp group isp-b neighbor 192.0.2.10 local-preference 80

Correct Answer: BCSection: BGPExplanation

Explanation/Reference:

QUESTION 70Click the Exhibit button.

Both autonomous systems shown in the exhibit use BGP with a full-mesh IBGP configuration within each autonomous system and EBGP between the twoautonomous systems. A single route is generated on R1 and advertised into BGP.

Page 161: JNCIP-SP JN0-661 · PDF file · 2017-07-29You must ensure that r1's IPv4 loopback address exists in r3 ... redistribute the VPN routes into OSPF. Correct Answer: D ... this route

http://www.gratisexam.com/

Which two statements are true in this scenario? (Choose two.)

A. R4 will not automatically readvertise the route to R5.

B. R5 will automatically readvertise the route to other routers in AS 65512.

C. R5 will not automatically readvertise the route to other routers in AS 65512.

D. R4 will automatically readvertise the route to R5.

Correct Answer: CDSection: BGPExplanation

Explanation/Reference:In general, deployed BGP implementations do not advertise the external route with the highest local preference value to internal peers unless it is the best route.

QUESTION 71Click the Exhibit button.

[edit]user@router# show protocols bgpexport nhs;group INT { type internal; local-address 172.16.12.205; cluster 172.16.12.205; neighbor 172.16.12.237; neighbor 172.16.12.210;}group EXT { type external; local-address 23.56.83.210; peer-as 200; neighbor 23.56.83.209;}

[edit]user@router# show policy-optionspolicy-statement nhs { term one { from protocol bgp; then {

Page 162: JNCIP-SP JN0-661 · PDF file · 2017-07-29You must ensure that r1's IPv4 loopback address exists in r3 ... redistribute the VPN routes into OSPF. Correct Answer: D ... this route

http://www.gratisexam.com/

next-hop self; } } term two { then accept; }}

You implemented the configuration shown in the exhibit on your route reflector device. However, you notice traffic is transiting the route reflector rather than takingthe optimum path.

Which two actions would solve the problem? (Choose two.)

A. Change the policy to match on the external BGP neighbor.

B. Change the policy to match on the internal BGP neighbor.

C. Change a direct peering session between both internal neighbors and use the multihop parameter.

D. Change a direct peering session between both internal neighbors and use the no-client-reflect parameter.

Correct Answer: BDSection: BGPExplanation

Explanation/Reference:The no-client-reflect command disables intra-cluster route redistribution by the system acting as the route reflector. Include this statement when the client cluster isfully meshed to prevent the sending of redundant route advertisements. Route reflection provides a way to decrease BGP control traffic and minimizing the numberof update messages sent within the AS.

References: https://www.juniper.net/documentation/en_US/junos16.1/topics/concept/routing-protocol-bgp-security-route-reflector-understanding.html

QUESTION 72Your company has multiple upstream BGP connections to the Internet ISP-A, ISP-B, and ISP-C. You want to ensure that all traffic coming into your network usesISP-A.

How would you accomplish this task?

A. Change the route preference to be higher on routes being advertised to ISP-B and ISP-C.

B. Prepend your AS number on routes being advertised to ISP-B and ISP-C.

C. Change the local preference to be higher on routes being advertised to ISP-A.

D. Prepend your AS number on routes being advertised to ISP-A.

Page 163: JNCIP-SP JN0-661 · PDF file · 2017-07-29You must ensure that r1's IPv4 loopback address exists in r3 ... redistribute the VPN routes into OSPF. Correct Answer: D ... this route

http://www.gratisexam.com/

Correct Answer: ASection: BGPExplanation

Explanation/Reference:Understanding BGP Path Selection

For each prefix in the routing table, the routing protocol process selects a single best path. After the best path is selected, the route is installed in the routing table.The best path becomes the active route if the same prefix is not learned by a protocol with a lower (more preferred) global preference value, also known as theadministrative distance. The algorithm for determining the active route is as follows:

1. Verify that the next hop can be resolved.2. Choose the path with the lowest preference value (routing protocol process preference).Routes that are not eligible to be used for forwarding (for example, because they were rejected by routing policy or because a next hop is inaccessible) have apreference of –1 and are never chosen.Etc.

References: https://www.juniper.net/documentation/en_US/junos12.3/topics/reference/general/routing-ptotocols-address-representation.html

QUESTION 73Click the Exhibit button.

Page 164: JNCIP-SP JN0-661 · PDF file · 2017-07-29You must ensure that r1's IPv4 loopback address exists in r3 ... redistribute the VPN routes into OSPF. Correct Answer: D ... this route

http://www.gratisexam.com/

RR:

protocols { bgp { group ebgd { type external; peer-as 100; neighbor 172.16.1.1 { description R1; } } group ibgp { type internal; neighbor 172.16.1.2 { description R2; } group cluster {

Page 165: JNCIP-SP JN0-661 · PDF file · 2017-07-29You must ensure that r1's IPv4 loopback address exists in r3 ... redistribute the VPN routes into OSPF. Correct Answer: D ... this route

http://www.gratisexam.com/

type internal; neighbor 172.16.1.3 { description R3; } neighbor 172.16.1.4 { description R4; } neighbor 172.16.1.5 { description R5; } cluster 0.0.0.1; no-client-reflect; } }}

Router RR is receiving routes from R1, R2, R3, and R4 as shown in the exhibit.

Which routes will RR advertise to R5? (Choose two.)

A. routes from R4

B. routes from R1

C. routes from R2

D. routes from R3

Correct Answer: ABSection: BGPExplanation

Explanation/Reference:

QUESTION 74Click the Exhibit button.

Page 166: JNCIP-SP JN0-661 · PDF file · 2017-07-29You must ensure that r1's IPv4 loopback address exists in r3 ... redistribute the VPN routes into OSPF. Correct Answer: D ... this route

http://www.gratisexam.com/

Referring to the exhibit, you control AS 24652. You are asked to ensure that traffic destined to the 23.56.83.0/24 network from ISP 4 takes the most optimum paththrough ISP 3. ISP 1 should be used as a backup for this traffic flow.

Which two actions would accomplish this task? (Choose two.)

A. Set a higher local preference for the route advertised by ISP 3.

B. Advertise a longer AS path from R2 to ISP 4.

C. Set a lower local preference for the route advertised by ISP 3.

D. Advertise a longer AS path from R1 to ISP4.

Correct Answer: ADSection: BGPExplanation

Explanation/Reference:A: Internal BGP (IBGP) sessions use a metric called the local preference, which is carried in IBGP update packets in the path attribute LOCAL_PREF. When anautonomous system (AS) has multiple routes to another AS, the local preference indicates the degree of preference for one route over the other routes. The routewith the highest local preference value is preferred.

D: BGP does not take bandwidth into consideration when determining the best path. By using AS path prepending, you can lengthen the AS path that routingdevices advertise to neighbors to make the neighbors calculate the path to be longer than it actually is.

References: https://www.juniper.net/documentation/en_US/junos15.1/topics/topic-map/bgp-local-preference.html

Page 167: JNCIP-SP JN0-661 · PDF file · 2017-07-29You must ensure that r1's IPv4 loopback address exists in r3 ... redistribute the VPN routes into OSPF. Correct Answer: D ... this route

http://www.gratisexam.com/

http://www.juniper.net/documentation/en_US/junos15.1/topics/example/routing-policy-security-routing-policy-to-prepend-to-as-path-configuring.html

QUESTION 75R1 is exporting 2000:FEFE:100::/64 to R2 over the EBGP peering session as shown in the exhibit.

What will R1 use for this route's protocol next hop when advertising it to R2?

Click the Exhibit button.

Exhibit:

A. 2000:FEFE:89::1

B. 172.16.1.1

C. 10.1.1.1

Page 168: JNCIP-SP JN0-661 · PDF file · 2017-07-29You must ensure that r1's IPv4 loopback address exists in r3 ... redistribute the VPN routes into OSPF. Correct Answer: D ... this route

http://www.gratisexam.com/

D. ::FFFF:172.16.1.1

Correct Answer: BSection: BGPExplanation

Explanation/Reference:When a BGP router reports itself as the next hop, whether because of an explicit neighbor next-hop-self configuration or implicitly as a result of participating in anEBGP session, BGP allocates a new in label and adds an entry to the MPLS forwarding table, creating a label-to-next-hop mapping.

Note: When a BGP router does not report itself as the next hop, whether because of an explicit neighbor next-hop-unchanged configuration or implicitly as a resultof a participating in an IBGP session, BGP does not allocate a new in label. Instead, if the route is advertised as a labeled route, BGP uses the existing out label.This feature is used mainly on route reflectors.

References: https://www.juniper.net/techpubs/en_US/junose16.1/topics/concept/mbgp-bgp-next-hop-self-overview.html

QUESTION 76Click on the exhibit

In the exhibit, you assigned Customer A route target of target:65432:100. You assigned Customer B a route target of target:65432:200. Customer A and CustomerB want to share specific routes between their networks to support an Extranet application. The customers would like to share these routes for the sites connected tothe PE1 router. What accomplishes this design?

A. Use the "auto-export" command

B. Use the "instance-export" command

C. Place both CE interfaces in the same VRF

Page 169: JNCIP-SP JN0-661 · PDF file · 2017-07-29You must ensure that r1's IPv4 loopback address exists in r3 ... redistribute the VPN routes into OSPF. Correct Answer: D ... this route

http://www.gratisexam.com/

D. Configure RIB groups between the VRFs

Correct Answer: DSection: BGPExplanation

Explanation/Reference:

QUESTION 77Click on the exhibit

Page 170: JNCIP-SP JN0-661 · PDF file · 2017-07-29You must ensure that r1's IPv4 loopback address exists in r3 ... redistribute the VPN routes into OSPF. Correct Answer: D ... this route

http://www.gratisexam.com/

Customer A is complaining that routes advertised from CE2 router are not beign received on the CE1 router. The physical topology of the network is CE-PE1-PE2-CE2. The CE1-PE1 subnet is running OSPF over 172.16.1.0/24. The CE2-PE2 subnet is running BGP over 172.16.2.0/24. PE1's loopback is 192.168.3.1 and PE2'sloopback is 192.168.4.1. Referring to the output in the exhibit, what it the problem.

A. No export policy exists for the PE1-CE1 protocol

B. "as-override" is not configured in the PE1 VRF

C. "vrf-export" is not configured in the PE1 VRF

D. The PE1-CE1 protocol is not operational

Correct Answer: ASection: BGPExplanation

Explanation/Reference:

QUESTION 78The regular expression ^42+ .+ (23|9)$ is found in a policy on a peer router. Which three AS paths match this expression? (Choose three)

A. 23 42 42 9

B. 42 42 9

C. 42 500 23

D. 42 23

E. 42 23 9

Correct Answer: BCESection: BGP

Page 171: JNCIP-SP JN0-661 · PDF file · 2017-07-29You must ensure that r1's IPv4 loopback address exists in r3 ... redistribute the VPN routes into OSPF. Correct Answer: D ... this route

http://www.gratisexam.com/

Explanation

Explanation/Reference:

QUESTION 79Click on the exhibit

R2 receives a router to 200.200/21 from R1. It arrives both as an IBGP route and as an OSPF route. You notice that R2 is not announcing the 200.200/21 route toR3. What needs to be done on R2 for R3 to receive the 200.200/21 route?

A. Add the "external-preference 100" parameter to its OSPF configuration

B. Add the "advertise-inactive" parameter to its EBGP configuration

C. Configure an EBGP export policy to accept the 200.200/21 route from protocol BGP

D. Create an export policy to accept the 200.200/21 route and apply it to the forwarding table

Correct Answer: BSection: BGPExplanation

Explanation/Reference:

QUESTION 80

Page 172: JNCIP-SP JN0-661 · PDF file · 2017-07-29You must ensure that r1's IPv4 loopback address exists in r3 ... redistribute the VPN routes into OSPF. Correct Answer: D ... this route

http://www.gratisexam.com/

You are configuring BGP for IPv4 and IPv6 connectivity. What are two ways to do this? (Choose two)

http://www.gratisexam.com

A. IPv4 peering carrying the IPv6 NLRI

B. IPv4 peering carrying the multiprotocol (MP) NLRI

C. IPv4 peering and IPv6 peering

D. IPv6 peering carrying the IPv4 NLRI

Correct Answer: ACSection: BGPExplanation

Explanation/Reference:

QUESTION 81Click the Exhibit button.

You want to advertise routes 2.0.0.0/8 and 2.6.6.6/32 to BGP peer 192.168.11.0

Referring to the exhibit, which configuration change would satisfy this requirement?

Exhibit:

Page 173: JNCIP-SP JN0-661 · PDF file · 2017-07-29You must ensure that r1's IPv4 loopback address exists in r3 ... redistribute the VPN routes into OSPF. Correct Answer: D ... this route

http://www.gratisexam.com/

Page 174: JNCIP-SP JN0-661 · PDF file · 2017-07-29You must ensure that r1's IPv4 loopback address exists in r3 ... redistribute the VPN routes into OSPF. Correct Answer: D ... this route

http://www.gratisexam.com/

A. Delete the as1000 export policy

B. Change the as1000 policy to orlonger

C. Delete the reject export policy

D. Change the reject policy to longer

Correct Answer: BSection: (none)Explanation

Explanation/Reference:

QUESTION 82An MX series router has received a BGP prefix from its peer. There are multiple destination routes to the BGP prefix with the default BGP preference.

In this scenario, what is the first tie-breaker used to select the destination route?

A. lowest MED

B. shortest cluster list length

C. highest local preference

D. lowest origin code

Correct Answer: CSection: (none)Explanation

Explanation/Reference:

QUESTION 83

Page 175: JNCIP-SP JN0-661 · PDF file · 2017-07-29You must ensure that r1's IPv4 loopback address exists in r3 ... redistribute the VPN routes into OSPF. Correct Answer: D ... this route

http://www.gratisexam.com/

AS 100 is originating and sending eBGP routes to AS 200. AS 200 is acting as a transit provider and sending those routes to AS 300. AS 200 is using theconfederation topology shown in the exhibit.

What will the AS path of AS 100's routes be when they are received on the AS 300 router?

A. 200 100

B. 200 (65200 65100) 100

C. (65200 65100) 100

D. ({65200 65100}) 100

Correct Answer: ASection: (none)Explanation

Explanation/Reference:

QUESTION 84

Page 176: JNCIP-SP JN0-661 · PDF file · 2017-07-29You must ensure that r1's IPv4 loopback address exists in r3 ... redistribute the VPN routes into OSPF. Correct Answer: D ... this route

http://www.gratisexam.com/

Which configuration supports inter-provider Layer 3 VPN option B on ASBR1 as shown in the exhibit.

A. [edit] user@router# show interfaces { ge-1/0/0 { unit 0 { family inet { address 10.0.0.1/31; } family mpls; } } }routing-options { autonomous-system 1; }protocols { mpls { interface ge-1/0/0.0; } bgp { group ebgp { family inet { unicast; } family inet-vpn { unicast; } neighbor 10.0.0.2 { peer-as 2;

Page 177: JNCIP-SP JN0-661 · PDF file · 2017-07-29You must ensure that r1's IPv4 loopback address exists in r3 ... redistribute the VPN routes into OSPF. Correct Answer: D ... this route

http://www.gratisexam.com/

} } }}

B. [edit]user@router# showinterfaces { ge-1/0/0 { unit 0 { family inet { address 10.0.0.1/31; } family mpls; } } }routing-options { autonomous-system 1; }protocols { mpls { interface ge-1/0/0.0; } bgp { group ebgp { family inet { unicast; } family route-target;{ neighbor 10.0.0.2 { peer-as 2; } } }}

C. [edit]user@router# show interfaces { ge-1/0/0 { unit 0 { family inet { address 10.0.0.1/31;

Page 178: JNCIP-SP JN0-661 · PDF file · 2017-07-29You must ensure that r1's IPv4 loopback address exists in r3 ... redistribute the VPN routes into OSPF. Correct Answer: D ... this route

http://www.gratisexam.com/

} } }}routing-options { autonomous-system 1;} protocols { mpls { interface ge-1/0/0.0; } bgp { group ebgp { family inet { unicast; } family inet-vpn { unicast; } neighbor 10.0.0.2 { peer-as 2; } } }}

D. [edit]user@router# show interfaces { ge-1/0/0 { unit 0 { family inet { address 10.0.0.1/31; } family mpls; } } }routing-options { autonomous-system 1; }protocols { mpls {

Page 179: JNCIP-SP JN0-661 · PDF file · 2017-07-29You must ensure that r1's IPv4 loopback address exists in r3 ... redistribute the VPN routes into OSPF. Correct Answer: D ... this route

http://www.gratisexam.com/

interface ge-1/0/0.0; } bgp { group ebgp { family inet { labeled-unicast; } neighbor 10.0.0.2 { peer-as 2; } } } }

Correct Answer: ASection: (none)Explanation

Explanation/Reference:

QUESTION 85

Referring to the exhibit, you control AS 24652. You are asked to ensure that traffic destined to the 23.56.83.0/24 network from ISP 4 takes the most optimum paththrough ISP 3. ISP 1 should be used as a backup for this traffic flow.

Page 180: JNCIP-SP JN0-661 · PDF file · 2017-07-29You must ensure that r1's IPv4 loopback address exists in r3 ... redistribute the VPN routes into OSPF. Correct Answer: D ... this route

http://www.gratisexam.com/

Which two actions would accomplish this task? (Choose two.)

A. Set a higher local preference for the route advertised by ISP 3.

B. Advertise a longer AS path from R2 to ISP 4.

C. Set a lower local preference for the route advertised by ISP 3.

D. Advertise a longer AS path from R1 to ISP4.

Correct Answer: ADSection: (none)Explanation

Explanation/Reference:

QUESTION 86You are asked to implement route damping on a BGP router. There are two specific requirements for your implementation.1. damp all prefixes with a mask length to or greater than /24 more aggressively than routers with a mask length between /17 and /23. 2. damp prefixes with a mask length between /0 and /16 less than routes with a mask length greater than /16.

Which policy configuration meets the requirements?

A. [edit policy-options]user@router# showpolicy-statement damping {term1 {from {route-filter 0.0.0.0/0 prefix-lengh-range /0-/16 damping minor;route-filter 0.0.0.0/0 prefix-lengh-range /24-/32 damping major;}then accept}}damping major {half-life 30;suppress 2500;}damping minor {half-life 5;}

B. [edit policy-options]

Page 181: JNCIP-SP JN0-661 · PDF file · 2017-07-29You must ensure that r1's IPv4 loopback address exists in r3 ... redistribute the VPN routes into OSPF. Correct Answer: D ... this route

http://www.gratisexam.com/

user@router# showpolicy-statement damping {term1 {from {route-filter 0.0.0.0/0 prefix-lengh-range /0-/23 damping minor;route-filter 0.0.0.0/0 prefix-lengh-range /24-/32 damping major;}then accept}}damping major {half-life 30;suppress 2500;}damping minor {half-life 5;}

C. [edit policy-options]user@router# showpolicy-statement damping {term1 {from {route-filter 0.0.0.0/0 prefix-lengh-range /0-/23 damping minor;route-filter 0.0.0.0/0 prefix-lengh-range /24-/32 damping major;}then accept}}damping major {half-life 5;}damping minor {half-life 30;suppress 2500;}

D. [edit policy-options]user@router# showpolicy-statement damping {term1 {from {route-filter 0.0.0.0/0 prefix-lengh-range /0-/16 damping minor;route-filter 0.0.0.0/0 prefix-lengh-range /24-/32 damping major;

Page 182: JNCIP-SP JN0-661 · PDF file · 2017-07-29You must ensure that r1's IPv4 loopback address exists in r3 ... redistribute the VPN routes into OSPF. Correct Answer: D ... this route

http://www.gratisexam.com/

}then accept}}damping major {half-life 5;}damping minor {half-life 5;suppress 2500;}

Correct Answer: ASection: (none)Explanation

Explanation/Reference:

QUESTION 87Which command will match communities 101:111, 111:1, and 999:1111?

A. set policy-options community COMMUNITY members "^...:1?"

B. set policy-options community COMMUNITY members "^1.^.1+"

C. set policy-options community COMMUNITY members ["^1.1:1?" 999:1111]

D. set policy-options community COMMUNITY members "^....:1+"

Correct Answer: DSection: (none)Explanation

Explanation/Reference:

QUESTION 88

Page 183: JNCIP-SP JN0-661 · PDF file · 2017-07-29You must ensure that r1's IPv4 loopback address exists in r3 ... redistribute the VPN routes into OSPF. Correct Answer: D ... this route

http://www.gratisexam.com/

RR:

protocols { bgp { group ebgp { type external; peer-as 100; neighbor 172.16.1.1 { description R1; } } group ibgp { type internal; neighbor 172.16.1.2 { description R2; } group cluster { type internal;

Page 184: JNCIP-SP JN0-661 · PDF file · 2017-07-29You must ensure that r1's IPv4 loopback address exists in r3 ... redistribute the VPN routes into OSPF. Correct Answer: D ... this route

http://www.gratisexam.com/

neighbor 172.16.1.3 { description R3; } neighbor 172.16.1.4 { description R4; } neighbor 172.16.1.5 { description R5; } cluster 0.0.0.1; no-client-reflect; } } }

Router RR is receiving routes from R1, R2, R3, and R4 as shown in the exhibit.

Which routes will RR advertise to R5? (Choose two.)

A. routes from R4

B. routes from R1

C. routes from R2

D. routes from R3

Correct Answer: BCSection: (none)Explanation

Explanation/Reference:

QUESTION 89Your company has multiple upstream BGP connections to the Internet ISP-A, ISP-B, and ISP-C. You want to ensure that all traffic coming into your network usesISP-A. How would you accomplish this task?

A. Change the route preference to be higher on routes being advertised to ISP-B and ISP-C.

B. Prepend your AS number on routes being advertised to ISP-B and ISP-C.

C. Change the local preference to be higher on routes being advertised to ISP-A.

D. Prepend your AS number on routes being advertised to ISP-A.

Page 185: JNCIP-SP JN0-661 · PDF file · 2017-07-29You must ensure that r1's IPv4 loopback address exists in r3 ... redistribute the VPN routes into OSPF. Correct Answer: D ... this route

http://www.gratisexam.com/

Correct Answer: BSection: (none)Explanation

Explanation/Reference:

QUESTION 90

Both autonomous systems shown in the exhibit use BGP with a full-mesh iBGP configuration within each autonomous system and eBGP between the twoautonomous systems. A single route is generated on R1 and advertised into BGP.

Which two statements are true in this scenario? (Choose two.)

http://www.gratisexam.com

A. R4 will not automatically readvertise the route to R5.

B. R5 will automatically readvertise the route to other routers in AS 65512.

C. R5 will not automatically readvertise the route to other routers in AS 65512.

D. R4 will automatically readvertise the route to R5.

Page 186: JNCIP-SP JN0-661 · PDF file · 2017-07-29You must ensure that r1's IPv4 loopback address exists in r3 ... redistribute the VPN routes into OSPF. Correct Answer: D ... this route

http://www.gratisexam.com/

Correct Answer: BDSection: (none)Explanation

Explanation/Reference:

Page 187: JNCIP-SP JN0-661 · PDF file · 2017-07-29You must ensure that r1's IPv4 loopback address exists in r3 ... redistribute the VPN routes into OSPF. Correct Answer: D ... this route

http://www.gratisexam.com/

CoS

QUESTION 1You need to ensure that your high-priority traffic uses the best-possible route while your best-effort traffic uses a lower preference route.

You want to use CoS-based forwarding to use the DSCP values of the different types of traffic to assign the LSP that should be used for the next hop.

Which three additions must be made to the configuration to satisfy the requirement? (Choose three.)

A. a class-of-service forwarding policy

B. a policy statement for LSP next-hop selection

C. an important policy applied to the forwarding table

D. an export policy applied to the forwarding table

E. a multifield firewall filter for LSP next-hop selection

Correct Answer: ADESection: CoSExplanation

Explanation/Reference:D: The final step is to apply the route filter to routes exported to the forwarding engine. This is shown in the following example:routing-options { forwarding-table { export my-cos-forwarding; }}This configuration instructs the routing process to insert routes to the forwarding engine matching my-cos-forwarding with the associated next-hop CBF rules.

A: Assigning Forwarding Class and DSCP Value for Routing Engine-Generated Traffic You can set the forwarding class and differentiated service code point(DSCP) value for traffic originating in the Routing Engine. To configure forwarding class and DSCP values that apply to Routing Engine–generated traffic only, applyan output filter to the loopback (lo.0) interface and set the appropriate forwarding class and DSCP bit configuration for various protocols.

E: The following example assigns Routing Engine sourced ping packets (using ICMP) a DSCP value of 38 and a forwarding class of af17, OSPF packets a DSCPvalue of 12 and a forwarding class of af11, and BGP packets (using TCP ) a DSCP value of 10 and a forwarding class of af16.

[edit class-of-service]forwarding-classes { class af11 queue-num 7; class af12 queue-num 1; class af13 queue-num 2; class af14 queue-num 4;

Page 188: JNCIP-SP JN0-661 · PDF file · 2017-07-29You must ensure that r1's IPv4 loopback address exists in r3 ... redistribute the VPN routes into OSPF. Correct Answer: D ... this route

http://www.gratisexam.com/

class af15 queue-num 5; class af16 queue-num 4; class af17 queue-num 6; class af18 queue-num 7;}[edit firewall filter family inet]filter loopback-filter { term t1 { from { protocol icmp; # For pings } then { forwarding-class af17; dscp 38; } } term t2 { from { protocol ospf; # For OSPF } then { forwarding-class af11; dscp 12; } }}Etc.

References: https://www.juniper.net/techpubs/en_US/junos16.1/topics/usage-guidelines/cos-assigning-fc-dscp-to-re-pkts.html

http://www.juniper.net/techpubs/en_US/junos13.3/information-products/pathway-pages/cos/forwarding-classes.pdf (page 42)

QUESTION 2A customer's traffic is traversing your network, which consists of Junos devices. You must configure class of service for the traffic to meet a service-levelagreement.

In this scenario, which two statements are true? (Choose two.)

Page 189: JNCIP-SP JN0-661 · PDF file · 2017-07-29You must ensure that r1's IPv4 loopback address exists in r3 ... redistribute the VPN routes into OSPF. Correct Answer: D ... this route

http://www.gratisexam.com/

http://www.gratisexam.com

A. By default, a packet's loss priority can be either low or high.

B. A packet's loss priority can be set using classifiers or rewrite markers.

C. A packet's loss priority can be set using classifiers or rewrite markers.

D. A packet's loss priority can be set using classifiers or policers.

Correct Answer: ADSection: CoSExplanation

Explanation/Reference:A: Loss priority settings help determine which packets are dropped from the network during periods of congestion. The software supports multiple packet losspriority (PLP) designations: low and high. (In addition, medium-low and medium-high PLPs are supported when you configure tricolor marking.)

D: Packet loss priorities (PLPs) allow you to set the priority for dropping packets.

You can use the PLP setting to identify packets that have experienced congestion.

Typically, you mark packets exceeding some service level with a high loss priority--that is, a greater likelihood of being dropped.

You set PLP by configuring a classifier or a policer.

References:

http://www.juniper.net/techpubs/en_US/junos15.1/topics/usage-guidelines/cos-setting-packetloss-priority.html

http://www.juniper.net/documentation/en_US/junos15.1x49/topics/concept/cos-packet-losspriority-understanding-security.html

QUESTION 3Packets traverse a Junos device configured for class of service. Which two statements are true in this scenario? (Choose two.)

A. Packets are subject to traffic shapers before policers.

B. Packets are subject to policers before traffic shapers.

C. Packets are processed by behavior aggregate classifiers before multifield classifiers.

D. Packets are processed by multifield classifier before behavior aggregate classifiers.

Correct Answer: BCSection: CoS

Page 190: JNCIP-SP JN0-661 · PDF file · 2017-07-29You must ensure that r1's IPv4 loopback address exists in r3 ... redistribute the VPN routes into OSPF. Correct Answer: D ... this route

http://www.gratisexam.com/

Explanation

Explanation/Reference:CoS Processing order:### Ingress ###1.) Code Point (BA) Classifier2.) Policing3.) Multifield Classifier4.) Forwarding Policy

#################==== FABRIC ====#################

### Egress ###5.) Policing6.) Multifield Classifier7.) Scheduler/Shaper/RED8.) Rewrite Marker

C: The simplest way to classify a packet is to use behavior aggregate (BA) classification.

For a specified interface, you can configure both a multifield classifier and a BA classifier without conflicts.

Because the classifiers are always applied in sequential order, the BA classifier followed by the multifield classifier, any BA classification result is overridden by amultifield classifier if they conflict.

Reference: http://www.juniper.net/techpubs/en_US/junos15.1/topics/concept/classifier-ba-overview-cos-config-guide.html

QUESTION 4You have a strict-high queue configured. You notice that under bursty traffic conditions, there are tail drops on the strict-high queue.

Which action would solve this problem?

A. Assign a policer on ingress to assign a low packet loss priority to the strict-high queue.

B. Decrease the buffer size of the strict-high queue.

C. Assign a policer on egress to assign a low packet loss priority to the strict-high queue.

D. Increase the buffer size of the strict-high queue.

Correct Answer: DSection: CoS

Page 191: JNCIP-SP JN0-661 · PDF file · 2017-07-29You must ensure that r1's IPv4 loopback address exists in r3 ... redistribute the VPN routes into OSPF. Correct Answer: D ... this route

http://www.gratisexam.com/

Explanation

Explanation/Reference:A queue with strict-high priority is assured unlimited transmission bandwidth but is not actually assigned a large delay buffer. Not configuring a transmit-rate or anexplicit buffer-size on a strict high priority queue only ensures that the queue gets assigned a default minimum delay buffer, making it possible, under burstyconditions, to see tail-drops on strict-high priority queues.

Assigning a small transmit-rate or an explicit temporal or percentage buffer-size to the queue ensures that the queue has a large enough buffer to hold bursts andprotect against tail-drops.

Reference: http://www.juniper.net/documentation/en_US/junos15.1/topics/usage-guidelines/cos-configuring-schedulers-for-priority-scheduling.html

QUESTION 5What is the final component of CoS processing on a Junos device?

A. drop profile map

B. behavior aggregate classifier

C. rewrite marker

D. multifield classifier

Correct Answer: CSection: CoSExplanation

Explanation/Reference:The following steps describe the CoS process:

1. A logical interface has one or more classifiers of different types applied to it.2. The classifier assigns the packet to a forwarding class and a loss priority3. Each forwarding class is assigned to a queue4. Input (and output) policers meter traffic and might change the forwarding class and loss priority if a traffic flow exceeds its service level.5. The physical or logical interface has a scheduler map applied to it6. The scheduler defines how traffic is treated in the output queue—for example, the transmit rate, buffer size, priority, and drop profile7. The scheduler map assigns a scheduler to each forwarding class (8. The drop-profile defines how aggressively to drop packets that are using a particular scheduler9. The rewrite rule takes effect as the packet leaves a logical interface that has a rewrite rule configured. The rewrite rule writes information to the packet (for

example, EXP or DSCP bits) according to the forwarding class and loss priority of the packet.

Reference: http://www.juniper.net/documentation/en_US/junos16.1/topics/concept/packet-flow-cos-process-cos-config-guide.html

QUESTION 6

Page 192: JNCIP-SP JN0-661 · PDF file · 2017-07-29You must ensure that r1's IPv4 loopback address exists in r3 ... redistribute the VPN routes into OSPF. Correct Answer: D ... this route

http://www.gratisexam.com/

Click the Exhibit button.

Referring to the exhibit, you must ensure that all traffic sourced from C1 and destined to C2 is associated with the expedited forwarding class. Also, you mustensure that all other traffic not sourced from C1 is not impacted by the identified modification.

Which method should you use?

A. Use an input behavior aggregate classifier on ge-1/0/8.0 that matches source address 10.1.1.0/24.

B. Use an output behavior aggregate classifier on ge-1/1/17.0 that matches destination address 10.2.2.0/24.

C. Use an input multifield classifier on ge-1/0/8.0 that matches source address 10.1.1.0/24.

D. Use an output multifield classifier on ge-1/1/17.0 that matches destination address 10.2.2.0/24.

Correct Answer: CSection: CoSExplanation

Explanation/Reference:

QUESTION 7You have recently configured an aggregated Ethernet interface between two devices in your network. The member links do not all reside within the same PFEcomplex. You must ensure that the bandwidth and burst size defined in a policer applied to this aggregated Ethernet interface are properly enforced when the trafficfalls out of profile.

Which configuration parameter should you use?

A. committed-information-rate

B. committed-burst-size

C. shared-bandwidth-policer

D. physical-interface-policer

Page 193: JNCIP-SP JN0-661 · PDF file · 2017-07-29You must ensure that r1's IPv4 loopback address exists in r3 ... redistribute the VPN routes into OSPF. Correct Answer: D ... this route

http://www.gratisexam.com/

Correct Answer: CSection: CoSExplanation

Explanation/Reference:

QUESTION 8Refer to the exhibit.

[edit class-of-service]user@router# showdrop-profiles { moderate-profile { fill-level 15 drop-probability 25; fill-level 45 drop-probability 50; fill-level 80 drop-probability 75; fill-level 95 drop-probability 100; }}

Referring to the applied drop profile shown in the exhibit, if the buffer is 30 percent full, what is the probability of traffic being dropped?

A. 25 percent

B. 30 percent

C. 50 percent

D. 75 percent

Correct Answer: ASection: CoSExplanation

Explanation/Reference:

QUESTION 9You want to aggregate policing for different protocol families and different logical interfaces on the same physical interface. Which CoS configuration attribute willaccomplish this goal?

A. hierarchical policer

Page 194: JNCIP-SP JN0-661 · PDF file · 2017-07-29You must ensure that r1's IPv4 loopback address exists in r3 ... redistribute the VPN routes into OSPF. Correct Answer: D ... this route

http://www.gratisexam.com/

B. shared bandwidth policer

C. physical interface policer

D. logical interface policer

Correct Answer: CSection: CoSExplanation

Explanation/Reference:

QUESTION 10In which configuration hierarchy must the hierarchical-scheduler parameter be applied to enable hierarchical scheduling?

http://www.gratisexam.com

A. [edit class-of-service]

B. [edit class-of-service <interface_name>]

C. [edit interfaces]

D. [edit interfaces <interface_name>]

Correct Answer: DSection: CoSExplanation

Explanation/Reference:

QUESTION 11Refer to the exhibit.

[edit class-of-service]user@router# showschedulers { best-effort { transmit-rate percent 25;

Page 195: JNCIP-SP JN0-661 · PDF file · 2017-07-29You must ensure that r1's IPv4 loopback address exists in r3 ... redistribute the VPN routes into OSPF. Correct Answer: D ... this route

http://www.gratisexam.com/

buffer-size percent 25; priority low; } assured-forwarding { transmit-rate percent 25; buffer-size percent 25; priority high; } expedited-forwarding { transmit-rate percent 25; buffer-size percent 25; priority high; } network-control { transmit-rate percent 25; buffer-size percent 25; priority medium-high; }}

Referring to the configuration shown in the exhibit, only the assured-forwarding queue exceeds its configured transmission rate. Given this scenario, in which orderwill the queues be serviced?

A. Assured-forwarding, expedited-forwarding, network-control, best-effort

B. Assured-forwarding, network-control, expedited-forwarding, best-effort

C. Expedited-forwarding, best-effort, network-control, assured-forwarding

D. Expedited-forwarding, network-control, best-effort, assured-forwarding

Correct Answer: DSection: CoSExplanation

Explanation/Reference:

QUESTION 12Refer to the exhibits.

Page 196: JNCIP-SP JN0-661 · PDF file · 2017-07-29You must ensure that r1's IPv4 loopback address exists in r3 ... redistribute the VPN routes into OSPF. Correct Answer: D ... this route

http://www.gratisexam.com/

Page 197: JNCIP-SP JN0-661 · PDF file · 2017-07-29You must ensure that r1's IPv4 loopback address exists in r3 ... redistribute the VPN routes into OSPF. Correct Answer: D ... this route

http://www.gratisexam.com/

Page 198: JNCIP-SP JN0-661 · PDF file · 2017-07-29You must ensure that r1's IPv4 loopback address exists in r3 ... redistribute the VPN routes into OSPF. Correct Answer: D ... this route

http://www.gratisexam.com/

In the exhibits, what is the reason for the tail drops in queue 0?

Page 199: JNCIP-SP JN0-661 · PDF file · 2017-07-29You must ensure that r1's IPv4 loopback address exists in r3 ... redistribute the VPN routes into OSPF. Correct Answer: D ... this route

http://www.gratisexam.com/

A. The interface cannot physically handle 3.37 Gbps of traffic.

B. The default network-control scheduler is taking bandwidth from the best-effort scheduler.

C. The default queue 0 scheduler does not allocate enough buffer size for 3.37 Gbps of traffic.

D. The default queue 0 scheduler does not allocate enough transmit rate for 3.37 Gbps of traffic.

Correct Answer: CSection: CoSExplanation

Explanation/Reference:

QUESTION 13Refer to the exhibit.

user@router# showclass-of-service { scheduler-maps { core { forwarding-class best-effort scheduler be; forwarding-class network-control scheduler nc; forwarding-class expedited-forwarding scheduler ef; forwarding-class assured-forwarding scheduler af; } } schedulers { be { transmit-rate percent 30; buffer-size percent 30; priority low; } nc { transmit-rate percent 3; buffer-size percent 3; priority high; } ef { transmit-rate { percent 24; exact; }

Page 200: JNCIP-SP JN0-661 · PDF file · 2017-07-29You must ensure that r1's IPv4 loopback address exists in r3 ... redistribute the VPN routes into OSPF. Correct Answer: D ... this route

http://www.gratisexam.com/

buffer-size percent 24; priority high; } af { transmit-rate percent 25; buffer-size percent 25; priority strict-high; } }}

The core scheduler-map is assigned to fe-0/l/0.

The following traffic is queued for transmission from fe-0/1/3:

- 40 Mbps of best-effort traffic- 2 Mbps of network-control traffic- 41 Mbps of expedited-forwarding traffic- 30 Mbps of assured-forwarding traffic

Which queue uses the highest amount of interface bandwidth?

A. The best-effort queue

B. The expedited-forwarding queue

C. The network-control queue

D. The assured-forwarding queue

Correct Answer: ASection: CoSExplanation

Explanation/Reference:

QUESTION 14Refer to the exhibit.

user@router# showchassis { aggregated-devices {

Page 201: JNCIP-SP JN0-661 · PDF file · 2017-07-29You must ensure that r1's IPv4 loopback address exists in r3 ... redistribute the VPN routes into OSPF. Correct Answer: D ... this route

http://www.gratisexam.com/

ethernet { device count 1; } }}interfacs { ge-0/0/0 { gigether-options { 802.3ad ae0; }}ge-1/0/0 { gigether-options { 802.3ad ae0; }}ae0 { unit 0 { family inet { policer { input limit-50m; } address 192.168.42.1/30; } }}firewall { policer limit-50m { if-exceeding { bandwidth-limit 50m; burst-size-limit 15k; } then discard; }}

What would explain why the policer is allowing 100 Mbps of traffic into the router?

A. The burst-size-limit is inappropriate for the bandwidth-limit and for the default MTU of the ge- */3# interfaces.

B. The policer is not using shared-bandwidth-policer, which it must to achieve a rate of 50 Mbps of traffic.

C. The policer is applied in the wrong direction.

D. The policer is not using logical-interface-policer, which it must to achieve a rate of 50 Mbps of traffic.

Page 202: JNCIP-SP JN0-661 · PDF file · 2017-07-29You must ensure that r1's IPv4 loopback address exists in r3 ... redistribute the VPN routes into OSPF. Correct Answer: D ... this route

http://www.gratisexam.com/

Correct Answer: BSection: CoSExplanation

Explanation/Reference:

QUESTION 15Which statement correctly describes the function of a policer?

A. It defines a set of parameters, including transmission rate, queue priority, delay buffers, and congestion management and avoidance.

B. It provides a first stage of congestion management by controlling the amount of traffic entering a device.

C. It writes a value into an outbound packet's CoS field according to the packet's forwarding class and loss priority.

D. It determines the amount of bandwidth allocated to a queue.

Correct Answer: BSection: CoSExplanation

Explanation/Reference:

QUESTION 16In your network, customers are complaining about the performance of voice traffic.

Which command displays the number of packets dropped due to the drop profile configured?

A. show interfaces queue ge-1/0/0

B. show interfaces terse

C. show class-of-service interface ge-1/0/0

D. show class-of-service forwarding-class

Correct Answer: ASection: CoSExplanation

Explanation/Reference:

Page 203: JNCIP-SP JN0-661 · PDF file · 2017-07-29You must ensure that r1's IPv4 loopback address exists in r3 ... redistribute the VPN routes into OSPF. Correct Answer: D ... this route

http://www.gratisexam.com/

QUESTION 17Click the Exhibit button.

Traffic is flowing through an MX Series router. Traffic using the top and critical schedulers is out of profile, while all other traffic is currently in profile.

Referring to the exhibit, which two statements are correct? (Choose two.)

A. The top queue is serviced before the best-effort queue.

B. The top queue is serviced after the best-effort queue.

C. The critical queue is serviced before the best-effort queue.

D. The critical queue is serviced after the best-effort queue.

Correct Answer: ADSection: CoSExplanation

Explanation/Reference:

Page 204: JNCIP-SP JN0-661 · PDF file · 2017-07-29You must ensure that r1's IPv4 loopback address exists in r3 ... redistribute the VPN routes into OSPF. Correct Answer: D ... this route

http://www.gratisexam.com/

QUESTION 18You are configuring CoS schedulers on an M Series router. For some queues, you want to limit throughput to the configured transmit rate, and buffer excess traffic.

Which two transmission rate options can you use? (Choose two.)

A. exact

B. rate-limit

C. remainder

D. shaping-rate

Correct Answer: ADSection: CoSExplanation

Explanation/Reference:

QUESTION 19Click the Exhibit button.

Page 205: JNCIP-SP JN0-661 · PDF file · 2017-07-29You must ensure that r1's IPv4 loopback address exists in r3 ... redistribute the VPN routes into OSPF. Correct Answer: D ... this route

http://www.gratisexam.com/

You manage an MX series router (with 100 ms buffer size per port) that includes the configuration shown in the exhibit. Traffic marked with DSCP 000011 isentering the ge-1/0/4 interface at 102 Mbps. The traffic exits the device on the ge-1/0/5 interface. There is no other traffic transiting the router. What happens totraffic exceeding 100 Mbps?

A. Traffic exceeding 100 Mbps is forwarded.

B. Traffic exceeding 100 Mbps is buffered.

C. Traffic exceeding 100 Mbps is redirected to a rate limiter.

D. Traffic exceeding 100 Mbps is dropped.

Correct Answer: ASection: CoSExplanation

Explanation/Reference:

Page 206: JNCIP-SP JN0-661 · PDF file · 2017-07-29You must ensure that r1's IPv4 loopback address exists in r3 ... redistribute the VPN routes into OSPF. Correct Answer: D ... this route

http://www.gratisexam.com/

QUESTION 20Click the Exhibit button.

[edit firewall three-color-policer policerA]user@router# showtwo-rate { color-aware; committed-information-rate 1m; committed-burst-size 500k; peak-information-rate 5m; peak-burst-size 1m;}

Traffic is flowing through the policer as shown in the exhibit. The traffic has a throughput rate of 3 Mbps, and the burst size counter is at 1.5 MB. How is trafficaffected?

A. Traffic has its PLP set to low.

B. Traffic has its PLP set to medium-low.

C. Traffic has its PLP set to medium-high.

D. Traffic has its PLP set to high.

Correct Answer: CSection: CoSExplanation

Explanation/Reference:

QUESTION 21Click the Exhibit button.

Page 207: JNCIP-SP JN0-661 · PDF file · 2017-07-29You must ensure that r1's IPv4 loopback address exists in r3 ... redistribute the VPN routes into OSPF. Correct Answer: D ... this route

http://www.gratisexam.com/

On your MX Series router, traffic using the less-critical scheduler is out of profile. All other data is currently in profile. Referring to the exhibit, which statement iscorrect?

A. The less-critical queue can use the remaining bandwidth.

B. The less-critical queue cannot buffer traffic, so traffic is dropped.

C. The less-critical queue is serviced before the critical queue.

D. The less-critical queue cannot use the remaining bandwidth.

Correct Answer: ASection: CoSExplanation

Explanation/Reference:

QUESTION 22Click the Exhibit button.

Page 208: JNCIP-SP JN0-661 · PDF file · 2017-07-29You must ensure that r1's IPv4 loopback address exists in r3 ... redistribute the VPN routes into OSPF. Correct Answer: D ... this route

http://www.gratisexam.com/

Page 209: JNCIP-SP JN0-661 · PDF file · 2017-07-29You must ensure that r1's IPv4 loopback address exists in r3 ... redistribute the VPN routes into OSPF. Correct Answer: D ... this route

http://www.gratisexam.com/

You manage an MX series router (with 100 ms buffer size per port) that includes the configuration shown in the exhibit. Traffic marked with DSCP 000101 isentering the ge-1/0/4 interface at 102 Mbps. The traffic exits the device on the ge-1/0/5 interface. There is no other traffic transiting the router. What happens totraffic exceeding 100 Mbps?

http://www.gratisexam.com

A. Traffic exceeding 100 Mbps is forwarded.

B. Traffic exceeding 100 Mbps is buffered.

Page 210: JNCIP-SP JN0-661 · PDF file · 2017-07-29You must ensure that r1's IPv4 loopback address exists in r3 ... redistribute the VPN routes into OSPF. Correct Answer: D ... this route

http://www.gratisexam.com/

C. Traffic exceeding 100 Mbps is redirected to a rate limiter.

D. Traffic exceeding 100 Mbps is dropped.

Correct Answer: DSection: CoSExplanation

Explanation/Reference:

QUESTION 23Click the Exhibit button.

On your MX Series router, traffic using the critical scheduler is out of profile. All other data is currently in profile. Referring to the exhibit, which statement is correct?

A. The critical queue is serviced before the less-critical queue.

B. The critical queue is serviced after the left-over queue.

Page 211: JNCIP-SP JN0-661 · PDF file · 2017-07-29You must ensure that r1's IPv4 loopback address exists in r3 ... redistribute the VPN routes into OSPF. Correct Answer: D ... this route

http://www.gratisexam.com/

C. The critical queue is serviced before the data queue.

D. The critical queue is serviced before the voice queue.

Correct Answer: BSection: CoSExplanation

Explanation/Reference:

QUESTION 24You are a network administrator in charge of configuring CoS for your network. Your network includes a voice application with strict latency requirements, so thatany packets delayed by more than 75 ms are effectively useless. When configuring the scheduler for this application, which feature ensures that you do not wastebuffer space?

A. rate-limit

B. adaptive

C. latency-limit

D. temporal

Correct Answer: DSection: CoSExplanation

Explanation/Reference:

QUESTION 25Click the Exhibit button.

Page 212: JNCIP-SP JN0-661 · PDF file · 2017-07-29You must ensure that r1's IPv4 loopback address exists in r3 ... redistribute the VPN routes into OSPF. Correct Answer: D ... this route

http://www.gratisexam.com/

On your MX Series router, traffic using the voice scheduler has exceeded its transmit rate. All other data is currently in profile. Referring to the exhibit, whichstatement is correct?

A. The voice queue is serviced later than the less-critical queue.

B. The voice queue is serviced later than the left-over queue.

C. The voice queue is serviced before the critical queue.

D. The voice queue is serviced after data queue.

Correct Answer: CSection: CoSExplanation

Explanation/Reference:

QUESTION 26Click the Exhibit button.

Page 213: JNCIP-SP JN0-661 · PDF file · 2017-07-29You must ensure that r1's IPv4 loopback address exists in r3 ... redistribute the VPN routes into OSPF. Correct Answer: D ... this route

http://www.gratisexam.com/

Page 214: JNCIP-SP JN0-661 · PDF file · 2017-07-29You must ensure that r1's IPv4 loopback address exists in r3 ... redistribute the VPN routes into OSPF. Correct Answer: D ... this route

http://www.gratisexam.com/

Page 215: JNCIP-SP JN0-661 · PDF file · 2017-07-29You must ensure that r1's IPv4 loopback address exists in r3 ... redistribute the VPN routes into OSPF. Correct Answer: D ... this route

http://www.gratisexam.com/

Traffic is flowing through the interfaces in the exhibit as follows:

On ge-0/0/2.0, IPv4 traffic has a throughput rate of 4 Mbps, and the burst size counter is at 200 KB.On ge-0/0/2.0, IPv6 traffic has a throughput rate of 7 Mbps, and the burst size counter is at 550 KB.On ge-0/0/3.0, IPv4 traffic has a throughput rate of 5 Mbps, and the burst size counter is at 250 KB.On ge-0/0/3.1, IPv6 traffic has a throughput rate of 12 Mbps, and the burst size counter is at 450 KB.

Which statement describes what is happening?

A. IPv6 traffic on ge-0/0.3.1 is being dropped; all other traffic is unaffected.

B. IPv4 traffic on ge-0/0/2.0 is unaffected; IPv6 traffic on ge-0/0/2.0 is being dropped; IPv4 traffic on ge-0/0/3.0 is unaffected; IPv6 traffic on ge-0/0/3.1 is beingdropped.

C. IPv4 traffic on ge-0/0/2.0 is being dropped; IPv6 traffic on ge-0/0/2.0 is being dropped; IPv4 traffic on ge-0/0/3.0 is unaffected; IPv6 traffic on ge-0/0/3.1 isunaffected.

D. All IPv4 and IPv6 traffic on ge-0/0/2 and ge-0/0/3 is being dropped.

Correct Answer: BSection: CoSExplanation

Explanation/Reference:

QUESTION 27Click the Exhibit button.

Page 216: JNCIP-SP JN0-661 · PDF file · 2017-07-29You must ensure that r1's IPv4 loopback address exists in r3 ... redistribute the VPN routes into OSPF. Correct Answer: D ... this route

http://www.gratisexam.com/

What would happen if the guaranteed-rate command is removed from the configuration shown in the exhibit?

A. The logical interface gets a minimal bandwidth reservation.

B. The minimum-rate command should be configured instead.

C. The logical interface receives no bandwidth constraints.

D. The transmit-rate command should be configured instead.

Correct Answer: ASection: CoSExplanation

Explanation/Reference:

QUESTION 28Which operational mode command displays the number of configured forwarding classes?

A. show interfaces queue ge-1/0/0

B. show interfaces terse

C. show class-of-service interface

D. show forwarding classes

Correct Answer: ASection: CoS

Page 217: JNCIP-SP JN0-661 · PDF file · 2017-07-29You must ensure that r1's IPv4 loopback address exists in r3 ... redistribute the VPN routes into OSPF. Correct Answer: D ... this route

http://www.gratisexam.com/

Explanation

Explanation/Reference:

QUESTION 29Click the Exhibit button.

drop-profiles { profileA { fill-level 60 drop-probability 60; fill-level 80 drop-probability 70; fill-level 100 drop-probability 100; }}

Given the drop profile in the exhibit, what is the drop probability when the buffer reaches 90% full?

A. 60%

B. 70%

C. 85%

D. 90%

Correct Answer: BSection: CoSExplanation

Explanation/Reference:

QUESTION 30Click the Exhibit button.

Page 218: JNCIP-SP JN0-661 · PDF file · 2017-07-29You must ensure that r1's IPv4 loopback address exists in r3 ... redistribute the VPN routes into OSPF. Correct Answer: D ... this route

http://www.gratisexam.com/

On your MX Series router, traffic using the critical scheduler is out of profile. All other data is currently in profile. Referring to the exhibit, which statement is correct?

A. The critical queue is serviced before the less-critical queue.

B. The critical queue is serviced after the left-over queue.

C. The critical queue is serviced before the data queue.

D. The critical queue is serviced before the voice queue.

Correct Answer: BSection: CoSExplanation

Explanation/Reference:

QUESTION 31Which CoS feature supports per-VLAN queuing and scheduling?

Page 219: JNCIP-SP JN0-661 · PDF file · 2017-07-29You must ensure that r1's IPv4 loopback address exists in r3 ... redistribute the VPN routes into OSPF. Correct Answer: D ... this route

http://www.gratisexam.com/

A. multilevel scheduling

B. hierarchical scheduling

C. tagged queuing

D. per-instance queuing

Correct Answer: CSection: CoSExplanation

Explanation/Reference:

QUESTION 32Packets traverse a Junos device configured for class of service.

Which two statements are true in this scenario? (Choose two.)

A. Packets are subject to traffic shapers before policers.

B. Packets are subject to policers before traffic shapers.

C. Packets are processed by behavior aggregate classifiers before multifield classifiers.

D. Packets are processed by multifield classifier before behavior aggregate classifiers.

Correct Answer: ACSection: CoSExplanation

Explanation/Reference:A: Traffic shaping and policing can work in tandem. For example, a good traffic shaping scheme should make it easy for nodes inside the network to detectmisbehaving flows. This activity is sometimes called policing the traffic of the flow.

C: The simplest way to classify a packet is to use behavior aggregate (BA) classification.For a specified interface, you can configure both a multifield classifier and a BA classifier without conflicts. Because the classifiers are always applied in sequentialorder, the BA classifier followed by the multifield classifier, any BA classification result is overridden by a multifield classifier if they conflict.

References: http://www.juniper.net/techpubs/en_US/junos15.1/topics/concept/classifier-ba-overview-cos-config-guide.html

QUESTION 33You have a strict-high queue configured. You notice that under bursty traffic conditions, there are tail drops on the strict-high queue.

Which action would solve this problem?

Page 220: JNCIP-SP JN0-661 · PDF file · 2017-07-29You must ensure that r1's IPv4 loopback address exists in r3 ... redistribute the VPN routes into OSPF. Correct Answer: D ... this route

http://www.gratisexam.com/

A. Assign a policer on ingress to assign a low packet loss priority to the strict-high queue.

B. Decrease the buffer size of the strict-high queue.

C. Assign a policer on egress to assign a low packet loss priority to the strict-high queue.

D. Increase the buffer size of the strict-high queue.

Correct Answer: DSection: CoSExplanation

Explanation/Reference:A queue with strict-high priority is assured unlimited transmission bandwidth but is not actually assigned a large delay buffer. Not configuring a transmit-rate or anexplicit buffer-size on a strict-high priority queue only ensures that the queue gets assigned a default minimum delay buffer, making it possible, under burstyconditions, to see tail-drops on strict-high priority queues. Assigning a small transmit-rate or an explicit temporal or percentage buffer-size to the queue ensures thatthe queue has a large enough buffer to hold bursts and protect against tail-drops.

References: http://www.juniper.net/documentation/en_US/junos15.1/topics/usage-guidelines/cos-configuring-schedulers-for-priority-scheduling.html

QUESTION 34Click on the exhibit

Page 221: JNCIP-SP JN0-661 · PDF file · 2017-07-29You must ensure that r1's IPv4 loopback address exists in r3 ... redistribute the VPN routes into OSPF. Correct Answer: D ... this route

http://www.gratisexam.com/

\

You manage an MX series router (with 100 ms buffer size per port) that includes the configuration shown in the exhibit. Traffic marked with DSCP 000001 isentering the ge-1/0/4 interface at 102 Mbps. The traffic exists the device on the ge-1/0/5 interface. There is no other traffic transiting the router. What happens totraffic exceeding 100 Mbps?

A. Traffic exceeding 100 Mbps is buffered.

B. Traffic exceeding 100 Mbps is dropped.

C. Traffic exceeding 100 Mbps is forwarded.

D. Traffic exceeding 100 Mbps is redirected to a rate limiter.

Correct Answer: ASection: CoSExplanation

Page 222: JNCIP-SP JN0-661 · PDF file · 2017-07-29You must ensure that r1's IPv4 loopback address exists in r3 ... redistribute the VPN routes into OSPF. Correct Answer: D ... this route

http://www.gratisexam.com/

Explanation/Reference:

QUESTION 35Click on the exhibit

Which effect will the policer in the exhibit have on traffic?

http://www.gratisexam.com

A. Traffic will have its PLP changed when throughput exceeds the CIR+CBS, and dropped when throughput exceeds the CIR+EBS

B. Traffic will have its forwarding class changed when the throughput exceeds the CIR+CBS and CIR+EBS.

C. Traffic will have its PLP changed when throughput exceeds the CIR+CBS and CIR+EBS.

D. Traffic will have tis forwarding class changed when throughput exceeds the CIR+EBS.

Correct Answer: CSection: CoSExplanation

Explanation/Reference:

QUESTION 36Click on the exhibit

Page 223: JNCIP-SP JN0-661 · PDF file · 2017-07-29You must ensure that r1's IPv4 loopback address exists in r3 ... redistribute the VPN routes into OSPF. Correct Answer: D ... this route

http://www.gratisexam.com/

Which effect will the policer in the exhibit have on traffic?

A. Traffic will have its forwarding class changed when the throughput exceeds the PIR+PBS.

B. Traffic will have its PLP changed when throughput exceeds the CIR+CBS and PIR+PBS.

C. Traffic will have its forwarding class changed when throughput exceeds the CIR and PIR.

D. Traffic will have its PLP changed when it exceeds the CIR+CBS, and dropped when throughput exceeds the PIR+PBS.

Correct Answer: BSection: CoSExplanation

Explanation/Reference:

QUESTION 37Packets traverse a JUNOS device configured for class of service.

Which two statements are true in this scenario? (Choose two.)

A. Packets are subject to traffic shapers before policers

B. Packets are subject to policers before traffic shapers

C. Packets are processed by behavior aggregate classifiers before multifield classifiers

D. Packets are processed by multifield classifier before behavior aggregate classifiers.

Correct Answer: BCSection: (none)Explanation

Explanation/Reference:

Page 224: JNCIP-SP JN0-661 · PDF file · 2017-07-29You must ensure that r1's IPv4 loopback address exists in r3 ... redistribute the VPN routes into OSPF. Correct Answer: D ... this route

http://www.gratisexam.com/

QUESTION 38A customer's traffic is traversing your network, which consists of JUNOS devices. You must configure class of service for the traffic to meet a service-levelagreement.

In this scenario, which two statements are true? (choose two.)

A. By Default, a packet's loss priority can be either low or high

B. A packet's loss priority can be set using classifiers or rewirte markers

C. By Default, a packet's loss priority can be either low, medium-low, medium-high, or high

D. A packet's loss priority can be set using classifier or policers.

Correct Answer: ADSection: (none)Explanation

Explanation/Reference:

QUESTION 39What is the final component of CoS processing on the JUNOS device?

A. drop profile map

B. behaviour aggregate classifier

C. rewrite marker

D. multifield classifier

Correct Answer: CSection: (none)Explanation

Explanation/Reference:

Page 225: JNCIP-SP JN0-661 · PDF file · 2017-07-29You must ensure that r1's IPv4 loopback address exists in r3 ... redistribute the VPN routes into OSPF. Correct Answer: D ... this route

http://www.gratisexam.com/

IP Multicast

QUESTION 1Which address range has been specifically reserved for use with SSM traffic?

A. 233.0.0.0/8

B. 224.2.0.0/16

C. 232.0.0.0/8

D. 239.0.0.0/8

Correct Answer: CSection: IP MulticastExplanation

Explanation/Reference:Source-Specific Multicast (SSM) Group address range is 224/4, but it is guaranteed only for 232/8.

Reference: https://www.juniper.net/documentation/en_US/junos15.1x49/topics/topic-map/mcast-ssm.html

QUESTION 2Referring to the exhibit, you have a network that uses PIM-SM and you need to block certain PIM register messages.

Which two statements are Correct in this situation? (Choose two.)

Click the Exhibit button.

http://www.gratisexam.com

Exhibit:

A. You should apply a policy that blocks PIM register messages from the source on R4.

B. You should apply a policy that blocks PIM register messages from the source on R3.

C. You should apply a policy that blocks PIM register messages from the source on R2.

D. You should apply a policy that blocks PIM register messages from the source on R1.

Page 226: JNCIP-SP JN0-661 · PDF file · 2017-07-29You must ensure that r1's IPv4 loopback address exists in r3 ... redistribute the VPN routes into OSPF. Correct Answer: D ... this route

http://www.gratisexam.com/

Correct Answer: ADSection: IP MulticastExplanation

Explanation/Reference:You can filter Protocol Independent Multicast (PIM) register messages sent from the designated router (DR) or to the rendezvous point (RP).

Note: In a shared tree, the root of the distribution tree is a router, not a host, and is located somewhere in the core of the network. In the primary sparse mode multicast routing protocol, Protocol Independent Multicast sparse mode (PIM SM), the core router at the root of the shared tree is the rendezvous point (RP).

Reference: http://www.juniper.net/documentation/en_US/junos15.1/topics/example/ospf-designated-router-election-configuring.html

QUESTION 3Click the exhibit button.

[edit protocols pim] user@R1# show

rp { bootstrap { family inet { priority 250; } } local { address 10.220.1.1; priority 1; group-ranges { 224.1.1.11/32; 224.0.0.0/4; } } } interface all; interface fxp0.0 { disable; }

[edit protocols pim]

Page 227: JNCIP-SP JN0-661 · PDF file · 2017-07-29You must ensure that r1's IPv4 loopback address exists in r3 ... redistribute the VPN routes into OSPF. Correct Answer: D ... this route

http://www.gratisexam.com/

user@R4# show

rp { bootstrap { family inet { priority 249; } } local { address 10.220.1.4; priority 5; group-ranges { 224.1.1.12/32; 224.0.0.0/4; } } } interface all; interface fxp0.0 { disable; }

Referring to the exhibit, which router will be the RP?

A. R4 for all groups

B. R1 for group 224.1.1.11 and R4 for all other groups

C. R1 for all groups

D. R4 for group 224.1.1.12 and R1 for all other groups

Correct Answer: ASection: IP MulticastExplanation

Explanation/Reference:The bootstrap router uses this field when selecting the list of candidate rendezvous points to send in the bootstrap message. A smaller number increases thelikelihood that the routing device or RP address becomes the RP. A priority value of 0 means that bootstrap router can override the group range being advertised bythe candidate RP.

number—Priority for becoming an RP. A lower value corresponds to a higher priority.

Page 228: JNCIP-SP JN0-661 · PDF file · 2017-07-29You must ensure that r1's IPv4 loopback address exists in r3 ... redistribute the VPN routes into OSPF. Correct Answer: D ... this route

http://www.gratisexam.com/

References:

https://www.juniper.net/documentation/en_US/junos/topics/reference/configuration-statement/priority-edit-protocols-pim-local.html

https://www.juniper.net/documentation/en_US/junos/topics/topic-map/mcast-static-rp.html

QUESTION 4Click the Exhibit.

Referring to the exhibit, which type of NG MVPN route will be advertised by PE2 to PE1?

A. Shared Tree Join C-Multicast route

B. Source Tree Join C-Multicast route

C. Source Active Auto-discovery route

D. Leaf Auto-discovery route

Correct Answer: ASection: IP MulticastExplanation

Explanation/Reference:Shared tree join route

Page 229: JNCIP-SP JN0-661 · PDF file · 2017-07-29You must ensure that r1's IPv4 loopback address exists in r3 ... redistribute the VPN routes into OSPF. Correct Answer: D ... this route

http://www.gratisexam.com/

• Originated by receiver PE routers. • Originated when a PE receives a shared tree C-join (C-*, C-G) through its PE-CE interface.

If the C-join received over a VPN interface is a source tree join (C-S, C-G), then the receiver PE simply originates a Type 7 route (Step 7 below). If the C-join is ashared tree join (C-*, C-G), then the receiver PE needs to go through a few steps (Steps 1-7) before originating a Type 7 route.

Source tree join route• Originated by receiver PE routers. • Originated when a PE receives a source tree C-join (C-S, C-G) or originated by the PE that already has a Type 6 route and receives a Type 5 route.

If the C-join received over a VPN interface is a source tree join (C-S, C-G), then the receiver PE simply originates a Type 7 route (Step 7 below). If the C-join is ashared tree join (C-*, C-G), then the receiver PE needs to go through a few steps (Steps 1-7) before originating a Type 7 route.

Source Trees Versus Shared TreesBoth source trees and shared trees are loop-free. Messages are replicated only where the tree branches.Members of multicast groups can join or leave at any time; therefore the distribution trees must be dynamically updated. When all the active receivers on a particularbranch stop requesting the traffic for a particular multicast group, the routers prune that branch from the distribution tree and stop forwarding traffic down thatbranch. If one receiver on that branch becomes active and requests the multicast traffic, the router will dynamically modify the distribution tree and start forwardingtraffic again.

Source trees have the advantage of creating the optimal path between the source and the receivers. This advantage guarantees the minimum amount of networklatency for forwarding multicast traffic. However, this optimization comes at a cost: The routers must maintain path information for each source. In a network thathas thousands of sources and thousands of groups, this overhead can quickly become a resource issue on the routers. Memory consumption from the size of themulticast routing table is a factor that network designers must take into consideration.

Shared trees have the advantage of requiring the minimum amount of state in each router. This advantage lowers the overall memory requirements for a networkthat only allows shared trees. The disadvantage of shared trees is that under certain circumstances the paths between the source and receivers might not be theoptimal paths, which might introduce some latency in packet delivery. For example, in Figure 12, the shortest path between Host A (source 1) and Host B (areceiver) would be Router A and Router C. Because we are using Router D as the root for a shared tree, the traffic must traverse Routers A, B, D and then C.Network designers must carefully consider the placement of the rendezvous point (RP) when implementing a shared tree-only environment.

References: https://kb.juniper.net/library/CUSTOMERSERVICE/GLOBAL_JTAC/technotes/2000320-en.pdf

http://www.cisco.com/c/en/us/td/docs/ios/solutions_docs/ip_multicast/White_papers/mcst_ovr.html#wp1009024

QUESTION 5You are asked to configure PIM-SM in your network.

Your implementation must allow for load sharing between redundant RPs and, should an RP failure occur, the RP failover time should be minimized.

Which two configuration tasks are required in this scenario? (Choose two.)

Page 230: JNCIP-SP JN0-661 · PDF file · 2017-07-29You must ensure that r1's IPv4 loopback address exists in r3 ... redistribute the VPN routes into OSPF. Correct Answer: D ... this route

http://www.gratisexam.com/

A. Configure MSDP peering sessions between the routers designated as RPs.

B. Configure at least two static RPs and bundle them in an RP redundancy group under [edit protocols pim].

C. On the routers designated as RPs, configure the shared anycast address on the loopback interface.

D. Configure the shared anycast address on the RPs as the primary address on the loopback interface.

Correct Answer: BDSection: IP MulticastExplanation

Explanation/Reference:For the purposes of load balancing and redundancy, you can configure anycast RP. You can use anycast RP within a domain to provide redundancy and RP loadsharing.

Anycast means that multiple RP routers share the same unicast IP address.

D: On each RP router in the domain, make sure that the router's regular loopback address is the primary address for the interface, and set the router ID.

B: On each non-RP router in the domain, configure a static RP address using the shared address.

Example: [edit protocols pim] user@host# set rp static address 10.1.1.2

Reference: http://www.juniper.net/techpubs/en_US/junos14.1/topics/topic-map/mcast-pim-anycast-rp.html

QUESTION 6Click the Exhibit button.

RP1 and RP2 are acting as PIM-SM rendezvous points (Rps) in their autonomous system. Referring to the diagram, which purpose does the MSDP sessionbetween RP1 and RP2 serve?

Page 231: JNCIP-SP JN0-661 · PDF file · 2017-07-29You must ensure that r1's IPv4 loopback address exists in r3 ... redistribute the VPN routes into OSPF. Correct Answer: D ... this route

http://www.gratisexam.com/

A. MSDP allows RPs in different PIM domains to advertise any active multicast receivers to each other.

B. MSDP allows RPs in different PIM domains to advertise any active multicast sources to each other.

C. MSDP routes are used by an RP for reverse path forwarding lookups when milticast sources exist in different autonomous systems.

D. MSDP allows RPs in different PIM domains to form PIM neighbor relationship with each other.

Correct Answer: BSection: IP MulticastExplanation

Explanation/Reference:The Multicast Source Discovery Protocol (MSDP) is used to connect multicast routing domains.

It typically runs on the same router as the Protocol Independent Multicast (PIM) sparse-mode rendezvous point (RP).

Each MSDP router establishes adjacencies with internal and external MSDP peers similar to the way BGP establishes peers. These peer routers inform each otherabout active sources within the domain. When they detect active sources, the routers can send PIM sparse-mode explicit join messages to the active source.

Reference: http://www.juniper.net/techpubs/en_US/junos15.1/topics/concept/multicast-msdp-overview.html

QUESTION 7Which two statements are associated with any-source multicast? (Choose two.)

A. Routes learn the source of the multicast traffic from the source address of the multicast traffic.

B. Routes learn the source of the multicast traffic from the receives.

C. Routes do not specify a specific source from which to receive traffic.

D. Receives select a specific source from which to receive traffic.

Correct Answer: ACSection: IP MulticastExplanation

Explanation/Reference:An any-source multicast (ASM) network must be able to determine the locations of all sources for a particular multicast group whenever there are interestedlisteners, no matter where the sources might be located in the network. In ASM, the key function of source discovery is a required function of the network itself.

Multicast source discovery appears to be an easy process, but in sparse mode it is not. In dense mode, it is simple enough to flood traffic to every router in thenetwork so that every router learns the source address of the content for that multicast group.

Reference: https://www.juniper.net/documentation/en_US/junos13.3/topics/topic-map/mcast-mvpns-draft-rosen-6.html

Page 232: JNCIP-SP JN0-661 · PDF file · 2017-07-29You must ensure that r1's IPv4 loopback address exists in r3 ... redistribute the VPN routes into OSPF. Correct Answer: D ... this route

http://www.gratisexam.com/

QUESTION 8You are using PIM-SM in your network and want to ensure that all available equal-cost paths are being used for multicast traffic.

Referring to the exhibit, where must you configure the PIM join-load-balance parameter to achieve this goal?

Click the Exhibit button.

Exhibit:

A. R2, R4, and R5

B. R1, R2, R4, and R5

C. R4

D. R4 and R5

Correct Answer: CSection: IP MulticastExplanation

Explanation/Reference:Incorrect Answers:A, B: R2 is the RP. You configure PIM join load balancing on the non-RP routers in the PIM domain.

Reference: http://www.juniper.net/documentation/en_US/junos15.1/topics/task/configuration/mcast-pim-join-load-balance.html

QUESTION 9Which two statements describe the benefits of using point-to-multipoint LSPs in an environment with MVPNs? (Choose two.)

A. Performance levels within the LSPs can be guaranteed, regardless of the signaling protocol used.

B. A service provider network does not need to run PIM to support multicast routing.

C. Data replication can be done by downstream LSRs and not just by the ingress PE router.

D. Multicast traffic can be protected, regardless of the signaling protocol used.

Correct Answer: BCSection: IP MulticastExplanation

Explanation/Reference:

QUESTION 10

Page 233: JNCIP-SP JN0-661 · PDF file · 2017-07-29You must ensure that r1's IPv4 loopback address exists in r3 ... redistribute the VPN routes into OSPF. Correct Answer: D ... this route

http://www.gratisexam.com/

You are asked to configure auto-RP as part of a new PIM sparse mode deployment in your network. Which two configuration tasks are required? (Choose two.)

http://www.gratisexam.com

A. All RP routers must be configured with the mapping auto-RP role.

B. All RP routers must be configured with the discovery auto-RP role.

C. All non-RP routers must be configured with the mapping auto-RP role.

D. All non-RP routers must be configured with the discovery auto-RP role.

Correct Answer: ADSection: IP MulticastExplanation

Explanation/Reference:

QUESTION 11You have configured PIM dense mode on your network. One of your PIM-enabled routers is not in the path of the source-based tree between the source and thereceivers, and has no need for the multicast traffic. Which behavior would you expect from that router?

A. The router will send register stop messages to the RP.

B. The router will send prune messages to its upstream router.

C. The router will send assert messages to the RP.

D. The router will send graft messages to its upstream router.

Correct Answer: BSection: IP MulticastExplanation

Explanation/Reference:

QUESTION 12You have established an MSDP peering between multicast domains for your AS and a neighboring AS. You are concerned about unnecessary flooding or looping ofsource active messages between MSDP peers. Which MSDP mechanism is used to prevent this problem?

Page 234: JNCIP-SP JN0-661 · PDF file · 2017-07-29You must ensure that r1's IPv4 loopback address exists in r3 ... redistribute the VPN routes into OSPF. Correct Answer: D ... this route

http://www.gratisexam.com/

A. The receiving MSDP peer performs a multicast RPF check to ensure that the SA messages are forwarded away from only the originating multicast source.

B. The receiving MSDP peer sends register-stop messages towards the originating RP that forwarded the SA messages.

C. The receiving MSDP peer performs a multicast peer-RPF check to ensure that the SA messages are forwarded away from only the originating RP.

D. The receiving MSDP peer sends prune messages to all upstream neighbors to avoid receiving additional SA messages.

Correct Answer: CSection: IP MulticastExplanation

Explanation/Reference:

QUESTION 13You are deploying a next-generation multicast VPN in your network and must identify which routers require tunnel services?

A. DRs closest to the receiver require tunnel services.

B. DRs closest to the source require tunnel services.

C. All MVPN PE routers require tunnel services.

D. All MVPN P routers require tunnel services.

Correct Answer: CSection: IP MulticastExplanation

Explanation/Reference:

QUESTION 14You are asked to configure auto-RP as part of a new PIM sparse mode deployment in your network.

Which two configuration tasks are required? (Choose two.)

A. Configure MSDP peering sessions between all RP candidates.

B. Configure PIM sparse-dense mode on all interfaces.

C. Configure IGMP version 2 on all routers.

D. Configure the appropriate auto-RP role on all routers.

Correct Answer: BD

Page 235: JNCIP-SP JN0-661 · PDF file · 2017-07-29You must ensure that r1's IPv4 loopback address exists in r3 ... redistribute the VPN routes into OSPF. Correct Answer: D ... this route

http://www.gratisexam.com/

Section: IP MulticastExplanation

Explanation/Reference:

QUESTION 15You are asked to implement PIM-SM in your network, which consists of equipment from multiple vendors.

You must configure multiple RP discovery methods in this environment for redundancy purposes.MSDP cannot be used.

Which two statements are true? (Choose two.)

A. If you configure a static RP and auto-RP, auto-RP will be preferred and used by all routers.

B. If you configure a static RP and a BSR, the BSR will be preferred and used by all routers.

C. Auto-RP can be used to provide RP failover and load sharing between the elected RPs.

D. The BSR can be used to provide RP failover and load sharing between the elected RPs.

Correct Answer: BDSection: IP MulticastExplanation

Explanation/Reference:

QUESTION 16You are using the 224.2.0.0/16 multicast address range for SSM applications in your network. However, since you have deployed SSM in your network, SAP/SDPapplication communications have not been functioning properly.

What must you do to allow the SSM and SAP/SDP applications to function properly?

A. Use the 232.0.0.0/3 address range for SAP/SDP applications.

B. Use the 232.0.0.0/B address range for SSM applications.

C. Use the 224.1.0.0/16 address range for SAP/SDP applications.

D. Use the 224.1.0.0/16 address range for SSM applications

Correct Answer: BSection: IP MulticastExplanation

Page 236: JNCIP-SP JN0-661 · PDF file · 2017-07-29You must ensure that r1's IPv4 loopback address exists in r3 ... redistribute the VPN routes into OSPF. Correct Answer: D ... this route

http://www.gratisexam.com/

Explanation/Reference:

QUESTION 17Refer to the exhibit.

Page 237: JNCIP-SP JN0-661 · PDF file · 2017-07-29You must ensure that r1's IPv4 loopback address exists in r3 ... redistribute the VPN routes into OSPF. Correct Answer: D ... this route

http://www.gratisexam.com/

Page 238: JNCIP-SP JN0-661 · PDF file · 2017-07-29You must ensure that r1's IPv4 loopback address exists in r3 ... redistribute the VPN routes into OSPF. Correct Answer: D ... this route

http://www.gratisexam.com/

Multicast traffic from 192.168.25.6 to 228.0.0.0/8 is entering the router on xe-3/1/0. Which statement is correct?

A. The reverse-path forwarding lookup will succeed without these policies because of a default route.

B. The traffic to 228.0.0.0/3 will be rejected.

C. The traffic from 192.168.25.6 will be rejected.

D. The reverse-path forwarding lookup will fail without these policies.

Correct Answer: DSection: IP MulticastExplanation

Explanation/Reference:

QUESTION 18You have recently deployed PIM-SM in your network and must control some of the associated protocol exchanges.

Which three statements are true? (Choose three.)

A. Policy can be used to control outgoing register messages at the source RP.

B. Policy can be used to control outgoing register messages at the source DR.

C. Policy can be used to control incoming register messages at the RP.

D. Policy can be used to control incoming register messages at the DR.

E. Policy can be used to control incoming and outgoing join and prune messages.

Correct Answer: BCESection: IP MulticastExplanation

Explanation/Reference:

QUESTION 19Click the Exhibit button

Page 239: JNCIP-SP JN0-661 · PDF file · 2017-07-29You must ensure that r1's IPv4 loopback address exists in r3 ... redistribute the VPN routes into OSPF. Correct Answer: D ... this route

http://www.gratisexam.com/

Given the topology in the exhibit, which two requirements must be met to allow multicast traffic to flow from AS65001 to AS65002? (Choose two.)

A. MSDP sessions must exist between all routers in AS65001.

B. Source information must be relayed from AS65001 to AS65002.

C. A full mesh of MBGP peering sessions must be formed within AS65001.

D. A TCP session must be formed between the RPs in AS65001 andAS65002.

Correct Answer: BDSection: IP MulticastExplanation

Explanation/Reference:

QUESTION 20You recently implemented an MSDP mesh group within your PIM-SM domain. Which two new behaviors can you expect? (Choose two.)

A. SA messages from peer ASs will now be received.

B. SA messages from group members will now require a peer-RPF check.

C. SA messages will no longer be forwarded to other members in the group.

D. SA messages from group members will no longer require a peer-RPF check.

Correct Answer: CD

Page 240: JNCIP-SP JN0-661 · PDF file · 2017-07-29You must ensure that r1's IPv4 loopback address exists in r3 ... redistribute the VPN routes into OSPF. Correct Answer: D ... this route

http://www.gratisexam.com/

Section: IP MulticastExplanation

Explanation/Reference:

QUESTION 21In an interdomain multicast deployment scenario, RP1 is in AS1 and RP2 is in AS2. MSDP is configured between RP1 and RP2 A source in AS1 and a receiver inAS2 have just become active. What initially triggers RP1 to send source-active messages (SAs) to RP2?

A. A join-to-RP message is sent from RP2 to RP1.

B. A join-to-source message is sent from RP2 to RP1

C. A register message is received on RP1.

D. A register message is received on RP2.

Correct Answer: CSection: IP MulticastExplanation

Explanation/Reference:

QUESTION 22Click the Exhibit button.

Page 241: JNCIP-SP JN0-661 · PDF file · 2017-07-29You must ensure that r1's IPv4 loopback address exists in r3 ... redistribute the VPN routes into OSPF. Correct Answer: D ... this route

http://www.gratisexam.com/

In the exhibit, all routers within each AS are configured for Anycast RP. All intra-AS routers are configured within the same MSDP mesh group. Inter-AS multicasthas been enabled using MSDP without MSDP mesh groups. Which statement is true?

A. R6 and R7 should have an MSDP peering, because multiple MSDP AS hops are not allowed.

B. SA messages received from R2 are not forwarded to R5, R7, and R8.

C. SA messages from R5 are not forwarded to AS1.

D. Duplicate SA messages may be received in AS2.

Correct Answer: DSection: IP MulticastExplanation

Explanation/Reference:

QUESTION 23Click the Exhibit button.

Page 242: JNCIP-SP JN0-661 · PDF file · 2017-07-29You must ensure that r1's IPv4 loopback address exists in r3 ... redistribute the VPN routes into OSPF. Correct Answer: D ... this route

http://www.gratisexam.com/

In the exhibit, NG-MVPN is used for a Layer 3 VPN. Which two statements are valid? (Choose two.)

http://www.gratisexam.com

A. The egress PEs for I-PMSI tunnels should signal a label value of 3.

B. The vrf-table-label parameter is configured on the PEs.

C. PIM must be enabled on the PE and P routers.

D. The provider tunnel shown is similar to a draft-Rosen default MDT.

Correct Answer: BDSection: IP MulticastExplanation

Explanation/Reference:

QUESTION 24Click the Exhibit button.

Page 243: JNCIP-SP JN0-661 · PDF file · 2017-07-29You must ensure that r1's IPv4 loopback address exists in r3 ... redistribute the VPN routes into OSPF. Correct Answer: D ... this route

http://www.gratisexam.com/

In the exhibit, R2 and R3 are both rendezvous points. Assume that R2 fails. Which RP redundancy method could converge the multicast stream and RP as quicklyas the IGP?

A. BSR without the use of MSDP

B. Anycast RP and MSDP

C. Auto-RP in combination with MSDP

D. Auto-RP without using MSDP

Correct Answer: BSection: IP MulticastExplanation

Explanation/Reference:

QUESTION 25Click the Exhibit button.

Page 244: JNCIP-SP JN0-661 · PDF file · 2017-07-29You must ensure that r1's IPv4 loopback address exists in r3 ... redistribute the VPN routes into OSPF. Correct Answer: D ... this route

http://www.gratisexam.com/

Page 245: JNCIP-SP JN0-661 · PDF file · 2017-07-29You must ensure that r1's IPv4 loopback address exists in r3 ... redistribute the VPN routes into OSPF. Correct Answer: D ... this route

http://www.gratisexam.com/

Given the output in the exhibit, which three statements are correct? (Choose three.)

A. PIM spare-dense mode is used.

B. PIM sparse mode is used.

C. The receiver and source 10.255.70.15 are on the shortest path tree.

D. The receiver and source 10.255.70.15 are on the shared tree.

E. The receiver and RP are on the shortest path tree.

Correct Answer: BCESection: IP MulticastExplanation

Explanation/Reference:

QUESTION 26The network design team has decided to activate multicast in the network. Auto-RP has been selected as the RP mechanism. Which PIM operational mode must beenabled in this network?

A. sparse mode

B. sparse-dense mode

C. dense mode

D. source specific multicast

Correct Answer: BSection: IP MulticastExplanation

Explanation/Reference:

QUESTION 27Click the Exhibit button.

Page 246: JNCIP-SP JN0-661 · PDF file · 2017-07-29You must ensure that r1's IPv4 loopback address exists in r3 ... redistribute the VPN routes into OSPF. Correct Answer: D ... this route

http://www.gratisexam.com/

A customer has the configuration shown in the exhibit applied to the VRF C-PIM domain. What can you determine from this configuration?

A. The PE is configured for selective PMSI (S-PMSI) only.

B. The C-RP is collocated on one of the PEs in the MVPN.

C. The MVPN is not working because the receiver-site command is missing.

D. Multicast traffic will not switch to the S-PMSI because the vpn-group-address command (data MDT) is missing.

Correct Answer: BSection: IP MulticastExplanation

Explanation/Reference:

Page 247: JNCIP-SP JN0-661 · PDF file · 2017-07-29You must ensure that r1's IPv4 loopback address exists in r3 ... redistribute the VPN routes into OSPF. Correct Answer: D ... this route

http://www.gratisexam.com/

QUESTION 28Click the Exhibit button.

user@router# show routing-options multicastscope 1 { prefix 224.0.1.39/32; interface fe-0/0/0.0;}

Referring to the exhibit, which statement is correct?

A. Only multicasts packets (224.0.1.39) are allowed on the input and output direction.

B. Auto-RP discovery messages are filtered in the input and output direction.

C. Rendezvous point announcements are filtered in the output direction.

D. This filter does not work because the input or output parameter is missing.

Correct Answer: CSection: IP MulticastExplanation

Explanation/Reference:

QUESTION 29Click the Exhibit button.

Page 248: JNCIP-SP JN0-661 · PDF file · 2017-07-29You must ensure that r1's IPv4 loopback address exists in r3 ... redistribute the VPN routes into OSPF. Correct Answer: D ... this route

http://www.gratisexam.com/

In the exhibit, what happens if the source starts sending multicast traffic toward R1 and there are receivers registered at the RP?

A. R1 encapsulates the multicast packets into a PIM register multicast packet.

B. R1 encapsulates the multicast packets into PIM join unicast messages.

C. R1 forwards the multicast packets on the S,G tree towards the RP.

D. R1 tunnels the multicast packets in PIM register messages toward the RP.

Correct Answer: DSection: IP MulticastExplanation

Explanation/Reference:

QUESTION 30In an interdomain multicast deployment scenario, an RP1 is in AS1 and an RP2 is in AS2. MSDP is configured between RP1 and RP2.In which routing table on RP1are source-active messages (SAs) received from RP2 by default?

A. inet.0

B. inet.2

C. inet.1

D. inet.4

Correct Answer: DSection: IP MulticastExplanation

Explanation/Reference:

QUESTION 31Click the Exhibit button.

Page 249: JNCIP-SP JN0-661 · PDF file · 2017-07-29You must ensure that r1's IPv4 loopback address exists in r3 ... redistribute the VPN routes into OSPF. Correct Answer: D ... this route

http://www.gratisexam.com/

A customer is using the Layer 3 VPN multicast technology shown in the exhibit. Which statement is true?

A. PE6 sends a BGP NG-MVPN NLRI Type 5 message upon receiving a *,G join on its VRF interface.

B. PE6 sends a BGP NG-MVPN NLRI Type 7 message upon receiving an S,G join on its VRF interface.

C. The P2MP sub LSP reduces the traffic load on the interface between PE2 and PE5.

D. PE6 signals PE2 through MBGP to include the I-PMSI tree on its P2MP sub LSP.

Correct Answer: BSection: IP MulticastExplanation

Explanation/Reference:

QUESTION 32Which statement is true about ASM and/ or SSM multicast?

A. ASM requires an external mechanism to find the source.

B. SSM only builds RPT trees, since the RP is replaced by an external mechanism.

C. ASM and SSM for IPv6 multicast use embedded RP.

D. SSM does not require MSDP.

Correct Answer: DSection: IP MulticastExplanation

Page 250: JNCIP-SP JN0-661 · PDF file · 2017-07-29You must ensure that r1's IPv4 loopback address exists in r3 ... redistribute the VPN routes into OSPF. Correct Answer: D ... this route

http://www.gratisexam.com/

Explanation/Reference:

QUESTION 33Your multicast receivers are indirectly connected to an MX Series router. The receivers need to join multicast group 224.2.2.2. What must be configured in IGMP toreceive report messages from receivers that are multiple hops away?

A. By default, IGMP accepts report messages from indirectly connected receivers.

B. Promiscuous mode must be enabled in IGMP.

C. Promiscuous mode must be disabled in IGMP.

D. DVMRP protocol must be configured.

Correct Answer: BSection: IP MulticastExplanation

Explanation/Reference:

QUESTION 34You need to ensure that your high-priority traffic uses the best-possible route while your best-effort traffic uses a lower preference route. You want to use CoS-basedforwarding to use the DSCP values of the different types of traffic to assign the LSP that should be used for the next hop.

Which three additions must be made to the configuration to satisfy the requirement? (Choose three.)

A. a class-of-service forwarding policy

B. a policy statement for LSP next-hop selection

C. an important policy applied to the forwarding table

D. an export policy applied to the forwarding table

E. a multifield firewall filter for LSP next-hop selection

Correct Answer: ADESection: IP MulticastExplanation

Explanation/Reference:D: The final step is to apply the route filter to routes exported to the forwarding engine. This is shown in the following example:routing-options { forwarding-table { export my-cos-forwarding;

Page 251: JNCIP-SP JN0-661 · PDF file · 2017-07-29You must ensure that r1's IPv4 loopback address exists in r3 ... redistribute the VPN routes into OSPF. Correct Answer: D ... this route

http://www.gratisexam.com/

}}This configuration instructs the routing process to insert routes to the forwarding engine matching my-cos-forwarding with the associated next-hop CBF rules.

A: Assigning Forwarding Class and DSCP Value for Routing Engine-Generated Traffic You can set the forwarding class and differentiated service code point(DSCP) value for traffic originating in the Routing Engine. To configure forwarding class and DSCP values that apply to Routing Engine–generated traffic only, applyan output filter to the loopback (lo.0) interface and set the appropriate forwarding class and DSCP bit configuration for various protocols.

E: The following example assigns Routing Engine sourced ping packets (using ICMP) a DSCP value of 38 and a forwarding class of af17, OSPF packets a DSCPvalue of 12 and a forwarding class of af11, and BGP packets (using TCP ) a DSCP value of 10 and a forwarding class of af16.

[edit class-of-service]forwarding-classes { class af11 queue-num 7; class af12 queue-num 1; class af13 queue-num 2; class af14 queue-num 4; class af15 queue-num 5; class af16 queue-num 4; class af17 queue-num 6; class af18 queue-num 7;}[edit firewall filter family inet]filter loopback-filter { term t1 { from { protocol icmp; # For pings } then { forwarding-class af17; dscp 38; } } term t2 { from { protocol ospf; # For OSPF } then { forwarding-class af11; dscp 12; } }}

Page 252: JNCIP-SP JN0-661 · PDF file · 2017-07-29You must ensure that r1's IPv4 loopback address exists in r3 ... redistribute the VPN routes into OSPF. Correct Answer: D ... this route

http://www.gratisexam.com/

Etc.

References: https://www.juniper.net/techpubs/en_US/junos16.1/topics/usage-guidelines/cos-assigning-fc-dscp-to-re-pkts.htmlhttp://www.juniper.net/techpubs/en_US/junos13.3/information-products/pathway-pages/cos/forwarding-classes.pdf (page 42)

QUESTION 35Which two statements are associated with any-source multicast? (Choose two.)

http://www.gratisexam.com

A. Routes learn the source of the multicast traffic from the source address of the multicast traffic.

B. Routes learn the source of the multicast traffic from the receives.

C. Routes do not specify a specific source from which to receive traffic.

D. Receives select a specific source from which to receive traffic.

Correct Answer: ACSection: IP MulticastExplanation

Explanation/Reference:An any-source multicast (ASM) network must be able to determine the locations of all sources for a particular multicast group whenever there are interestedlisteners, no matter where the sources might be located in the network. In ASM, the key function of source discovery is a required function of the network itself.Multicast source discovery appears to be an easy process, but in sparse mode it is not. In dense mode, it is simple enough to flood traffic to every router in thenetwork so that every router learns the source address of the content for that multicast group.

References: https://www.juniper.net/documentation/en_US/junos13.3/topics/topic-map/mcast-mvpns-draft-rosen-6.html

QUESTION 36You are using PIM-SM in your network and want to ensure that all available equal-cost paths are being used for multicast traffic.

Referring to the exhibit, where must you configure the PIM join-load-balance parameter to achieve this goal?

Click the Exhibit button.

Exhibit:

A. R2, R4, and R5

Page 253: JNCIP-SP JN0-661 · PDF file · 2017-07-29You must ensure that r1's IPv4 loopback address exists in r3 ... redistribute the VPN routes into OSPF. Correct Answer: D ... this route

http://www.gratisexam.com/

B. R1, R2, R4, and R5

C. R4

D. R4 and R5

Correct Answer: DSection: IP MulticastExplanation

Explanation/Reference:Incorrect Answers:A, B: R2 is the RP. You configure PIM join load balancing on the non-RP routers in the PIM domain.

References: http://www.juniper.net/documentation/en_US/junos15.1/topics/task/configuration/mcast-pim-join-load-balance.html

QUESTION 37Click on the exhibit

Page 254: JNCIP-SP JN0-661 · PDF file · 2017-07-29You must ensure that r1's IPv4 loopback address exists in r3 ... redistribute the VPN routes into OSPF. Correct Answer: D ... this route

http://www.gratisexam.com/

Page 255: JNCIP-SP JN0-661 · PDF file · 2017-07-29You must ensure that r1's IPv4 loopback address exists in r3 ... redistribute the VPN routes into OSPF. Correct Answer: D ... this route

http://www.gratisexam.com/

Page 256: JNCIP-SP JN0-661 · PDF file · 2017-07-29You must ensure that r1's IPv4 loopback address exists in r3 ... redistribute the VPN routes into OSPF. Correct Answer: D ... this route

http://www.gratisexam.com/

In a single-domain multicast deployment a centrally located router is chosen as RP. However, the administrator wants to control source registration messagesreceived on the RP to secure it from registration message storms caused by untrusted sources. Which of the options in the exhibit will accomplish this on the RP?

A. Option B

B. Option C

C. Option D

D. Option A

Correct Answer: DSection: IP MulticastExplanation

Explanation/Reference:

QUESTION 38Click on the exhibit

Page 257: JNCIP-SP JN0-661 · PDF file · 2017-07-29You must ensure that r1's IPv4 loopback address exists in r3 ... redistribute the VPN routes into OSPF. Correct Answer: D ... this route

http://www.gratisexam.com/

In the exhibit, R4 is on the RPT for group 224.224.1.2. R2 is the rendezvous point. Which event could initiate R4 switching from RPT to SPT?

A. R4 received a PIM join message (192.168.1.1, 224.224.1.2) from R3

B. R3 sent a PIM join message (192.168.1.1, 224.224.1.2) towards R2

C. R1 sent a PIM join message (192.168.1.1, 224.224.1.2) to R2

D. R1 sent a PIM register message (192.168.1.1, 224.224.1.2) to R2

Correct Answer: ASection: IP MulticastExplanation

Explanation/Reference:

QUESTION 39Click on the exhibit

Referring to the exhibit, what confirms that graceful restart is turned on for protocol PIM?

Page 258: JNCIP-SP JN0-661 · PDF file · 2017-07-29You must ensure that r1's IPv4 loopback address exists in r3 ... redistribute the VPN routes into OSPF. Correct Answer: D ... this route

http://www.gratisexam.com/

A. The Hello Option LAN Prune Delay bit in the options field

B. The Bidirectional Capable bit in the options field

C. The Generation Identifier bit in the options field

D. The Hello Option DR Priority bit in the options field

Correct Answer: CSection: IP MulticastExplanation

Explanation/Reference:

QUESTION 40Which address range has been specifically reserved for use with SSM traffic?

A. 233.0.0.0/8

B. 224.2.0.0/16

C. 232.0.0.0/8

D. 239.0.0.0/8

Correct Answer: CSection: (none)Explanation

Explanation/Reference:

QUESTION 41You are asked to configure PIM-SM in your network. Your implementation must allow for load sharing between redundant RPs and should an RP failure occur, theRP failover time should be minimized.

A. Configure MSDP peering sessions between the routers designated as RPs.

B. Configure at least two static RPs and bundle them in an RP redundancy group under [edit protocols pim]

C. On the routers designed as RPs, configure the shared anycast address on the loopback interface.

D. Configure the shared anycast on the RPs as the primary address on the loopback interface.

Correct Answer: ACSection: (none)Explanation

Page 259: JNCIP-SP JN0-661 · PDF file · 2017-07-29You must ensure that r1's IPv4 loopback address exists in r3 ... redistribute the VPN routes into OSPF. Correct Answer: D ... this route

http://www.gratisexam.com/

Explanation/Reference:

QUESTION 42You are using PIM-SM in your network and want to ensure that all available equal-cost paths are being used for multicast traffic.

Referring to the exhibit, where must you configure the PIM join-load-balance parameter to achieve this goal?

Click the exhibit button.

Exhibit:

A. R2, R4, and R5

B. R1, R2, R4, and R5

C. R4

D. R4 and R5

Correct Answer: DSection: (none)Explanation

Explanation/Reference:

QUESTION 43Which statement are true about NG MVPNs? (Choose two.)

A. NG MVPN membership is signaled between PEs using PIM

B. Every NG MVPN PE router builds a selective provider multicast service interface tunnel to every other router in the same NG MVPN

C. NG MVPN membership is signaled between PEs using MP-BGP

D. Customer multicast traffic can be transported over the provider network using point-to-multipoint MPLS LSPs.

Correct Answer: CDSection: (none)Explanation

Explanation/Reference:Inter-AS MVPN Membership Discovery (Type 2 Routes), via BGP MCAST-VPN address family, are used for membership discovery between PE routers that belongto different autonomous systems (ASs).

Page 260: JNCIP-SP JN0-661 · PDF file · 2017-07-29You must ensure that r1's IPv4 loopback address exists in r3 ... redistribute the VPN routes into OSPF. Correct Answer: D ... this route

http://www.gratisexam.com/

The service provider uses RSVP-TE point-to-multipoint LSPs for transmitting VPNmulticast data across the network.

Reference: Technology Overview, Understanding Junos OS Next-Generation Multicast VPN, pages 2, 8

https://www.juniper.net/techpubs/en_US/release-independent/nce/information-products/topic-collections/nce/nce0090-ng-mvpn-understanding/ng-mvpn-understanding.pdf

QUESTION 44You need to ensure that your high-priority traffic uses the best-possible route while your best-effort traffic uses a lower preference route. You want to use CoS-basedforwarding to use the DSCP values of the different types of traffic to assign the LSP that should be used for the next hop.

Which three additions must be made to the configuration to satisfy the requirement? (Choose three.)

A. a class-of-service forwarding policy

B. a policy statement for LSP next-hop selection

C. an import policy applied to the forwarding table

D. an export policy applied to the forwarding table

E. a multifield firewall filter for LSP next-hop selection

Correct Answer: ADESection: (none)Explanation

Explanation/Reference:

QUESTION 45

Referring to the exhibit, you have a network that uses PIM-SM and you need to block certain PIM register messages.

Which two statements are correct in this situation? (Choose two.)

A. You should apply a policy that blocks PIM register messages from the source on R4.

B. You should apply a policy that blocks PIM register messages from the source on R3.

Page 261: JNCIP-SP JN0-661 · PDF file · 2017-07-29You must ensure that r1's IPv4 loopback address exists in r3 ... redistribute the VPN routes into OSPF. Correct Answer: D ... this route

http://www.gratisexam.com/

C. You should apply a policy that blocks PIM register messages from the source on R2.

D. You should apply a policy that blocks PIM register messages from the source on R1.

Correct Answer: ADSection: (none)Explanation

Explanation/Reference:

QUESTION 46

RP1 and PR2 are acting as PIM-SM rendezvous points (RPs) in their autonomous system.

Referring to the diagram, which purpose does the MSDP session between RP1 and RP2 serve?

A. MSDP allows RPs in different domains to advertise any active multicast receivers to each other

B. MSDP allows RPs in different PIM domains to advertise any active multicast sources to each other

C. MSDP routes are used by an RP for reverse path forwarding lookups when multicast sources exist in different autonomous systems.

D. MSDP allows RPs in different PIM domains to form PIM neighbor relationship with each other.

Correct Answer: BSection: (none)Explanation

Explanation/Reference:

QUESTION 47[edit protocols pim]user@R1# showrp { bootstrap {

Page 262: JNCIP-SP JN0-661 · PDF file · 2017-07-29You must ensure that r1's IPv4 loopback address exists in r3 ... redistribute the VPN routes into OSPF. Correct Answer: D ... this route

http://www.gratisexam.com/

family inet { priority 250; } }local { address 10.220.1.1; priority 1; group-ranges { 224.1.1.11/32 224.0.0.0/4 } }}interfacr all;interface fxp0.0 {disable;}

[edit protocols pim]user@R4# showrp { bootstrap { family inet { priority 249; } }local { address 10.220.1.1; priority 5; group-ranges { 224.1.1.12/32 224.0.0.0/4 } }}interfacr all;interface fxp0.0 {disable;}

Referring to the exhibit, which router will be the RP?

Page 263: JNCIP-SP JN0-661 · PDF file · 2017-07-29You must ensure that r1's IPv4 loopback address exists in r3 ... redistribute the VPN routes into OSPF. Correct Answer: D ... this route

http://www.gratisexam.com/

A. R4 for all groups

B. R1 for group 224.1.1.11 and R4 for all other groups

C. R1 for all groups

D. R4 for group 224.1.1.11 and R1 for all other groups

Correct Answer: CSection: (none)Explanation

Explanation/Reference:

QUESTION 48Which two statements are associated with any-source multicast? (Choose two.)

http://www.gratisexam.com

A. Routes learn the source of the multicast traffic from the source address of the multicast traffic.

B. Routes learn the source of the multicast traffic from the receives.

C. Routes do not specify a specific source from which to receive traffic.

D. Receives select a specific source from which to receive traffic.

Correct Answer: ACSection: (none)Explanation

Explanation/Reference:

Page 264: JNCIP-SP JN0-661 · PDF file · 2017-07-29You must ensure that r1's IPv4 loopback address exists in r3 ... redistribute the VPN routes into OSPF. Correct Answer: D ... this route

http://www.gratisexam.com/

Advanced MPLS

QUESTION 1You are working with a new MPLS network that is using the default EXP classifier and default schedules. A small amount of traffic is being placed in the assuredforwarding class.

No other traffic is passing through the network at this time.

In this scenario, what happens to the traffic that is being placed in the assured forwarding class?

A. The traffic is reclassified to the best effort forwarding class and is forwarded.

B. The traffic remains in the assured forwarding class and is forwarded.

C. The traffic is reclassified to the network control forwarding class and is forwarded.

D. The traffic remains in the assured forwarding class and is dropped.

Correct Answer: BSection: Advanced MPLSExplanation

Explanation/Reference:Reference: https://www.juniper.net/documentation/en_US/junos15.1/topics/concept/forwarding-classes-default-cos-config-guide.html

QUESTION 2Click the Exhibit button.

PE1 Configuration

interfaces { ge-1/1/0 { unit 0 { family inet { address 10.1.1.1/24;

Page 265: JNCIP-SP JN0-661 · PDF file · 2017-07-29You must ensure that r1's IPv4 loopback address exists in r3 ... redistribute the VPN routes into OSPF. Correct Answer: D ... this route

http://www.gratisexam.com/

} family mpls; } } ge-1/1/1 { unit 0 { family inet 6 { address 2000:FEFE::2/64; } } }}protocols { bgp { group PE2 { type internal; neighbor 10.0.0.2; } } mpls { interface ge-1/1/0.0; ldp { interface ge-1/1/0.0; ospf { area 0.0.0.0 { interface lo0.0 passive; interface ge-1/1/0.0; } }}routing-instance { Customer-1 { instance-type vrf; interface ge-1/1/1.0; route-distinguisher 100:101; vrf-target target:100:101; }}

ISP 1 wants to configure an IPv6 L3VPN over its IPv4-only MPLS network for Customer-A. PE1 has been configured as shown in the exhibit; however, IPv6 routesare not being passed between PE1 and PE2 in the Customer-A VPN.

Page 266: JNCIP-SP JN0-661 · PDF file · 2017-07-29You must ensure that r1's IPv4 loopback address exists in r3 ... redistribute the VPN routes into OSPF. Correct Answer: D ... this route

http://www.gratisexam.com/

In this scenario, which two commands are necessary on PE1 to enable IPv6 connectivity between CE1 and CE2? (Choose two.)

http://www.gratisexam.com

A. set protocols bgp group PE2 family inet6 unicast

B. set interfaces ge-1/1/1.0 family mpls

C. set protocols bgp group PE2 family inet6-vpn

D. set protocols mpls ipv6-tunneling

Correct Answer: ADSection: Advanced MPLSExplanation

Explanation/Reference:Tunneling IPv6 Traffic over MPLS IPv4 Networks

D: You enable IPv6 tunneling by including the ipv6-tunneling statement in the configuration for the PE routers.

A: BGP automatically runs its import policy even when copying routes from a primary routing table group to a secondary routing table group. If IPv4 labeled routes arrive from a BGP session (for example, when you have configured the labeled-unicast statement at the [edit protocols bgp family inet] hierarchy level on the PE router), the BGP neighbor's import policy also accepts IPv6 routes, since the neighbor's import policy is run while doing the copy operation to the inet6.3 routing table.

http://www.juniper.net/documentation/en_US/junos15.1/topics/example/mpls-tunneling-ipv6-over-mpls-ipv4.html

QUESTION 3A service provider wants to start using all of their LSPs for internal traffic and not just their MPLS VPNs. Any solution must ensure that existing VPNs and routingpolicies will continue to function properly.

Which MPLS traffic engineering parameter would accomplish this task?

Page 267: JNCIP-SP JN0-661 · PDF file · 2017-07-29You must ensure that r1's IPv4 loopback address exists in r3 ... redistribute the VPN routes into OSPF. Correct Answer: D ... this route

http://www.gratisexam.com/

A. bgp

B. bgp-igp-both-ribs

C. bgp-igp

D. mpls-forwarding

Correct Answer: DSection: Advanced MPLSExplanation

Explanation/Reference:When you configure an LSP, a host route (a 32-bit mask) is installed in the ingress router toward the egress router; the address of the host route is the destinationaddress of the LSP. The bgp option for the traffic engineering statement at the [edit protocols mpls] hierarchy level is enabled by default (you can also explicitlyconfigure the bgp option), allowing only BGP to use LSPs in its route calculations. The other traffic-engineering statement options allow you to alter this behavior inthe master routing instance. This functionality is not available for specific routing instances. Also, you can enable only one of the traffic-engineering statementoptions (bgp, bgp-igp, bgp-igp-both-ribs, or mpls-forwarding) at a time.

Note: Enabling or disabling any of the traffic-engineering statement options causes all the MPLS routes to be removed and then reinserted into the routing tables.

If you configure the mpls-forwarding option for the traffic-engineering statement, LSPs are used for forwarding but are excluded from route selection. These routesare added to both the inet.0 and inet.3 routing tables. LSPs in the inet.0 routing table are given a low preference when the active route is selected. However, LSPs inthe inet.3 routing table are given a normal preference and are therefore used for selecting forwarding next hops.When you activate the mpls-forwarding option, routes whose state is ForwardingOnly are preferred for forwarding even if their preference is lower than that of thecurrently active route. To examine the state of a route, execute a show route detail command.To use LSPs for forwarding but exclude them from route selection, include the mpls-forwarding option for the traffic-engineering statement:

Unlike the bgp-igp-both-ribs option, the mpls-forwarding option allows you to use the LDP-signaled and RSVP-signaled routes for forwarding, and keep the BGP andIGP routes active for routing purposes so that routing policies can act upon them.

Incorrect Answer:

C: You can configure BGP and the IGPs to use LSPs for forwarding traffic destined for egress routers by including the bgp-igp option for the traffic-engineeringstatement.

Reference: https://www.juniper.net/documentation/en_US/junos/topics/usage-guidelines/mpls-configuring-traffic-engineering-for-lsps.html

QUESTION 4Click the Exhibit button.

Page 268: JNCIP-SP JN0-661 · PDF file · 2017-07-29You must ensure that r1's IPv4 loopback address exists in r3 ... redistribute the VPN routes into OSPF. Correct Answer: D ... this route

http://www.gratisexam.com/

Given the configuration shown in the exhibit and the admin groups assigned to the equal cost links, which path will the LSP take to get from R1 to R10?

A. R1 > R2 > R5 > R6 > R7 > R10

B. R1 > R2 > R5 > R8 > R10

C. R1 > R2 > R4 > R3 > R6 > R7 > R8 > R10

D. R1 > R2 > R5 > R6 > R9 > R10

Correct Answer: CSection: Advanced MPLSExplanation

Explanation/Reference:

Page 269: JNCIP-SP JN0-661 · PDF file · 2017-07-29You must ensure that r1's IPv4 loopback address exists in r3 ... redistribute the VPN routes into OSPF. Correct Answer: D ... this route

http://www.gratisexam.com/

QUESTION 5Which two statements are true regarding the CSPF algorithm? (Choose two.)

A. The selected path for a given LSP is passed to the TED in the form of an ERO.

B. LSPs with lower numerical setup priorities are computed before LSPs with higher setup priority values.

C. The selected path for a given LSP is passed to RSVP in the form of an ERO.

D. LSPs with higher numerical setup priorities are computed before LSPs with lower setup priority values.

Correct Answer: BCSection: Advanced MPLSExplanation

Explanation/Reference:The CSPF algorithm first calculates the highest-priority LSP (the one with the lowest setup priority value).

Do I need to enable CSPF to control where to send my traffic? The answer is no.

You can manually configure an Explicit Route Objects (ERO) list, and let RSVP doing the job. In the presence of the ERO object, the RSVP Path messages willfollow the path specified, thus the Resv messages carrying the labels in the opposite direction.

Reference: https://www.netflask.net/jnpr-constrained-shortest-path-first/

QUESTION 6Click the Exhibit button.

Page 270: JNCIP-SP JN0-661 · PDF file · 2017-07-29You must ensure that r1's IPv4 loopback address exists in r3 ... redistribute the VPN routes into OSPF. Correct Answer: D ... this route

http://www.gratisexam.com/

Referring to the exhibit button, you are asked to ensure that traffic destined for the 5.5.5.0/24 network must use the LSP named Top.

A. Apply the policy as an import policy for BGP on R1.

B. Create a routing policy that matches the route 5.5.5.0/24 with an action of install-nexthop lsp Top.

C. Create a routing policy that matches the route 5.5.5.0/24 with an action of next-hop Top.

D. Apply the policy to the forwarding table on R1.

Correct Answer: BDSection: Advanced MPLSExplanation

Explanation/Reference:B: The install-nexthop command selects a specific label-switched path (LSP), or select an LSP from a set of similarly named LSPs as the traffic destination for theconfigured community.

D: You can apply an export routing policy to a forwarding table. You include the export statement:export [ policy-names ];

Reference: https://www.juniper.net/documentation/en_US/junos14.1/topics/reference/configuration-statement/install-nexthop-edit-policy-options.html

QUESTION 7Click the Exhibit button.

Page 271: JNCIP-SP JN0-661 · PDF file · 2017-07-29You must ensure that r1's IPv4 loopback address exists in r3 ... redistribute the VPN routes into OSPF. Correct Answer: D ... this route

http://www.gratisexam.com/

Referring to the exhibit, which two configuration steps must be implemented so that LSPs will be able to use link protection from R1 to R3? (Choose two.)

A. Configure each eligible interface for link protection.

B. Configure each eligible router's protocol RSVP for fast reroute.

C. Configure each eligible router's protocol MPLS for link protection.

D. Configure each eligible LSP for link protection.

Correct Answer: ADSection: Advanced MPLSExplanation

Explanation/Reference:Explanation:

QUESTION 8Click the Exhibit button.

Page 272: JNCIP-SP JN0-661 · PDF file · 2017-07-29You must ensure that r1's IPv4 loopback address exists in r3 ... redistribute the VPN routes into OSPF. Correct Answer: D ... this route

http://www.gratisexam.com/

You have an established RSVP LSP from R1 to R4. As shown in the exhibit, you experience a link failure between R2 and R3.

Which two statements are correct? (Choose two.)

A. R2 will send a PathTear message upstream to R1, indicating a failure has occurred.

B. R3 will send a PathTear message downstream to R4, indicating a failure has occurred.

C. R3 will send a ResvTear message downstream to R4, indicating a failure has occurred.

D. R2 will send a ResvTear message upstream to R1, indicating a failure has occurred.

Correct Answer: BDSection: Advanced MPLSExplanation

Explanation/Reference:

QUESTION 9Click the Exhibit button.

Your network has multiple LSPs between Router A and Router B, as shown in the exhibit. You add a new LSP between these routers with the following parameters:

LSP5: 20 Mbps; Priority 2 2

Page 273: JNCIP-SP JN0-661 · PDF file · 2017-07-29You must ensure that r1's IPv4 loopback address exists in r3 ... redistribute the VPN routes into OSPF. Correct Answer: D ... this route

http://www.gratisexam.com/

Assuming no link has 20 Mbps available, which LSPs are candidates for preemption by LSP5? (Choose two.)

A. LSP1

B. LSP2

C. LSP3

D. LSP4

Correct Answer: CDSection: Advanced MPLSExplanation

Explanation/Reference:Explanation:

Real 221Juniper JN0-660 Exam

QUESTION 10Click the Exhibit button.

Your network has multiple LSPs between Router A and Router B, as shown in the exhibit. You add a new LSP between these routers with the following parameters:

LSP5: 20 Mbps; Priority 4 3

Assuming no link has 20 Mbps available, which LSP will be preempted by LSP5?

A. LSP1

Page 274: JNCIP-SP JN0-661 · PDF file · 2017-07-29You must ensure that r1's IPv4 loopback address exists in r3 ... redistribute the VPN routes into OSPF. Correct Answer: D ... this route

http://www.gratisexam.com/

B. LSP2

C. LSP3

D. LSP4

Correct Answer: DSection: Advanced MPLSExplanation

Explanation/Reference:Explanation:

Real 220Juniper JN0-660 Exam

QUESTION 11You have recently deployed an MPLS network using CSPF with its default settings. Which statement is true regarding path selection when multiple candidate pathsexist?

http://www.gratisexam.com

A. The path selected will be based on the most-fill bandwidth ratio.

B. The path selected will be based on the least-fill bandwidth ratio.

C. The path selected will be based on a randomized algorithm.

D. The path selected will be based on the first-hop LSR's RID.

Correct Answer: CSection: Advanced MPLSExplanation

Explanation/Reference:

QUESTION 12You are asked to mask your Junos MPLS core network from users that use traceroute. You have configuration privileges only on the ingress device. Which featurewill accomplish this task?

Page 275: JNCIP-SP JN0-661 · PDF file · 2017-07-29You must ensure that r1's IPv4 loopback address exists in r3 ... redistribute the VPN routes into OSPF. Correct Answer: D ... this route

http://www.gratisexam.com/

A. Egress-protection

B. No-propagate-ttl

C. No-record

D. No-decrement-ttl

Correct Answer: DSection: Advanced MPLSExplanation

Explanation/Reference:

QUESTION 13You have configured an MPLS LSP that includes defined hops. For this path, you want the MPLS label to be popped at the egress node.

Which configuration statement meets this requirement?

A. Set protocols rsvp explicit-null, configured on the ingress node

B. Set protocols mpls explicit-null, configured on the egress node

C. Set protocols mpls explicit-null, configured on the ingress node

D. Set protocols rsvp implicit-null, configured on the egress node

Correct Answer: BSection: Advanced MPLSExplanation

Explanation/Reference:

QUESTION 14You want to ensure that your all-Junos MPLS core network does not decrease the TTL when using ping and traceroute from IP endpoints. Which two configurationparameters satisfy this requirement? (Choose two.)

A. no-decrement-ttl, configured on all routers in the path

B. no-decrement-ttl, configured on the ingress router only

C. no-propagate-ttl, configured on all routers in the path

D. no-propagate-ttl, configured on the ingress router only

Correct Answer: BC

Page 276: JNCIP-SP JN0-661 · PDF file · 2017-07-29You must ensure that r1's IPv4 loopback address exists in r3 ... redistribute the VPN routes into OSPF. Correct Answer: D ... this route

http://www.gratisexam.com/

Section: Advanced MPLSExplanation

Explanation/Reference:

QUESTION 15You want to ensure your multivendor MPLS core network does not decrease the TTL when using ping and traceroute from IP endpoints. Which configurationparameter satisfies this requirement?

A. no-decrement-ttl, configured on all routers in the path

B. no-decrement-ttl, configured on the ingress router only

C. no-propagate-ttl, configured on all routers in the path

D. no-propagate-ttl, configured on the ingress router only

Correct Answer: CSection: Advanced MPLSExplanation

Explanation/Reference:

QUESTION 16Which two statements are true regarding the CSPF algorithm? (Choose two.)

A. LSPs with higher numerical setup priorities are computed before LSPs with lower setup priority values.

B. LSPs with lower numerical setup priorities are computed before LSPs with higher setup priority values.

C. The selected path for a given LSP is passed to RSVP in the form of an ERO.

D. The selected path for a given LSP is passed to the TED in the form of an ERO.

Correct Answer: BCSection: Advanced MPLSExplanation

Explanation/Reference:The CSPF algorithm first calculates the highest-priority LSP (the one with the lowest setup priority value).

Do I need to enable CSPF to control where to send my traffic? The answer is no. You can manually configure an Explicit Route Objects (ERO) list, and let RSVPdoing the job. In the presence of the ERO object, the RSVP Path messages will follow the path specified, thus the Resv messages carrying the labels in theopposite direction.

Page 277: JNCIP-SP JN0-661 · PDF file · 2017-07-29You must ensure that r1's IPv4 loopback address exists in r3 ... redistribute the VPN routes into OSPF. Correct Answer: D ... this route

http://www.gratisexam.com/

References: https://www.netflask.net/jnpr-constrained-shortest-path-first/

QUESTION 17You are deploying an MPLS network that uses traffic engineering. You are asked to formulate a plan to engineer LSPs and must identify configurable user inputs todo this. Which three inputs would be used? (Choose three.)

A. Bandwidth requirement

B. Source prefix

C. Explicit route

D. Protocol type

E. Administrative group

Correct Answer: ACESection: Advanced MPLSExplanation

Explanation/Reference:

QUESTION 18You are setting up MPLS RSVP LSPs between R1 and R6 through your core network. You must ensure that the R1 has redundant ERO paths. You must alsoensure that both paths are signaled and ready for traffic.

Which action will accomplish these requirements?

A. Create two primary paths.

B. Create a primary path and create a secondary path.

C. Create a primary path and create a secondary path with the standby parameter.

D. Create a primary path and create a secondary path with the active parameter.

Correct Answer: CSection: Advanced MPLSExplanation

Explanation/Reference:

QUESTION 19You are setting up MPLS RSVP LSPs between R1 and R6 through your core network. You must ensure that R1 has redundant ERO paths. If the main path fails

Page 278: JNCIP-SP JN0-661 · PDF file · 2017-07-29You must ensure that r1's IPv4 loopback address exists in r3 ... redistribute the VPN routes into OSPF. Correct Answer: D ... this route

http://www.gratisexam.com/

and moves traffic to a second path, it should not switch back to the original path automatically. Which two actions will accomplish these requirements? (Choosetwo.)

A. Create two secondary paths.

B. Create a primary path with a revert timer of 0 and create a secondary path.

C. Create two primary paths.

D. Create a primary path with the revert timer set to 255 and create a secondary path.

Correct Answer: ABSection: Advanced MPLSExplanation

Explanation/Reference:

QUESTION 20You want to enable PFE fast reroute for the MPLS nodes that are acting as bypass routers for multiple MPLS LSPs.

Which action must you take to facilitate this behavior?

A. Apply a load balancing policy to the forwarding tables of the bypass routers.

B. Apply the RSVP fast reroute feature on the bypass routers.

C. Apply the MPLS link protection feature on the bypass routers.

D. Apply the RSVP load balance feature on the ingress and the bypass routers.

Correct Answer: ASection: Advanced MPLSExplanation

Explanation/Reference:

QUESTION 21What are two elements that must be configured to enable LDP? (Choose two.)

A. Add the relevant interfaces under the [edit protocols ldp] hierarchy.

B. Add the relevant interfaces under the [edit protocols rsvp] hierarchy.

C. Add the family iso statement to the relevant interfaces under the [edit interfaces] hierarchy.

D. Add the family mpls statement to the relevant interfaces under the [edit interfaces]

Page 279: JNCIP-SP JN0-661 · PDF file · 2017-07-29You must ensure that r1's IPv4 loopback address exists in r3 ... redistribute the VPN routes into OSPF. Correct Answer: D ... this route

http://www.gratisexam.com/

Correct Answer: ADSection: Advanced MPLSExplanation

Explanation/Reference:

QUESTION 22Which table is considered the MPLS routing table?

.

http://www.gratisexam.com

A. inet.0

B. inet.2

C. inet.3

D. inet6.0

Correct Answer: CSection: Advanced MPLSExplanation

Explanation/Reference:

QUESTION 23Click the Exhibit button.

Page 280: JNCIP-SP JN0-661 · PDF file · 2017-07-29You must ensure that r1's IPv4 loopback address exists in r3 ... redistribute the VPN routes into OSPF. Correct Answer: D ... this route

http://www.gratisexam.com/

You have an MPLS network and you have configured least-fill as your CSPF tiebreaker.

Using the information in the exhibit, which path will be used to signal a new LSP requiring 12 Mbps?

A. Path 1

B. Path 2

C. Path 3

D. Path 4

Correct Answer: DSection: Advanced MPLSExplanation

Explanation/Reference:

QUESTION 24Click the Exhibit button.

Page 281: JNCIP-SP JN0-661 · PDF file · 2017-07-29You must ensure that r1's IPv4 loopback address exists in r3 ... redistribute the VPN routes into OSPF. Correct Answer: D ... this route

http://www.gratisexam.com/

On the network shown in the exhibit, a network administrator is attempting to bring up an LSP between Boston and Seattle using administrative groups.

Which two of the following LSP configurations allow the LSP to establish? (Choose two.)

A. [edit protocols mpls label-switched-path Boston-to-Seattle]user@Boston# showto 192.168.10.100;admin-group { include-any White; exclude Red;}

B. [edit protocols mpls label-switched-path Boston-to-Seattle]user@Boston# showto 192.168.10.100;admin-group include-all [Red White Blue];

C. [edit protocols mpls label-switched-path Boston-to-Seattle]user@Boston# showto 192.168.10.100;admin-group { include-any [Red Blue]; include-all Blue;}

D. [edit protocols mpls label-switched-path Boston-to-Seattle]user@Boston# showto 192.168.10.100;admin-group {

Page 282: JNCIP-SP JN0-661 · PDF file · 2017-07-29You must ensure that r1's IPv4 loopback address exists in r3 ... redistribute the VPN routes into OSPF. Correct Answer: D ... this route

http://www.gratisexam.com/

include-any Red; include-all Blue;}

Correct Answer: CDSection: Advanced MPLSExplanation

Explanation/Reference:

QUESTION 25Which statement is true regarding the no-propagate-ttl feature?

A. Supported only by Junos devices

B. Configured on every LSR

C. Configured only on ingress LSR

D. Supported only on RSVP LSPs

Correct Answer: BSection: Advanced MPLSExplanation

Explanation/Reference:

QUESTION 26What is the first step of the CSPF algorithm's pruning process?

A. Prune links with insufficient bandwidth.

B. Prune links that contain an excluded administrative group.

C. Prune links that do not contain an included administrative group.

D. Prune links that do not contain an administrative group.

Correct Answer: ASection: Advanced MPLSExplanation

Explanation/Reference:

Page 283: JNCIP-SP JN0-661 · PDF file · 2017-07-29You must ensure that r1's IPv4 loopback address exists in r3 ... redistribute the VPN routes into OSPF. Correct Answer: D ... this route

http://www.gratisexam.com/

QUESTION 27Click the Exhibit button.

[edit protocols mpls]user@Boston# showlabel-switched-path Boston-to-Seattle { to 192.168.10.100; bandwidth 6g; priority 5 4;}label-switched-path Boston-to-Denver { to 192.168.10.200; bandwidth 6g; priority 4 4;}

A network administrator has configured the LSPs shown in the exhibit on the ingress router of a 10-Gigabit Ethernet network. Which statement is true?

A. Both LSPs will establish and remain established.

B. The Boston-to-Denver LSP will establish and remain established.

C. The Boston-to-Seattle LSP will establish and remain established.

D. Neither LSP will remain established.

Correct Answer: BSection: Advanced MPLSExplanation

Explanation/Reference:

QUESTION 28Click the Exhibit button.

Page 284: JNCIP-SP JN0-661 · PDF file · 2017-07-29You must ensure that r1's IPv4 loopback address exists in r3 ... redistribute the VPN routes into OSPF. Correct Answer: D ... this route

http://www.gratisexam.com/

Referring to the exhibit, which statement is true assuming LDP VPN signaling?

A. PE1 uses the label value received from PE2 for VPN B as the inner label for VPN B.

B. PE2 uses the label value received from PE1 for VPN A as the transport label for VPN A.

C. P1 uses the label value for VPN A advertised by PE1, because RSVP is enabled.

D. PE1 uses the transport label value received for VPN A that is advertised by PE2 as the inner label for VPN A.

Correct Answer: ASection: Advanced MPLSExplanation

Explanation/Reference:

QUESTION 29Click the Exhibit button.

Page 285: JNCIP-SP JN0-661 · PDF file · 2017-07-29You must ensure that r1's IPv4 loopback address exists in r3 ... redistribute the VPN routes into OSPF. Correct Answer: D ... this route

http://www.gratisexam.com/

Using the configuration and topology in the exhibit, which statement is true?

A. Each LSR randomly selects the physical path to reach the loose hop R5 for the LSP.

B. Each LSR uses the IGP to select the physical path to reach the loose hop on R5 for the LSP.

C. Each LSR selects the lowest next-hop IP address to reach the loose hop on R5 for the LSP.

D. Each LSR selects the highest next-hop IP address to reach the loose hop on R5 for the LSP.

Correct Answer: BSection: Advanced MPLSExplanation

Explanation/Reference:

QUESTION 30Click the Exhibit button.

[edit protocols mpls]

Page 286: JNCIP-SP JN0-661 · PDF file · 2017-07-29You must ensure that r1's IPv4 loopback address exists in r3 ... redistribute the VPN routes into OSPF. Correct Answer: D ... this route

http://www.gratisexam.com/

user@router# showlabel-switched-path to-egress { to 172.40.21.1; primary path-one; secondary path-two;}path path-one { 172.20.20.5;}path path-two { 172.20.21.5;}interface all;interface fxp0.0 { disable;}

Based on the configuration shown in the exhibit, which two statements are correct? (Choose two.)

A. The secondary path is only signaled if the primary path fails.

B. The secondary path is signaled and in standby mode.

C. The LSP will revert back to the primary path when it becomes available.

D. The LSP will not revert back to the primary path until the session is cleared.

Correct Answer: ACSection: Advanced MPLSExplanation

Explanation/Reference:

QUESTION 31Click the Exhibit button.

As shown in the exhibit, you have an LSP established from R1 to R4. Your network experiences a link failure between R2 and R3.Which statement is correct?

A. A ResvTear message is sent toward the egress router.

Page 287: JNCIP-SP JN0-661 · PDF file · 2017-07-29You must ensure that r1's IPv4 loopback address exists in r3 ... redistribute the VPN routes into OSPF. Correct Answer: D ... this route

http://www.gratisexam.com/

B. A ResvConf message is sent toward the ingress router.

C. A PathErr message is sent toward the egress router.

D. A ResvTear message is sent toward the ingress router.

Correct Answer: DSection: Advanced MPLSExplanation

Explanation/Reference:

QUESTION 32Click the Exhibit button.

[edit protocols mpls]user@router# showlabel-switched-path to-egress { to 172.40.100.10; secondary path-one; secondary path-three; secondary path-two;}path path-one { 172.20.100.1;}path path-two { 172.20.100.5;}path path-three { 172.20.100.5;}interface all;interface fxp0.0 { disable;}

Based on the configuration in the exhibit, which statement is correct?

A. If path-one fails, the LSP will attempt to signal a new LSP using path-three.

B. If path-one fails, the LSP will attempt to signal a new LSP using path-two.

C. If path-one fails, the LSP will not attempt to signal a new LSP.

Page 288: JNCIP-SP JN0-661 · PDF file · 2017-07-29You must ensure that r1's IPv4 loopback address exists in r3 ... redistribute the VPN routes into OSPF. Correct Answer: D ... this route

http://www.gratisexam.com/

D. If path-one fails, the LSP will attempt to signal a new LSP using both path-two and path-three.

Correct Answer: ASection: Advanced MPLSExplanation

Explanation/Reference:

QUESTION 33An administrator wants to block the re-advertisement of the 10.10.255.6 FEC to all LDP neighbors while still advertising the local router's loopback address. Whatwill accomplish this?

A. ldp { egress-policy block-one; interface all;}policy-options policy-statement block-one { term 1 { from { router-filter 10.10.255.6/32 exact reject; } } term 2 { then accept ; } }

B. ldp { export block-one; interface all;}policy-options policy-statement block-one { term 1 { from { router-filter 10.10.255.6/32 exact reject; } } term 2 { then accept ; }

Page 289: JNCIP-SP JN0-661 · PDF file · 2017-07-29You must ensure that r1's IPv4 loopback address exists in r3 ... redistribute the VPN routes into OSPF. Correct Answer: D ... this route

http://www.gratisexam.com/

}}

C. ldp { import block-one; interface all;}policy-options policy-statement block-one { term 1 { from { router-filter 10.10.255.6/32 exact reject; } } term 2 { then accept ; } }}

D. ldp { ingress-policy block-one; interface all;}policy-options policy-statement block-one { term 1 { from { router-filter 10.10.255.6/32 exact reject; } } term 2 { then accept ; } }}

Correct Answer: BSection: Advanced MPLSExplanation

Explanation/Reference:

Page 290: JNCIP-SP JN0-661 · PDF file · 2017-07-29You must ensure that r1's IPv4 loopback address exists in r3 ... redistribute the VPN routes into OSPF. Correct Answer: D ... this route

http://www.gratisexam.com/

QUESTION 34Click the Exhibit button.

Referring to the exhibit, which type of traffic protection mechanism is used for the LSP?

A. link-protection

B. fast-reroute

C. node-link-protection

D. bypass

Correct Answer: BSection: Advanced MPLSExplanation

Page 291: JNCIP-SP JN0-661 · PDF file · 2017-07-29You must ensure that r1's IPv4 loopback address exists in r3 ... redistribute the VPN routes into OSPF. Correct Answer: D ... this route

http://www.gratisexam.com/

Explanation/Reference:

QUESTION 35You manage an MPLS network. You are asked to classify traffic using the EXP bits from ingress to egress. What will allow you to accomplish this?

http://www.gratisexam.com

A. Configure explicit-null on the penultimate router.

B. Configure explicit-null on the egress router.

C. Configure implicit-null on the penultimate router.

D. Configure implicit-null on the egress router.

Correct Answer: BSection: Advanced MPLSExplanation

Explanation/Reference:

QUESTION 36Click the Exhibit button.

Page 292: JNCIP-SP JN0-661 · PDF file · 2017-07-29You must ensure that r1's IPv4 loopback address exists in r3 ... redistribute the VPN routes into OSPF. Correct Answer: D ... this route

http://www.gratisexam.com/

You have an MPLS network and you have configured most-fill as a CSPF tiebreaker. Using the information in the exhibit, which path will be used to signal a newLSP requiring 12 Mbps?

A. Path 1

B. Path 2

C. Path 3

D. Path 4

Correct Answer: DSection: Advanced MPLSExplanation

Explanation/Reference:

QUESTION 37What is the purpose of the no-cspf command?

A. to successfully signal the LSP across the network regardless of constraints

B. to delete the CSPF database

Page 293: JNCIP-SP JN0-661 · PDF file · 2017-07-29You must ensure that r1's IPv4 loopback address exists in r3 ... redistribute the VPN routes into OSPF. Correct Answer: D ... this route

http://www.gratisexam.com/

C. to ignore OSPF when calculating the ERO

D. to successfully signal the LSP only if the default IGP path (or named path) meets all constraints

Correct Answer: ASection: Advanced MPLSExplanation

Explanation/Reference:

QUESTION 38Click the Exhibit button.

Referring to the exhibit, which type of traffic protection mechanism is used for the LSP?

Page 294: JNCIP-SP JN0-661 · PDF file · 2017-07-29You must ensure that r1's IPv4 loopback address exists in r3 ... redistribute the VPN routes into OSPF. Correct Answer: D ... this route

http://www.gratisexam.com/

A. link-protection

B. fast-reroute

C. node-link-protection

D. bypass

Correct Answer: BSection: Advanced MPLSExplanation

Explanation/Reference:

QUESTION 39Which two statements describe advantages of using BGP for VPLS signaling instead of LDP signaling? (Choose two.)

A. There is no need for MPLS signaling protocol.

B. There is a well-defined scaling hierarchy.

C. There is a separation of signaling from other services.

D. There is auto discovery.

Correct Answer: BDSection: Advanced MPLSExplanation

Explanation/Reference:

QUESTION 40What is a limitation of LDP?

A. Traffic must follow explicitly configured paths.

B. It requires a full mesh of LSPs throughout the network.

C. It requires a traffic engineering database (TED).

D. It does not support traffic engineering.

Correct Answer: DSection: Advanced MPLSExplanation

Page 295: JNCIP-SP JN0-661 · PDF file · 2017-07-29You must ensure that r1's IPv4 loopback address exists in r3 ... redistribute the VPN routes into OSPF. Correct Answer: D ... this route

http://www.gratisexam.com/

Explanation/Reference:

QUESTION 41Click the Exhibit button.

Referring to the exhibit, which type of traffic protection mechanism is used for the LSP?

A. fast-reroute

B. link-protection

C. node-link-protection

D. secondary

Correct Answer: BSection: Advanced MPLSExplanation

Explanation/Reference:

QUESTION 42

Page 296: JNCIP-SP JN0-661 · PDF file · 2017-07-29You must ensure that r1's IPv4 loopback address exists in r3 ... redistribute the VPN routes into OSPF. Correct Answer: D ... this route

http://www.gratisexam.com/

Click the Exhibit button.

As shown in the exhibit, you have an adaptive LSP that requires 85 Mbps. The LSP is configured with a primary path and a secondary path in standby mode. Allconnections in the MPLS network are Fast Ethernet. Which statement is correct?

A. The primary and secondary paths are in an up state and operational.

B. The primary and secondary paths are in a down state and not operational.

C. The secondary path is in a down state and not operational.

D. The primary path is in a down state and not operational.

Correct Answer: ASection: Advanced MPLSExplanation

Explanation/Reference:

QUESTION 43Click the Exhibit button.

[edit protocols mpls]user@router# show

Page 297: JNCIP-SP JN0-661 · PDF file · 2017-07-29You must ensure that r1's IPv4 loopback address exists in r3 ... redistribute the VPN routes into OSPF. Correct Answer: D ... this route

http://www.gratisexam.com/

label-switched-path to-egress { to 192.168.1.1; install 172.20.20.0/24;}interface all;

Based on the configuration in the exhibit, which statement is correct?

A. The 172.20.20.0/24 route is installed in the inet.0 table with the next hop of the LSP.

B. The 172.20.20.0/24 route is installed in the mpls.0 table with the next hop of the LSP.

C. The 172.20.20.0/24 route is installed in the inet.3 table with the next hop of the LSP.

D. The 172.20.20.0/24 route is installed in the inet6.3 table with the next hop of the LSP.

Correct Answer: CSection: Advanced MPLSExplanation

Explanation/Reference:

QUESTION 44You manage an MPLS network where the PE devices consist of multiple vendors. You are asked to conceal the MPLS topology for all LSPs. Which globalconfiguration parameter will accomplish this?

A. Configure no-decrement-ttl on the ingress router only.

B. Configure no-propagate-ttl on the ingress router only.

C. Configure no-decrement-ttl on all routers within the MPLS network.

D. Configure no-propagate-ttl on all routers within the MPLS network.

Correct Answer: DSection: Advanced MPLSExplanation

Explanation/Reference:

QUESTION 45Click the Exhibit button.

Page 298: JNCIP-SP JN0-661 · PDF file · 2017-07-29You must ensure that r1's IPv4 loopback address exists in r3 ... redistribute the VPN routes into OSPF. Correct Answer: D ... this route

http://www.gratisexam.com/

Referring to the exhibit, which MPLS feature was used to make the LSP the preferred path for internal routes?

A. traffic engineering bgp-igp

B. traffic engineering shortcuts

C. traffic engineering mpls-forwarding

D. install active

Correct Answer: CSection: Advanced MPLSExplanation

Explanation/Reference:

QUESTION 46Click the Exhibit button.

Page 299: JNCIP-SP JN0-661 · PDF file · 2017-07-29You must ensure that r1's IPv4 loopback address exists in r3 ... redistribute the VPN routes into OSPF. Correct Answer: D ... this route

http://www.gratisexam.com/

Referring to the exhibit, which LDP Layer 2 circuit configuration on PE1 maps traffic to an LSP destined to the secondary loopback address of PE2?

A. [edit protocols l2circuit]user@PE1# showneighbor 10.10.10.2 { interface ge-1/1/1.1 { psn-tunnel-endpoint 10.10.10.1; virtual-circuit-id 1; encapsulation-type ethernet-vlan; }}

B. [edit protocols l2circuit]user@PE1# showneighbor 10.10.10.2 { interface ge-1/1/1.1 { virtual-circuit-id 1; encapsulation-type ethernet-vlan; }}

C. [edit protocols l2circuit]user@PE1# showneighbor 10.10.10.2 { interface ge-1/1/1.1 { psn-tunnel-endpoint 10.10.10.2; virtual-circuit-id 1; encapsulation-type ethernet-vlan; }}

D. [edit protocols l2circuit]user@PE1# showneighbor 10.10.10.1 {

Page 300: JNCIP-SP JN0-661 · PDF file · 2017-07-29You must ensure that r1's IPv4 loopback address exists in r3 ... redistribute the VPN routes into OSPF. Correct Answer: D ... this route

http://www.gratisexam.com/

interface ge-1/1/1.1 { psn-tunnel-endpoint 10.10.10.2; virtual-circuit-id 1; encapsulation-type ethernet-vlan; }}

Correct Answer: CSection: Advanced MPLSExplanation

Explanation/Reference:

QUESTION 47In a carrier-of-carrier VPN model, which type of network layer reachability information is used for the MP-BGP signaling between CE and PE routers?

A. inet-vpn

B. flow

C. labeled-unicast

D. unicast

Correct Answer: BSection: Advanced MPLSExplanation

Explanation/Reference:In a Carrier-of-Carrier VPN environment, specify the inet-vpn address family and unicast traffic type to enable BGP to carry IPv4 network layer reachabilityinformation (NLRI) for VPN routes.

Reference: http://www.juniper.net/documentation/en_US/junos15.1/topics/example/mpls-vpn-option2-configuration.html

QUESTION 48Which two statements are true regarding the CSPF algorithm? (Choose two.)

A. The selected path for a given LSP is passed to the TED in the form of an ERO.

B. LSPs with lower numerical setup priorities are computed before LSPs with higher setup priority values.

C. The selected path for a given LSP is passed to RSVP in the form of an ERO.

D. LSPs with higher numerical setup priorities are computed before LSPs with lower setup priority values.

Page 301: JNCIP-SP JN0-661 · PDF file · 2017-07-29You must ensure that r1's IPv4 loopback address exists in r3 ... redistribute the VPN routes into OSPF. Correct Answer: D ... this route

http://www.gratisexam.com/

Correct Answer: BCSection: Advanced MPLSExplanation

Explanation/Reference:The CSPF algorithm first calculates the highest-priority LSP (the one with the lowest setup priority value).

Do I need to enable CSPF to control where to send my traffic? The answer is no. You can manually configure an Explicit Route Objects (ERO) list, and let RSVPdoing the job. In the presence of the ERO object, the RSVP Path messages will follow the path specified, thus the Resv messages carrying the labels in theopposite direction.

References: https://www.netflask.net/jnpr-constrained-shortest-path-first/

QUESTION 49Click the Exhibit button.

Referring to the exhibit button, you are asked to ensure that traffic destined for the 5.5.5.0/24 network must use the LSP named Top.

Which two actions would you perform to accomplish this task? (Choose two.)

A. Apply the policy as an import policy for BGP on R1.

B. Create a routing policy that matches the route 5.5.5.0/24 with an action of install-nexthop lsp Top.

C. Create a routing policy that matches the route 5.5.5.0/24 with an action of next-hop Top.

D. Apply the policy to the forwarding table on R1.

Correct Answer: BDSection: Advanced MPLS

Page 302: JNCIP-SP JN0-661 · PDF file · 2017-07-29You must ensure that r1's IPv4 loopback address exists in r3 ... redistribute the VPN routes into OSPF. Correct Answer: D ... this route

http://www.gratisexam.com/

Explanation

Explanation/Reference:B: The install-nexthop command selects a specific label-switched path (LSP), or select an LSP from a set of similarly named LSPs as the traffic destination for theconfigured community.

D: You can apply an export routing policy to a forwarding table. You include the export statement:export [ policy-names ];

References: https://www.juniper.net/documentation/en_US/junos14.1/topics/reference/configuration-statement/install-nexthop-edit-policy-options.html

QUESTION 50You are working with a new MPLS network that is using the default EXP classifier and default schedules. A small amount of traffic is being placed in the assuredforwarding class. No other traffic is passing through the network at this time.

In this scenario, what happens to the traffic that is being placed in the assured forwarding class?

A. The traffic is reclassified to the best effort forwarding class and is forwarded.

B. The traffic remains in the assured forwarding class and is forwarded.

C. The traffic is reclassified to the network control forwarding class and is forwarded.

D. The traffic remains in the assured forwarding class and is dropped.

Correct Answer: BSection: Advanced MPLSExplanation

Explanation/Reference:References: https://www.juniper.net/documentation/en_US/junos15.1/topics/concept/forwarding-classes-default-cos-config-guide.html

QUESTION 51Click on the exhibit

Page 303: JNCIP-SP JN0-661 · PDF file · 2017-07-29You must ensure that r1's IPv4 loopback address exists in r3 ... redistribute the VPN routes into OSPF. Correct Answer: D ... this route

http://www.gratisexam.com/

The configuration excerpt shown below is applied to R1:

label-switched-path R1-to-R9 { to 1.1.1.1; primary primary-path { admin-group { exclude red; } }}

Referring to the exhibit, on which path will the LSP be established?

http://www.gratisexam.com

A. R1-R4-R5-R2-R3-R6-R9

B. R1-R4-R7-R8-R9

C. R1-R4-R5-R6-R9

D. R1-R4-R5-R8-R9

Correct Answer: A

Page 304: JNCIP-SP JN0-661 · PDF file · 2017-07-29You must ensure that r1's IPv4 loopback address exists in r3 ... redistribute the VPN routes into OSPF. Correct Answer: D ... this route

http://www.gratisexam.com/

Section: Advanced MPLSExplanation

Explanation/Reference:

QUESTION 52Click on the exhibit

As shown in the exhibit, you have an LSP established from R1 to R4. Your network experiences a link failure between R4 and R3. Which statement is correct?

A. A PathTear message is sent toward the ingress router.

B. A ResvErr message is sent toward the ingress router.

C. A PathTear message is sent toward the egress router.

D. A ResvConf message is sent toward the egress router.

Correct Answer: CSection: Advanced MPLSExplanation

Explanation/Reference:

QUESTION 53Click on the exhibit

[edit protocols mpls]user@router# showlabel-switched-path to-egress { to 172.40.100.10; secondary path-one; secondary path-three; secondary path-two;}path path-one { 172.20.100.1;}

Page 305: JNCIP-SP JN0-661 · PDF file · 2017-07-29You must ensure that r1's IPv4 loopback address exists in r3 ... redistribute the VPN routes into OSPF. Correct Answer: D ... this route

http://www.gratisexam.com/

path path-two { 172.20.100.5;}path path-three { 172.20.100.5;}interface all;interface fxp0.0 { disable;}

You have a router using the MPLS configuration shown in the exhibit. Your LSP switched to "path-three" because of a failure. After addressing the link failure in"path-one", the network experiences a failure in "path-three" causing the LSP to re-signal. Which statement is correct?

A. The LSP attempts to use "path-one" first for signaling the new LSP.

B. The LSP attempts to signal using both "path-one" and "path-two" simultaneously.

C. The LSP attempts to signal by choosing the path randomly for signaling the new LSP.

D. The LSP attempts to use "path-two" first for signaling the new LSP.

Correct Answer: ASection: Advanced MPLSExplanation

Explanation/Reference:

QUESTION 54Click on the exhibit

Page 306: JNCIP-SP JN0-661 · PDF file · 2017-07-29You must ensure that r1's IPv4 loopback address exists in r3 ... redistribute the VPN routes into OSPF. Correct Answer: D ... this route

http://www.gratisexam.com/

Page 307: JNCIP-SP JN0-661 · PDF file · 2017-07-29You must ensure that r1's IPv4 loopback address exists in r3 ... redistribute the VPN routes into OSPF. Correct Answer: D ... this route

http://www.gratisexam.com/

Customer A is complaining that CE1 and CE2 cannot form an OSPF adjacency across your LDP Layer 2 circuit. The physical topology of the network is CE1-PE1-P-PE2-CE2. PE1's loopback is 192.168.5.1, P's loopback is 192.168.6.1, and PE2's loopback is 192.168.7.1. Referring to the output in the exhibit, what is theproblem?

A. Mismatched interface encapsulations

B. Mismatched virtual circuit ID values

C. Extended LDP neighbor not established

D. Incorrect PE-CE interface configuration

Correct Answer: DSection: Advanced MPLSExplanation

Explanation/Reference:

QUESTION 55Click on the exhibit

Page 308: JNCIP-SP JN0-661 · PDF file · 2017-07-29You must ensure that r1's IPv4 loopback address exists in r3 ... redistribute the VPN routes into OSPF. Correct Answer: D ... this route

http://www.gratisexam.com/

As shown in the exhibit, you have an MPLS network with multiple physical paths to R6. You also have fast reroute configured on your ingress LSR. Which statementis true if you experience a link failure between R2 and R4?

A. R1 will recognize the failure and immediately switch traffic to the detour LSP.

B. R2 will recognize the failure and immediately switch traffic to the detour LSP.

C. R2 will receive a PathTear message and immediately switch traffic to the detour LSP.

D. R1 will receive a PathTear message and immediately switch traffic to the detour LSP.

Correct Answer: BSection: Advanced MPLSExplanation

Explanation/Reference:

QUESTION 56You are implementing traffic engineering in your MPLS network without using CSPF. Which three constraints can you use? (Choose three)

A. bandwidth requirements

B. administrative groups

C. explicit route object

D. hop count for detour LSP

E. hold and setup priority

Correct Answer: ACESection: Advanced MPLSExplanation

Explanation/Reference:

QUESTION 57Click on the exhibit

Page 309: JNCIP-SP JN0-661 · PDF file · 2017-07-29You must ensure that r1's IPv4 loopback address exists in r3 ... redistribute the VPN routes into OSPF. Correct Answer: D ... this route

http://www.gratisexam.com/

As shown in the exhibit, you have a multi-area OSPF network and you are establishing an LSP from R1 to R6 with a loose ERO hop for R5. Though not displayed,OSPF is configured for traffic engineering. Based on the information provided, wich statement is correct?

A. The LSP is not established and usable from R1 to R6.

B. The LSP is established and usable from R1 to R6.

C. The LSP is not established because strict EROs are required from multi-area OSPF

D. The LSP is not established until you configure "propagate-ted" on the ABRs.

Correct Answer: ASection: Advanced MPLSExplanation

Explanation/Reference:

QUESTION 58You are working with a new MPLS network that is using the default EXP classifier and default schedules. A small amount of traffic is being placed in the assuredforwarding class. No other traffic is passing through the network at this time.

In this scenario, what happens to the traffic that is being placed in the assured forwarding class?

Page 310: JNCIP-SP JN0-661 · PDF file · 2017-07-29You must ensure that r1's IPv4 loopback address exists in r3 ... redistribute the VPN routes into OSPF. Correct Answer: D ... this route

http://www.gratisexam.com/

A. The traffic is reclassified to the best effort forwarding class and is forwarded.

B. The traffic remains in the assured forwarding class and is forwarded.

C. The traffic is reclassified to the network control forwarding class and is forwarded.

D. The traffic remains in the assured forwarding class and is dropped.

Correct Answer: BSection: (none)Explanation

Explanation/Reference:

QUESTION 59

Referring to the exhibit button, you are asked to ensure that traffic destined for the 5.5.5.0/24 network must use the LSP named Top.

Which two actions would you perform to accomplish this task? (Choose two.)

A. Apply the policy as an import policy for BGP on R1.

B. Create a routing policy that matches the route 5.5.5.0/24 with an action of install-nexthop lsp Top

C. Create a routing policy that matches the route 5.5.5.0/24 with an action of next-hop Top.

D. Apply the policy to the forwarding table on R1.

Correct Answer: BDSection: (none)Explanation

Page 311: JNCIP-SP JN0-661 · PDF file · 2017-07-29You must ensure that r1's IPv4 loopback address exists in r3 ... redistribute the VPN routes into OSPF. Correct Answer: D ... this route

http://www.gratisexam.com/

Explanation/Reference:

QUESTION 60A service provider wants to start using all of their LSPs for internal traffic and not just their MPLS VPNs. Any solution must ensure that existing VPNs and routingpolicies will continue to function properly.

Which MPLS traffic engineering parameter would accomplish this task?

A. bgp

B. bgp-igp-both-ribs

C. bgp-igp

D. mpls-forwarding

Correct Answer: BSection: (none)Explanation

Explanation/Reference:

QUESTION 61Click on the exhibit

Page 312: JNCIP-SP JN0-661 · PDF file · 2017-07-29You must ensure that r1's IPv4 loopback address exists in r3 ... redistribute the VPN routes into OSPF. Correct Answer: D ... this route

http://www.gratisexam.com/

The exhibit shows the partial configurations of PE1 and PE2. PE2 is unable to forward VPN data to PE1. What should be configured to solve this problem?

A. Configure an MPLS LSP from PE2 to PE1.

B. Configure a route on PE2 to PE1's loopback address in inet 0.

C. Configure a matching vrf-target statement on PE1 and PE2.

D. Configure a static default route in inet 3 on PE2.

Correct Answer: ASection: (none)Explanation

Explanation/Reference:

Page 313: JNCIP-SP JN0-661 · PDF file · 2017-07-29You must ensure that r1's IPv4 loopback address exists in r3 ... redistribute the VPN routes into OSPF. Correct Answer: D ... this route

http://www.gratisexam.com/

A label-switched path (LSP) is a path through an MPLS network.

Unusable path: Path is not usable because of one of the following conditions:The route is damped.The route is rejected by an import policy.The route is unresolved.

Incorrect Answers:C: The vrf-target statements are matching.

Reference: http://forums.juniper.net/t5/Routing/VPLS-MPLS-TE-problem/td-p/259975

QUESTION 62You work for a service provider and need to build EVPN service which provides an active/active multihoming topology using a single CE at each site.

In this scenario, which two statements are true? (Choose two.)

A. An Ethernet segment appears as a LAG to the CE device.

B. A backup designated forwarder is elected for forwarding BUM traffic to the CE device.

C. The Ethernet segment identifier must be an all zeros identifier.

D. A designated forwarder is elected for forwarding BUM traffic to the CE device.

Correct Answer: ADSection: (none)Explanation

Explanation/Reference:

QUESTION 63An LDP layer 2 circuit between PE1 and PE2 is not passing traffic. Both PE1 and PE2 show the circuit state as VM -- vlan id mismatch

Referring to the exhibit, which action will solve this problem?

http://www.gratisexam.com

Page 314: JNCIP-SP JN0-661 · PDF file · 2017-07-29You must ensure that r1's IPv4 loopback address exists in r3 ... redistribute the VPN routes into OSPF. Correct Answer: D ... this route

http://www.gratisexam.com/

Exhibit:

Page 315: JNCIP-SP JN0-661 · PDF file · 2017-07-29You must ensure that r1's IPv4 loopback address exists in r3 ... redistribute the VPN routes into OSPF. Correct Answer: D ... this route

http://www.gratisexam.com/

Page 316: JNCIP-SP JN0-661 · PDF file · 2017-07-29You must ensure that r1's IPv4 loopback address exists in r3 ... redistribute the VPN routes into OSPF. Correct Answer: D ... this route

http://www.gratisexam.com/

A. Configure interfaces PE1 ge-1/0/1.5 and PE2 ge-1/1/1.6 with the output-vlan-map pop parameter

B. Configure interfaces PE1 ge-1/0/1.5 or PE2 ge-1/1/1.6 with the output-vlan-map swap parameter

C. Configure the LDP layer 2 circuit with the no-control-word command on PE1 and PE2

D. Configure interfaces PE1 ge-1/0/1.5 and PE2 ge-1/1/1.6 with the output-vlan-map swap parameter

Correct Answer: DSection: (none)Explanation

Explanation/Reference:

Page 317: JNCIP-SP JN0-661 · PDF file · 2017-07-29You must ensure that r1's IPv4 loopback address exists in r3 ... redistribute the VPN routes into OSPF. Correct Answer: D ... this route

http://www.gratisexam.com/

Layer 3 VPNs

QUESTION 1Click the Exhibit button.

Referring to the exhibit, You have a Layer 3 VPN connecting Site 1, Site 2, and Site 3.

Site 1 and Site 3 have a backdoor IBGP connection.

You must meet these requirements:

1. Ensure that PE2 does not advertise the routes learned from PE1 to CE3. 2. Ensure that PE1 does not advertise the routes learned from PE2 that originated from CE3. 3. All routes must be present in Site 2.

Which two statements meet these requirements? (Choose two.)

A. Use a unique origin community on each PE and tag the appropriate BGP routes when importing them from the local CE devices.

B. Use a unique origin community on each PE and tag the appropriate BGP routes when exporting them to the connected CE devices.

C. Use an export policy that matches routes with the remote origin community and blocks these routes from being advertised to the connected CE devices.

D. Use a VRF import policy that matches the routes with the remote origin community and blocks these routes from being accepted.

Correct Answer: ACSection: Layer 3 VPNs

Page 318: JNCIP-SP JN0-661 · PDF file · 2017-07-29You must ensure that r1's IPv4 loopback address exists in r3 ... redistribute the VPN routes into OSPF. Correct Answer: D ... this route

http://www.gratisexam.com/

Explanation

Explanation/Reference:

QUESTION 2Which configuration supports interprovider Layer 3 VPN option B on ASBR1 as shown in the exhibit.

Click the Exhibit button

http://www.gratisexam.com

Exhibit:

A. [edit] user@router# show interfaces { ge-1/0/0 { unit 0 { family inet { address 10.0.0.1/31; } family mpls; } } } routing-options { autonomous-system 1; } protocols { mpls { interface ge-1/0/0.0; } bgp { group ebgp { family inet { unicast;

Page 319: JNCIP-SP JN0-661 · PDF file · 2017-07-29You must ensure that r1's IPv4 loopback address exists in r3 ... redistribute the VPN routes into OSPF. Correct Answer: D ... this route

http://www.gratisexam.com/

} family inet-vpn { unicast; } neighbor 10.0.0.2 { peer-as 2; } } }

B. user@router# show interfaces { ge-1/0/0 { unit 0 { family inet { address 10.0.0.1/31; } family mpls; } } } routing-options { autonomous-system 1; } protocols { mpls { interface ge-1/0/0.0; } bgp { group ebgp { family inet { unicast; } family route-target; neighbor 10.0.0.2 { peer-as 2; } } } }

C. [edit] user@router# show interfaces {

Page 320: JNCIP-SP JN0-661 · PDF file · 2017-07-29You must ensure that r1's IPv4 loopback address exists in r3 ... redistribute the VPN routes into OSPF. Correct Answer: D ... this route

http://www.gratisexam.com/

ge-1/0/0 { unit 0 { family inet { address 10.0.0.1/31; } } } } routing-options { autonomous-system 1; } protocols { mpls { interface ge-1/0/0.0; } bgp { group ebgp { family inet { unicast; } family inet-vpn { unicast; } neighbor 10.0.0.2 { peer-as 2; } } } }

D. [edit] user@router# show interfaces { ge-1/0/0 { unit 0 { family inet { address 10.0.0.1/31; } family mpls; } } } routing-options {

Page 321: JNCIP-SP JN0-661 · PDF file · 2017-07-29You must ensure that r1's IPv4 loopback address exists in r3 ... redistribute the VPN routes into OSPF. Correct Answer: D ... this route

http://www.gratisexam.com/

autonomous-system 1; } protocols { mpls { interface ge-1/0/0.0; } bgp { group ebgp { family inet { labeled-unicast; } neighbor 10.0.0.2 { peer-as 2; } } }

Correct Answer: ASection: Layer 3 VPNsExplanation

Explanation/Reference:Specify the mpls address family on the Fast Ethernet interface.

Specify the inet-vpn address family and unicast traffic type to enable BGP to carry IPv4 network layer reachability information (NLRI) for VPN routes.

Incorrect Answers:B, D: BGP is the configured inet address family, but inet-vpn is required.C: The interface lacks the family mpls statement.

Reference: https://www.juniper.net/documentation/en_US/junos16.1/topics/example/mpls-vpn-option2-configuration.html

QUESTION 3Click the Exhibit button.

[edit] user@PE1# show protocols

rsvp { interface all; } mpls {

Page 322: JNCIP-SP JN0-661 · PDF file · 2017-07-29You must ensure that r1's IPv4 loopback address exists in r3 ... redistribute the VPN routes into OSPF. Correct Answer: D ... this route

http://www.gratisexam.com/

label-switched-path p1 { from 1.1.1.1; to 4.4.4.4; no-cspf; } interface all; } bgp { group Int { type internal; local-address 1.1.1.1; family inet { unicast; } family inet-vpn { unicast; } neighbor 2.2.2.2; neighbor 3.3.3.3; neighbor 4.4.4.4; } } ospf { area 0.0.0.0 { interface ge-0/0/2.0; interface lo0.0; } }

[edit] user@PE1# show routing-instances CE-1

instance-type vrf; interface ge-0/0/1.0; route-distinguisher 65305:395; vrf-target target:65412:100; routing-options { static { route 100.100.100.0/24 next-hop { 192.168.1.100; } } }

Page 323: JNCIP-SP JN0-661 · PDF file · 2017-07-29You must ensure that r1's IPv4 loopback address exists in r3 ... redistribute the VPN routes into OSPF. Correct Answer: D ... this route

http://www.gratisexam.com/

[edit] user@PE1# show protocols

rsvp { interface all; } mpls { interface all; } ospf { area 0.0.0.0 { interface ge-0/0/1.0; interface ge-0/0/2.0; interface lo0,0; } }

[edit] user@PE2# show protocols

rsvp { interface all; } mpls { interface all; } ospf { area 0.0.0.0 { interface ge-0/0/1.0; interface ge-0/0/2.0; interface lo0,0; } }

[edit] user@PE2# show protocols

rsvp { interface all; } mpls { label-switched-path p2 {

Page 324: JNCIP-SP JN0-661 · PDF file · 2017-07-29You must ensure that r1's IPv4 loopback address exists in r3 ... redistribute the VPN routes into OSPF. Correct Answer: D ... this route

http://www.gratisexam.com/

from 4.4.4.4; to 1.1.1.1; no-cspf; } interface all; } bgp { group Int { type internal; local address 4.4.4.4; family inet { unicast; } family inet-vpn { unicast; } neighbor 2.2.2.2; neighbor 3.3.3.3; neighbor 1.1.1.1; } } ospf { area 0.0.0.0 { interface ge-0/0/2.0; interface lo0.0; } }

[edit] user@PE2# show routing-instances CE-2

instance-type vrf; interface ge-0/0/1.0; route-distinguisher 65305:395; vrf-target target:64512:100; routing-options { static { route 200.200.200.0/24 next-hop { 10.1.1.100; } } }

Page 325: JNCIP-SP JN0-661 · PDF file · 2017-07-29You must ensure that r1's IPv4 loopback address exists in r3 ... redistribute the VPN routes into OSPF. Correct Answer: D ... this route

http://www.gratisexam.com/

Referring to the exhibit, you have configured an L3VPN that connects Site-1 and Site-2 together, but the BGP routes are not showing up on the PE routers. The topology in this scenario is shown below.

Site-1 > PE-1 > P-1 > P-2 > PE-2 > Site-2

Which action should you take to allow communication between Site-1 and Site-2?

A. Enable LDP for all interfaces on all routes.

B. Change the route distinguisher to be different on PE-1 and PE-2.

C. Change the route target to match on PE-1 and PE-2.

D. Configure BGP on P-1 and P-2.

Correct Answer: CSection: Layer 3 VPNsExplanation

Explanation/Reference:If routes from the local CE router are not present in the bgp.l3vpn.0 routing table on the remote PE router, do the following:

1. Check the VRF import filter on the remote PE router, which is configured in the vrf-importstatement. (On the local PE router, you check the VRF export filter,which is configured with the vrf-export statement.)

2. Check that there is an operational LSP or an LDP path between the PE routers. To do this, check that the IBGP next-hop addresses are in the inet.3 table.3. Check that the IBGP session between the PE routers is established and configured properly.4. Check for “hidden” routes, which usually means that routes were not labeled properly. To do this, use the show route table bgp.l3vpn.0 hidden command.5. Check that the inner label matches the inner VPN label that is assigned by the local PE router. To do this, use the show route table mpls command.

Reference: https://www.juniper.net/documentation/en_US/junos/topics/task/troubleshooting/layer-three-vpns-diagnosing-common-problems.html

QUESTION 4Click the Exhibit button.

[edit] user@PE-1# show protocols rsvp { interface all; } mpls { label-switched-path p1 { from 1.1.1.1; to 4.4.4.4;

Page 326: JNCIP-SP JN0-661 · PDF file · 2017-07-29You must ensure that r1's IPv4 loopback address exists in r3 ... redistribute the VPN routes into OSPF. Correct Answer: D ... this route

http://www.gratisexam.com/

no cspf; } interface all; } bgp { group Int { type Internal; local-address 1.1.1.1; family inet { unicast; } family inet-vpn { unicast; } neighbor 2.2.2.2; neighbor 3.3.3.3; neighbor 4.4.4.4; } } ospf { area 0.0.0.0 { interface ge-0/0/2.0; interf lo0.0; } }

[edit] user@p-1# show protocols

mpls { interface all; } ospf { area 0.0.0.0 { interface ge-0/0/1.0; interface ge-0/0/2.0; interface ge-1o0.0; } }

[edit] user@p-2# show protocols

Page 327: JNCIP-SP JN0-661 · PDF file · 2017-07-29You must ensure that r1's IPv4 loopback address exists in r3 ... redistribute the VPN routes into OSPF. Correct Answer: D ... this route

http://www.gratisexam.com/

mpls { interface all; } ospf { area 0.0.0.0 { interface ge-0/0/1.0; interface ge-0/0/2.0; interface ge-lo0.0; } }

[edit] user@p-2# show protocols

rsvr { interface all; } mpls { label-switched-path p2 { from 4.4.4.4; to 1.1.1.1; no-ospf; } interface all; } bgp { group INT { type internal; local-address 4.4.4.4, family inet { unicast; } neighbor 2.2.2.2; neighbor 3.3.3.3; neighbor 1.1.1.1; } } ospf { area 0.0.0.0 { interface ge-0/0/2.0; interface 1o0; } }

Page 328: JNCIP-SP JN0-661 · PDF file · 2017-07-29You must ensure that r1's IPv4 loopback address exists in r3 ... redistribute the VPN routes into OSPF. Correct Answer: D ... this route

http://www.gratisexam.com/

Referring to the exhibit, you have configured an L3VPN that connects Site-1 and Site-2 together, but the BGP routes are being hidden on the PE routers. Thetopology in this scenario is shown below.

Site-1 > PE-1 > P-1 > P-2 > PE-2 > Site-2

Which two actions would allow communication Site-1 and Site-2? (Choose two.)

A. Disable CSPF on under MPLS on P-1 and P-2.

B. Configure DGP on P-1 and P-2.

C. Enable RSVP for all interfaces on P-1 and P-2.

D. Enable LDP for all interfaces on all routers.

Correct Answer: ACSection: Layer 3 VPNsExplanation

Explanation/Reference:Hidden routes usually means that routes were not labeled properly. You should enable RSVP or LDP on all routers. RSVP is already configured on PE-1 so we onlyneed to configure it on P-1 and P-2.

References:

https://packetcorner.wordpress.com/2013/01/30/mpls-l3vpn/

https://packetcorner.wordpress.com/2013/01/30/mpls-l3vpn/

QUESTION 5Click the Exhibit button.

Page 329: JNCIP-SP JN0-661 · PDF file · 2017-07-29You must ensure that r1's IPv4 loopback address exists in r3 ... redistribute the VPN routes into OSPF. Correct Answer: D ... this route

http://www.gratisexam.com/

As a network administrator, you are asked to configure the VPN-B routing instance so that P routers are masked in CE2-to-CE5 trace routes. For the VPN-A routinginstance, P routers should appear in CE1-to- CE4 trace routes.

Referring to the exhibit, which two actions achieve this task? (Choose two.)

A. Add the no-vrf-propagate-ttl statement to the VPN-B routing instance on PE1.

B. Add the no-vrf-propagate-ttl statement on egress router PE2.

C. Add the no-vrf-propagate-ttl statement on transit router P.

D. Add the no-vrf-propagate-ttl statement to the VPN-B routing instance on PE2.

Correct Answer: ACSection: Layer 3 VPNsExplanation

Explanation/Reference:You do not need to include the no-vrf-propagate-ttl statement on the egress router (PE2).

Reference: Junos OS, Layer 3 VPNs Configuration Guide, page 208

QUESTION 6Which routing instance type is used with a Layer 3 VPN?

A. l2vpn

B. virtual-switch

C. vrf

D. vpls

Correct Answer: CSection: Layer 3 VPNs

Page 330: JNCIP-SP JN0-661 · PDF file · 2017-07-29You must ensure that r1's IPv4 loopback address exists in r3 ... redistribute the VPN routes into OSPF. Correct Answer: D ... this route

http://www.gratisexam.com/

Explanation

Explanation/Reference:Use the VPN routing and forwarding routing (VRF) instance type for Layer 3 VPN implementations.

Reference: https://www.juniper.net/documentation/en_US/junos15.1/topics/concept/routing-instancesoverview.html

QUESTION 7What are two characteristics of L3VPNs? (Choose two.)

A. Matching route targets are required for L3VPNs to function Correctly.

B. Multiprotocol BGP is required for L3VPNs to function Correctly.

C. The IPv4 NLRI is required for L3 VPNs to function Correctly.

D. Matching route distinguisher are required for L3VPNs to function Correctly.

Correct Answer: ADSection: Layer 3 VPNsExplanation

Explanation/Reference:D: When customer networks that use private addresses connect to the Internet infrastructure, the private addresses might overlap with the same private addressesused by other network users. MPLS/BGP VPNs solve this problem by adding a route distinguisher.

A: The PE router uses the route target to constrain the import of remote routes into its VRF tables.

Incorrect Answer:

B: Multiprotocol BGP is not required for L3VPNs.

Note: Multiprotocol Extensions for BGP (MBGP), sometimes referred to as Multiprotocol BGP or Multicast BGP and defined in IETF RFC 4760, is an extension toBorder Gateway Protocol (BGP) that allows different types of addresses (known as address families) to be distributed in parallel.

In Junos OS, Layer 3 VPNs are based on RFC 4364. RFC 4364 VPNs are also known as

BGP/MPLS VPNs because BGP is used to distribute VPN routing information across the provider's backbone, and MPLS is used to forward VPN traffic across thebackbone to remote VPN sites.

Reference: http://www.juniper.net/documentation/en_US/junos15.1/topics/concept/layer-3-vpn-overview.html

Page 331: JNCIP-SP JN0-661 · PDF file · 2017-07-29You must ensure that r1's IPv4 loopback address exists in r3 ... redistribute the VPN routes into OSPF. Correct Answer: D ... this route

http://www.gratisexam.com/

QUESTION 8Click the Exhibit button.

ISP1 has created an L3VPN to connect CE1 and CE2. The PE-CE routing protocol is OSPF.

Referring to the exhibit, which technology will allow CE1 to receive Type 1 and Type 2 LSAs from CE2?

A. OSPF sham links

B. RIB groups

C. OSPF domain IDs

D. OSPF virtual links

Correct Answer: ASection: Layer 3 VPNsExplanation

Explanation/Reference:OSPF requires that all areas in an autonomous system (AS) must be physically connected to the backbone area (area 0). In large networks with many areas, inwhich direct connectivity between all areas and the backbone area is physically difficult or impossible.

The sham link is a logical intra-area link between VRF's on PE 1 and PE 2. OSPF creates an adjacency and exchanges LSAs across the sham link. As a result,OSPF sees both the path over the backdoor link and the path over the backbone as intra-area paths. OSPF then selects the best path based on the metrics of thelinks and selects the sham link path, ensuring that the backdoor link is not used.

Incorrect Answers:B: A RIB group is a way to have a routing protocol, in most cases, place information in multiple route tables.

C: When OSPF is used as the routing protocol on a provider edge to customer edge (PE-CE) link in a multiprotocol label switching (MPLS) VPN. PE routers markOSPF routes with the domain attribute derived from the OSPF process number to indicate whether the route originated within the same OSPF domain or fromoutside it. If the OSPF process numbering is inconsistent on PE routers in the MPLS VPN, the domain-id OSPF mode command should be used to mark that theOSPF processes with different numbers belong to the same OSPF domain.

Reference: https://www.juniper.net/documentation/en_US/junose15.1/topics/concept/ospf-sham-links-overview.html

Page 332: JNCIP-SP JN0-661 · PDF file · 2017-07-29You must ensure that r1's IPv4 loopback address exists in r3 ... redistribute the VPN routes into OSPF. Correct Answer: D ... this route

http://www.gratisexam.com/

QUESTION 9PE1 and PE2 provide a BGP-signaled VPLS service named VPN Blue. PE1 has site ID 2, label base 2500, and label offset 1. PE2 has site ID 4, label base 3000,and label offset 1.

Which label does PE2 expect to receive on VPLS VPN Blue traffic received from PE1 site ID 2?

A. 2505

B. 5499

C. 2503

D. 3001

Correct Answer: CSection: Layer 3 VPNsExplanation

Explanation/Reference:The formula used is VPN label = label-base-remote + local-site-id ?label-offset-remote, which here is 2500 + 4 -1 = 2503.

https://inetzero.com/verifying-a-bgp-signaled-vpls/

QUESTION 10Click the Exhibit. The exhibit shows the partial configurations of PE1 and PE2. PE2 is unable to forward VPN data to PE1.

Page 333: JNCIP-SP JN0-661 · PDF file · 2017-07-29You must ensure that r1's IPv4 loopback address exists in r3 ... redistribute the VPN routes into OSPF. Correct Answer: D ... this route

http://www.gratisexam.com/

What should be configured to solve this problem?

http://www.gratisexam.com

A. Configure an MPLS LSP from PE2 to PE1.

B. Configure a route on PE2 to PE1's loopback address in inet 0.

C. Configure a matching vrf-target statement on PE1 and PE2.

D. Configure a static default route in inet 3 on PE2.

Correct Answer: ASection: Layer 3 VPNs

Page 334: JNCIP-SP JN0-661 · PDF file · 2017-07-29You must ensure that r1's IPv4 loopback address exists in r3 ... redistribute the VPN routes into OSPF. Correct Answer: D ... this route

http://www.gratisexam.com/

Explanation

Explanation/Reference:A label-switched path (LSP) is a path through an MPLS network.

Path is not usable because of one of the following conditions: The route is damped. The route is rejected by an import policy. The route is unresolved.

InAnswer:

C: The vrf-target statements are matching.

http://forums.juniper.net/t5/Routing/VPLS-MPLS-TE-problem/td-p/259975

QUESTION 11Click the Exhibit button.

Referring to the exhibit, You have a Layer 3 VPN connecting Site 1, Site 2, and Site 3. Site 1 and Site 3 have a backdoor IBGP connection. You must meet theserequirements:

1. Ensure that PE2 does not advertise the routes learned from PE1 to CE3.

2. Ensure that PE1 does not advertise the routes learned from PE2 that originated from CE3.

3. All routes must be present in Site 2.

Page 335: JNCIP-SP JN0-661 · PDF file · 2017-07-29You must ensure that r1's IPv4 loopback address exists in r3 ... redistribute the VPN routes into OSPF. Correct Answer: D ... this route

http://www.gratisexam.com/

Which two statements meet these requirements? (Choose two.)

A. Use a unique origin community on each PE and tag the appropriate BGP routes when importing them from the local CE devices.

B. Use a unique origin community on each PE and tag the appropriate BGP routes when exporting them to the connected CE devices.

C. Use an export policy that matches routes with the remote origin community and blocks these routes from being advertised to the connected CE devices.

D. Use a VRF import policy that matches the routes with the remote origin community and blocks these routes from being accepted.

Correct Answer: ACSection: Layer 3 VPNsExplanation

Explanation/Reference:

QUESTION 12You are asked to share a customer's routes between two separate Layer 3 VPNs. The VPNs must remain separate. None of the shared routes should be sent to theremote PE devices.

Which two configuration elements are used to meet these requirements? (Choose two.)

A. auto-export

B. export-rib

C. [edit policy-options policy-statement vpnb-export]user@router# showterm 1 { from { protocol bgp; interface ge-0/0/1.0; } then { community add vpnb-target; accept; }}term 2 { then reject;}

D. [edit policy-options policy-statement vpnb-export]user@router# showterm 1 {

Page 336: JNCIP-SP JN0-661 · PDF file · 2017-07-29You must ensure that r1's IPv4 loopback address exists in r3 ... redistribute the VPN routes into OSPF. Correct Answer: D ... this route

http://www.gratisexam.com/

from { protocol bgp; interface ge-0/0/1.0; } then { community add vpnb-target; accept; }}

Correct Answer: ACSection: Layer 3 VPNsExplanation

Explanation/Reference:

QUESTION 13You have a Layer 3 VPN established between Site 1 and Site 2. You are asked to limit the number of OSPF routes that the PE devices will accept from the CEs.

Which statement is correct?

A. You should use the prefix-limit feature to limit the number of accepted routes.

B. You should use the allow feature to limit the accepted routes.

C. You should use the route-target filtering feature to limit the accepted routes.

D. You should use the maximum-prefixes feature to limit the number of accepted routes.

Correct Answer: DSection: Layer 3 VPNsExplanation

Explanation/Reference:

QUESTION 14You are asked to provide Layer 3 VPN services to a new customer site. The site will connect to the Layer 3 VPN using a Layer 2 switch. Which two configurationelements meet the requirement? (Choose two.)

A. vrf-table-label

B. vt interface

Page 337: JNCIP-SP JN0-661 · PDF file · 2017-07-29You must ensure that r1's IPv4 loopback address exists in r3 ... redistribute the VPN routes into OSPF. Correct Answer: D ... this route

http://www.gratisexam.com/

C. vrf-target

D. vrf-export

Correct Answer: ABSection: Layer 3 VPNsExplanation

Explanation/Reference:

QUESTION 15You have an existing Layer 3 VPN connecting Site 1 and Site 2. Both CE devices are in the same autonomous system and are sharing routes with your PE devicesusing EBGP. You must share routes between the sites.

Which BGP configuration parameter must you use?

A. Advertise-inactive

B. Remove-private

C. As-override

D. Multihop

Correct Answer: CSection: Layer 3 VPNsExplanation

Explanation/Reference:

QUESTION 16You operate a Layer 3 VPN for multiple customers. To support advanced route filtering on your PE routers, you must advertise more than one BGP community onadvertised VPN routes to remote PE routers. Which routing-instance configuration parameter supports this requirement?

A. vrf-import

B. vrf-export

C. vrf-target import

D. vrf-target export

Correct Answer: BSection: Layer 3 VPNsExplanation

Page 338: JNCIP-SP JN0-661 · PDF file · 2017-07-29You must ensure that r1's IPv4 loopback address exists in r3 ... redistribute the VPN routes into OSPF. Correct Answer: D ... this route

http://www.gratisexam.com/

Explanation/Reference:

QUESTION 17Click the Exhibit button

You manage the network in the exhibit. Your customer contacts you and requests that OSPF traffic being routed between CE-2 and CE-3 use the VPN connectioninstead of the direct connection in its local network.

In addition to creating a sham link between PE-2 and PE-3, what step is required?

A. Set the sham link remote metric to be lower than 8.

B. Set the sham link local metric to be lower than 8.

C. Set the sham link preference to be lower than 8.

D. Set the sham link interface metric to be lower than 8.

Correct Answer: ASection: Layer 3 VPNsExplanation

Explanation/Reference:

QUESTION 18Click the Exhibit button.

Page 339: JNCIP-SP JN0-661 · PDF file · 2017-07-29You must ensure that r1's IPv4 loopback address exists in r3 ... redistribute the VPN routes into OSPF. Correct Answer: D ... this route

http://www.gratisexam.com/

In the exhibit, R1 is advertising a BGP route into both IS-IS and OSPF. There is mutual redistribution from R1 and R2 into both OSPF and IS-IS.

The following traceroute is performed on R4:

What is one way to fix the routing loop?

A. On all routers:[edit]user@router# set protocols bgp preference 145

Page 340: JNCIP-SP JN0-661 · PDF file · 2017-07-29You must ensure that r1's IPv4 loopback address exists in r3 ... redistribute the VPN routes into OSPF. Correct Answer: D ... this route

http://www.gratisexam.com/

B. On all routers:[edit]user@router# set protocols isis level 2 wide-metrics-only

C. On all routers:[edit]user@router# set protocols ospf external-preference 180

D. On all routers:[edit]user@router# set protocols ospf referenced bandwidth 10g

Correct Answer: ASection: Layer 3 VPNsExplanation

Explanation/Reference:

QUESTION 19Click the Exhibit button.

Customer A wants a Layer 3 VPN between their two sites. To support this, you purchase a carrier- of-carriers solution from ISP2. Referring to the topology in theexhibit, how many labels does PE1 push onto data packets destined for PE2?

A. 1

B. 2

C. 3

D. 4

Page 341: JNCIP-SP JN0-661 · PDF file · 2017-07-29You must ensure that r1's IPv4 loopback address exists in r3 ... redistribute the VPN routes into OSPF. Correct Answer: D ... this route

http://www.gratisexam.com/

Correct Answer: CSection: Layer 3 VPNsExplanation

Explanation/Reference:

QUESTION 20Click the Exhibit button.

Referring to the exhibit, Customer A is complaining that no OSPF routes are being received across your Layer 3 VPN. You suspect that a problem exists with thePE-CE protocol. The core network is operational. Which operational command on PE1 helps troubleshoot this problem?

A. show ospf neighbor

B. show bgp summary

C. show ospf neighbor instance customer-a

D. show bgp summary instance customer-a

Correct Answer: CSection: Layer 3 VPNsExplanation

Explanation/Reference:

QUESTION 21Click the Exhibit button.

Page 342: JNCIP-SP JN0-661 · PDF file · 2017-07-29You must ensure that r1's IPv4 loopback address exists in r3 ... redistribute the VPN routes into OSPF. Correct Answer: D ... this route

http://www.gratisexam.com/

After adding Customer C to your Layer 3 VPN, you must validate that PE2 is receiving VPN routes for all customers attached to PE1, as shown in the exhibit. Whichoperational command displays this information?

A. show route instance

B. show route summary

C. show route table bgp.l3vpn.0

D. show route table customer-c.inet.0

Correct Answer: CSection: Layer 3 VPNsExplanation

Explanation/Reference:

QUESTION 22You are adding nonforwarding route reflectors to your network. Which three actions ensure that VPN routes are advertised properly? (Choose three.)

http://www.gratisexam.com

Page 343: JNCIP-SP JN0-661 · PDF file · 2017-07-29You must ensure that r1's IPv4 loopback address exists in r3 ... redistribute the VPN routes into OSPF. Correct Answer: D ... this route

http://www.gratisexam.com/

A. Use rib-groups to add IGP routes to inet.3 and/or inet6.3 on the route reflectors.

B. Add MPLS LSPs between the route reflectors and their client routers.

C. Add the route reflectors to the same IGP domain as their clients.

D. Use rib-groups to add VPN routes to inet.0 and/or inet6.0 on the route reflectors.

E. Add a static default route to inet.3 and/or inet6.3 on the route reflectors.

Correct Answer: ABESection: Layer 3 VPNsExplanation

Explanation/Reference:

QUESTION 23Click the Exhibit button.

Given the existing operational network shown in the exhibit, you now want to add a remote site for Customer B to the PE3 router. This change should not have aneffect on the existing BGP sessions between the PE routers. Which Layer 3 VPN scaling mechanism allows PE3 to begin receiving Customer B routes?

A. route origin

B. route refresh

C. route reflection

Page 344: JNCIP-SP JN0-661 · PDF file · 2017-07-29You must ensure that r1's IPv4 loopback address exists in r3 ... redistribute the VPN routes into OSPF. Correct Answer: D ... this route

http://www.gratisexam.com/

D. route target filtering

Correct Answer: BSection: Layer 3 VPNsExplanation

Explanation/Reference:

QUESTION 24You just added route reflectors to your network and you find that all of your VPN routes are hidden on the route reflectors. What three solutions can you use to solvethis? (Choose three.)

A. Use rib-groups to add IGP routes to inet.3 and/or inet6.3 on all of the client routers.

B. Add MPLS LSPs between the route reflectors and their client routers.

C. Apply a next-hop-self export policy on each of the route reflectors.

D. Use rib-groups to add IGP routes to inet.3 and/or inet6.3 on the route reflectors.

E. Add a static default route to inet.3 and/or inet6.3 on the route reflectors.

Correct Answer: BDESection: Layer 3 VPNsExplanation

Explanation/Reference:

QUESTION 25Click the Exhibit button.

Page 345: JNCIP-SP JN0-661 · PDF file · 2017-07-29You must ensure that r1's IPv4 loopback address exists in r3 ... redistribute the VPN routes into OSPF. Correct Answer: D ... this route

http://www.gratisexam.com/

In the exhibit, your Layer 3 VPN uses BGP to send and receive routes from customers. Customer A reports that remote routes are not being received onCE2.Which configuration parameter is missing from your PE router configuration?

A. vrf-import

B. vrf-export

C. as-override

D. advertise-peer-as

Correct Answer: CSection: Layer 3 VPNsExplanation

Explanation/Reference:

QUESTION 26Click the Exhibit button.

Page 346: JNCIP-SP JN0-661 · PDF file · 2017-07-29You must ensure that r1's IPv4 loopback address exists in r3 ... redistribute the VPN routes into OSPF. Correct Answer: D ... this route

http://www.gratisexam.com/

Customer A is complaining that routes advertised from the CE2 router are not being received on the CE1 router. The physical topology of the network is CE1-PE1-PE2-CE2. The CE1-PE1 subnet is 172.16.1.0/24. The CE2-PE2 subnet is 172.16.2.0/24. PE1's loopback is 192.168.3.1 and PE2's loopback is192.168.4.1.Referring to the output in the exhibit, what is the problem?

A. No LSP exists between PE1 and PE2.

B. Route targets are not properly configured.

C. as-override is not configured in the VRFs.

D. family inet-vpn is not configured on the PEs.

Correct Answer: ASection: Layer 3 VPNsExplanation

Explanation/Reference:

QUESTION 27You are facing BGP scaling issues and decide to add dedicated route reflectors to your network. You notice that VPN routes are not being advertised by your routereflectors. Which three actions can you take to solve this? (Choose three.)

Page 347: JNCIP-SP JN0-661 · PDF file · 2017-07-29You must ensure that r1's IPv4 loopback address exists in r3 ... redistribute the VPN routes into OSPF. Correct Answer: D ... this route

http://www.gratisexam.com/

A. Add a static default route to inet.3 and/or inet6.3 on the route reflectors.

B. Add a full mesh of MPLS LSPs between all of the route reflectors.

C. Add MPLS LSPs between the route reflectors and their client routers.

D. Add a static default route to inet.3 and/or inet6.3 on all of the client routers.

E. Use rib-groups to add IGP routes to inet.3 and/or inet6.3 on the route reflectors.

Correct Answer: ACESection: Layer 3 VPNsExplanation

Explanation/Reference:

QUESTION 28Click the Exhibit button.

Referring to the exhibit, your network management systems have alerted you to a loss of connectivity to the CE2 router in your Layer 3 VPN. The loopback addressof the CE router is 10.10.1.1/32.Which operational command on PE2 verifies connectivity across the PE-CE link?

A. ping 10.10.1.1

B. ping 10.10.1.1 table customer-a

C. ping 10.10.1.1 instance customer-a

D. ping 10.10.1.1 routing-instance customer-a

Correct Answer: D

Page 348: JNCIP-SP JN0-661 · PDF file · 2017-07-29You must ensure that r1's IPv4 loopback address exists in r3 ... redistribute the VPN routes into OSPF. Correct Answer: D ... this route

http://www.gratisexam.com/

Section: Layer 3 VPNsExplanation

Explanation/Reference:

QUESTION 29Click the Exhibit button.

Referring to the exhibit, you want to save CPU processing load on the PE3 router by preventing the reception of routes belonging to Customer B. Which Layer 3VPN scaling mechanism provides this functionality?

A. route origin

B. route refresh

C. route reflection

D. route target filtering

Correct Answer: DSection: Layer 3 VPNsExplanation

Explanation/Reference:

Page 349: JNCIP-SP JN0-661 · PDF file · 2017-07-29You must ensure that r1's IPv4 loopback address exists in r3 ... redistribute the VPN routes into OSPF. Correct Answer: D ... this route

http://www.gratisexam.com/

QUESTION 30You are provisioning a new customer for access to your Layer 3 VPN. The customer is using 172.16.35.0/24 as their internal IP address space, which is also beingused by an existing Layer 3 VPN customer. The two customers share many PE routers in common across your network. Which mechanism allows these duplicateaddresses to exist in your network?

A. route origin

B. route target

C. route refresh

D. route distinguisher

Correct Answer: DSection: Layer 3 VPNsExplanation

Explanation/Reference:

QUESTION 31Which configuration supports interprovider Layer 3 VPN option B on ASBR1 as shown in the exhibit.

Click the Exhibit button.

Exhibit:

A. [edit]user@router# showinterfaces { ge-1/0/0 { unit 0 { family inet { address 10.0.0.1/31; } family mpls; } }}routing-options { autonomous-system 1;}protocols { mpls {

Page 350: JNCIP-SP JN0-661 · PDF file · 2017-07-29You must ensure that r1's IPv4 loopback address exists in r3 ... redistribute the VPN routes into OSPF. Correct Answer: D ... this route

http://www.gratisexam.com/

interface ge-1/0/0.0; } bgp { group ebgp { family inet { unicast; } family inet-vpn { unicast; } neighbor 10.0.0.2 { peer-as 2; } } }}

B. [edit]user@router# showinterfaces { ge-1/0/0 { unit 0 { family inet { address 10.0.0.1/31; } family mpls; } }}routing-options { autonomous-system 1;}protocols { mpls { interface ge-1/0/0.0; } bgp { group ebgp { family inet { unicast; } family route-target;{ neighbor 10.0.0.2 {

Page 351: JNCIP-SP JN0-661 · PDF file · 2017-07-29You must ensure that r1's IPv4 loopback address exists in r3 ... redistribute the VPN routes into OSPF. Correct Answer: D ... this route

http://www.gratisexam.com/

peer-as 2; } } }}

C. [edit]user@router# showinterfaces { ge-1/0/0 { unit 0 { family inet { address 10.0.0.1/31; } } }}routing-options { autonomous-system 1;}protocols { mpls { interface ge-1/0/0.0; } bgp { group ebgp { family inet { unicast; } family inet-vpn { unicast; } neighbor 10.0.0.2 { peer-as 2; } } }}

D. [edit]user@router# showinterfaces { ge-1/0/0 { unit 0 {

Page 352: JNCIP-SP JN0-661 · PDF file · 2017-07-29You must ensure that r1's IPv4 loopback address exists in r3 ... redistribute the VPN routes into OSPF. Correct Answer: D ... this route

http://www.gratisexam.com/

family inet { address 10.0.0.1/31; } family mpls; } }}routing-options { autonomous-system 1;}protocols { mpls { interface ge-1/0/0.0; } bgp { group ebgp { family inet { labeled-unicast; } neighbor 10.0.0.2 { peer-as 2; } } }}

Correct Answer: ASection: Layer 3 VPNsExplanation

Explanation/Reference:Specify the mpls address family on the Fast Ethernet interface.Specify the inet-vpn address family and unicast traffic type to enable BGP to carry IPv4 network layer reachability information (NLRI) for VPN routes.

Incorrect Answers:B, D: BGP is the configured inet address family, but inet-vpn is required.C: The interface lacks the family mpls statement.

References: https://www.juniper.net/documentation/en_US/junos16.1/topics/example/mpls-vpn-option2-configuration.html

QUESTION 32Click the Exhibit button.

Page 353: JNCIP-SP JN0-661 · PDF file · 2017-07-29You must ensure that r1's IPv4 loopback address exists in r3 ... redistribute the VPN routes into OSPF. Correct Answer: D ... this route

http://www.gratisexam.com/

PE1 configuration

interfaces { ge-1/1/0 { unit 0 { family inet { address 10.1.1.1/24; } family mpls; } } ge-1/1/1 { unit 0 { family inet6 { address 2000:FEFE::1/64; } } }}protocols { bgp { group PE2 { type internal; neighbor 10.0.0.2; } } mpls { interface ge-1/1/0.0; } ldp { interface ge-1/1/0.0;

Page 354: JNCIP-SP JN0-661 · PDF file · 2017-07-29You must ensure that r1's IPv4 loopback address exists in r3 ... redistribute the VPN routes into OSPF. Correct Answer: D ... this route

http://www.gratisexam.com/

} ospf { area 0.0.0.0 { interface lo0.0 passive; interface ge-1/1/0.0; } }}routing-instance { Customer-A { instance-type vrf; interface ge-1/1/1.0; route-distinguisher 100:101; vrf-target target:100:101; }}

ISP 1 wants to configure an IPv6 L3VPN over its IPv4-only MPLS network for Customer-A. PE1 has been configured as shown in the exhibit; however, IPv6 routesare not being passed between PE1 and PE2 in the Customer-A VPN.

In this scenario, which two commands are necessary on PE1 to enable IPv6 connectivity between CE1 and CE2? (Choose two.)

A. set protocols bgp group PE2 family inet6 unicast

B. set interfaces ge-1/1/1.0 family mpls

C. set protocols bgp group PE2 family inet6-vpn

D. set protocols mpls ipv6-tunneling

Correct Answer: ADSection: Layer 3 VPNsExplanation

Explanation/Reference:Tunneling IPv6 Traffic over MPLS IPv4 NetworksD: You enable IPv6 tunneling by including the ipv6-tunneling statement in the configuration for the PE routers.A: BGP automatically runs its import policy even when copying routes from a primary routing table group to a secondary routing table group. If IPv4 labeled routesarrive from a BGP session (for example, when you have configured the labeled-unicast statement at the [edit protocols bgp family inet] hierarchy level on the PErouter), the BGP neighbor’s import policy also accepts IPv6 routes, since the neighbor’s import policy is run while doing the copy operation to the inet6.3 routingtable.

Referencs: http://www.juniper.net/documentation/en_US/junos15.1/topics/example/mpls-tunneling-ipv6-over-mpls-ipv4.html

Page 355: JNCIP-SP JN0-661 · PDF file · 2017-07-29You must ensure that r1's IPv4 loopback address exists in r3 ... redistribute the VPN routes into OSPF. Correct Answer: D ... this route

http://www.gratisexam.com/

QUESTION 33Click the Exhibit button.

[edit]user@PE-1# show protocolsrsvp { interface all;}mpls { label-switched-path p1 { from 1.1.1.1; to 4.4.4.4; no-cspf; } interface all;}bgp { group Int { type internal; local-address 1.1.1.1; family inet { unicast; } family inet-vpn { unicast; } neighbor 2.2.2.2; neighbor 3.3.3.3; neighbor 4.4.4.4; }}ospf { area 0.0.0.0 { interface ge-0/0/2.0; interface lo0.0; }}

[edit]user@PE-1# show routing-instances CE-1instance-type vrf;interface ge-0/0/1.0;route-destinguisher 65305:395;

Page 356: JNCIP-SP JN0-661 · PDF file · 2017-07-29You must ensure that r1's IPv4 loopback address exists in r3 ... redistribute the VPN routes into OSPF. Correct Answer: D ... this route

http://www.gratisexam.com/

vrf-target target:65412:100;routing-options { static { route 100.100.100.0/24 next-hop192.168.1.100; }}

[edit]user@P-1# show protocolsrsvp { interface all;}mpls { interface all;}ospf { area 0.0.0.0 { interface ge-0/0/1.0; interface ge-0/0/2.0; interface lo0,0; }}

[edit]user@P-2# show protocolsrsvp { interface all;}mpls { interface all;}ospf { area 0.0.0.0 { interface ge-0/0/1.0; interface ge-0/0/2.0; interface lo0,0; }}

Page 357: JNCIP-SP JN0-661 · PDF file · 2017-07-29You must ensure that r1's IPv4 loopback address exists in r3 ... redistribute the VPN routes into OSPF. Correct Answer: D ... this route

http://www.gratisexam.com/

[edit]user@PE-2# show protocolsrsvp { interface all;}mpls { label-switched-path p2 { from 4.4.4.4; to 1.1.1.1; no-cspf; } interface all;}bgp { group Int { type internal; local address 4.4.4.4; family inet { unicast; } family inet-vpn { unicast; } neighbor 2.2.2.2; neighbor 3.3.3.3; neighbor 1.1.1.1; }}ospf { area 0.0.0.0 { interface ge-0/0/2.0; interface lo0.0; }}

[edit]user@PE2# show routing-instances CE-2instance-type vrf;interfcae ge-0/0/1.0;route-distinguisher 65305:395;vrf-target target:64512�:100;routing-options { static {

Page 358: JNCIP-SP JN0-661 · PDF file · 2017-07-29You must ensure that r1's IPv4 loopback address exists in r3 ... redistribute the VPN routes into OSPF. Correct Answer: D ... this route

http://www.gratisexam.com/

route 200.200.200.0/24 next-hop10.1.1.100; }}

Referring to the exhibit, you have configured an L3VPN that connects Site-1 and Site-2 together, but the BGP routes are not showing up on the PE routers. Thetopology in this scenario is shown below.

Site-1 > PE-1 > P-1 > P-2 > PE-2 > Site-2

Which action should you take to allow communication between Site-1 and Site-2?

A. Enable LDP for all interfaces on all routes.

B. Change the route distinguisher to be different on PE-1 and PE-2.

C. Change the route target to match on PE-1 and PE-2.

D. Configure BGP on P-1 and P-2.

Correct Answer: ASection: Layer 3 VPNsExplanation

Explanation/Reference:Hidden” routes usually means that routes were not labeled properly.

Label Distribution Protocol (LDP) is a protocol in which routers capable of Multiprotocol Label Switching (MPLS) exchange label mapping information. Two routerswith an established session are called LDP peers and the exchange of information is bi-directional.

References: https://www.juniper.net/documentation/en_US/junos14.2/topics/task/troubleshooting/layer-three-vpns-diagnosing-common-problems.html

QUESTION 34Click the Exhibit.

Page 359: JNCIP-SP JN0-661 · PDF file · 2017-07-29You must ensure that r1's IPv4 loopback address exists in r3 ... redistribute the VPN routes into OSPF. Correct Answer: D ... this route

http://www.gratisexam.com/

The exhibit shows the partial configurations of PE1 and PE2. PE2 is unable to forward VPN data to PE1.

What should be configured to solve this problem?

A. Configure an MPLS LSP from PE2 to PE1.

B. Configure a route on PE2 to PE1's loopback address in inet 0.

C. Configure a matching vrf-target statement on PE1 and PE2.

D. Configure a static default route in inet 3 on PE2.

Correct Answer: ASection: Layer 3 VPNsExplanation

Page 360: JNCIP-SP JN0-661 · PDF file · 2017-07-29You must ensure that r1's IPv4 loopback address exists in r3 ... redistribute the VPN routes into OSPF. Correct Answer: D ... this route

http://www.gratisexam.com/

Explanation/Reference:A label-switched path (LSP) is a path through an MPLS network.

Note: Unusable path: Path is not usable because of one of the following conditions:The route is damped.The route is rejected by an import policy.The route is unresolved.

Incorrect Answers:C: The vrf-target statements are matching.

References: http://forums.juniper.net/t5/Routing/VPLS-MPLS-TE-problem/td-p/259975

QUESTION 35In a Layer 3 VPN, which mechanism is used by a PE router to ensure received routers are placed into the correct VRF?

A. route distinguisher

B. inner label

C. route target

D. outer label

Correct Answer: CSection: Layer 3 VPNsExplanation

Explanation/Reference:

QUESTION 36Referring to the exhibit, you have configured an L3VPN that connects Site-1 and Site-2 together, but the BGP routes are not showing up on the PE routers. Thetopology in this scenario is shown below.

Site-1 > PE-1 > P-1 > P-2 > PE-2 > Site-2

Which action should you take to allow communication between Site-1 and Site-2?

Exhibit:

Page 361: JNCIP-SP JN0-661 · PDF file · 2017-07-29You must ensure that r1's IPv4 loopback address exists in r3 ... redistribute the VPN routes into OSPF. Correct Answer: D ... this route

http://www.gratisexam.com/

Page 362: JNCIP-SP JN0-661 · PDF file · 2017-07-29You must ensure that r1's IPv4 loopback address exists in r3 ... redistribute the VPN routes into OSPF. Correct Answer: D ... this route

http://www.gratisexam.com/

A. Enable LDP for all interfaces on all routes

B. Change the route distinguisher to be different on PE-1 and PE-2

C. Change the route target to match on PE-1 and PE-2.

D. Configure BGP on P-1 and P-2.

Correct Answer: CSection: (none)Explanation

Explanation/Reference:

QUESTION 37Which routing instance type is used with a Layer 3 VPN?

http://www.gratisexam.com

A. l2vpn

B. virtual-switch

C. vrf

D. vpls

Correct Answer: CSection: (none)Explanation

Explanation/Reference:

QUESTION 38What are two characteristics of L3VPNs? (Choose two.)

A. Matching route targets are required for L3VPNs for function correctly

B. Multiprotocol BGP is required for L3VPNs to function correctly

Page 363: JNCIP-SP JN0-661 · PDF file · 2017-07-29You must ensure that r1's IPv4 loopback address exists in r3 ... redistribute the VPN routes into OSPF. Correct Answer: D ... this route

http://www.gratisexam.com/

C. The IPv4 NLRI is required for L3VPNs to function correctly

D. Matching route distinguishes are required for L3VPNs to function correctly

Correct Answer: ABSection: (none)Explanation

Explanation/Reference:

QUESTION 39

ISP1 has created an L3VPN to connect CE1 and CE2. The PE-CE routing protocol is OSPF.

Referring to the exhibit, which technology will allow CE1 to receive Type 1 and Type 2 LSAs from CE2?

A. OSPF sham links

B. RIB groups

C. OSPF domain IDs

D. OSPF virtual links

Correct Answer: CSection: (none)Explanation

Explanation/Reference:

QUESTION 40Referring to the exhibit, you have a L3VPN that connect Site-1 and Site-2 together, but the BGP routers are being hidden on the PE routers. The topology in thisscenario is shown below.

Site-1>PE-1>P-1>P-2>PE-2>Site-2

Which two actions would allow communication Site-1 and Site-2? (Choose two.)

Page 364: JNCIP-SP JN0-661 · PDF file · 2017-07-29You must ensure that r1's IPv4 loopback address exists in r3 ... redistribute the VPN routes into OSPF. Correct Answer: D ... this route

http://www.gratisexam.com/

Exhibit:

Page 365: JNCIP-SP JN0-661 · PDF file · 2017-07-29You must ensure that r1's IPv4 loopback address exists in r3 ... redistribute the VPN routes into OSPF. Correct Answer: D ... this route

http://www.gratisexam.com/

Page 366: JNCIP-SP JN0-661 · PDF file · 2017-07-29You must ensure that r1's IPv4 loopback address exists in r3 ... redistribute the VPN routes into OSPF. Correct Answer: D ... this route

http://www.gratisexam.com/

A. Disable CSPF on under MPLS on P-1 and P-2

B. Configure BGP on P-1 and P-2

C. Enable RSVP for all interfaces on P-1 and P-2

D. Enable LDP for all interfaces on all routers

Correct Answer: CDSection: (none)Explanation

Explanation/Reference:

QUESTION 41

ISP 1 wants to configure an IPv6 L3VPN over its IPv4-only MPLS network for Customer-A. PE1 has been configured as shown in the exhibit; however, IPv6 routesare not being passed between PE1 and PE2 in the Customer-A VPN.

In this scenario, which two commands are necessary on PE1 to enable IPv6 connectivity between CE1 and CE2? (Choose two.)

A. set protocols bgp group PE2 family inet6 unicast

B. set interfaces ge-1/1/1.0 family mpls

C. set protocols bgp group PE2 family inet6-vpn

D. set protocols mpls ipv6-tunneling

Correct Answer: AD

Page 367: JNCIP-SP JN0-661 · PDF file · 2017-07-29You must ensure that r1's IPv4 loopback address exists in r3 ... redistribute the VPN routes into OSPF. Correct Answer: D ... this route

http://www.gratisexam.com/

Section: (none)Explanation

Explanation/Reference:

Page 368: JNCIP-SP JN0-661 · PDF file · 2017-07-29You must ensure that r1's IPv4 loopback address exists in r3 ... redistribute the VPN routes into OSPF. Correct Answer: D ... this route

http://www.gratisexam.com/

Layer 2 VPNs

QUESTION 1You are asked to design a Layer 2 VPN service between service provider networks that needs Ethernet transport capabilities. The VPN should support two or threeendpoints. Which Layer 2 VPN technology should you propose?

A. LDP-signaled VPLS

B. BGP-signaled VPLS, using the RFC 4448 Layer 2 frame format

C. LDP Layer 2 circuit, using the RFC 4448 Layer 2 frame format

D. BGP Layer 2 VPN

Correct Answer: BSection: Layer 2 VPNsExplanation

Explanation/Reference:

QUESTION 2A layer 2 circuit (RFC 4447) is established between two PE routers to provide connectivity between two customer sites.

Which two statements related to this deployment are true?

http://www.gratisexam.com

A. Kompella encapsulation is used in the data plane communications.

B. LDP must be used for the control plane communications.

C. BGP must be used for the control plane communications.

D. Martini encapsulation is used in the data plane communications.

Correct Answer: BDSection: Layer 2 VPNsExplanation

Explanation/Reference:

Page 369: JNCIP-SP JN0-661 · PDF file · 2017-07-29You must ensure that r1's IPv4 loopback address exists in r3 ... redistribute the VPN routes into OSPF. Correct Answer: D ... this route

http://www.gratisexam.com/

Junos OS substantially supports RFC 4447, Pseudowire Setup and Maintenance Using the Label Distribution Protocol (LDP).

Martini uses directed LDP to signal the VPN label between the PE devices, Kompella uses BGP to signal the VPN label between the PE devices.

References: https://www.juniper.net/documentation/en_US/junos15.1/topics/reference/standards/layer-2-circuit.html

QUESTION 3Click the Exhibit button.

[edit] user@PE-1# run show l2circuit connections Layer-2 Circuit Connections:

Legend for connection status (St) EI - - encapsulation invalid NP - - interface h/w not present MM - - mtu mismatch Dn - - down

EM - - encapsulation mismatch VC-Dn - - Virtual circuit Down CM - - control-word mismatch Up - - operational VM - - vlan id mismatch CF - - Call admission control failure OL - - no outgoing label IB - - TDM incompatible bitrare NC - - intf encaps not CCC/TCC TM - - TDM misconfiguration BK - - Backup Connection ST - - Standby Connection CB - - rcvd cell-bundle size bad SP - - Static Pseudowire LD - - local site signaled down RS - - remote site standby RD - - remote site signaled down XX - - unknown

Legend for interface status Up - - operational Dn - - down Neighbor: 4.4.4.4 Interface Type St Time last up #Up trans

Page 370: JNCIP-SP JN0-661 · PDF file · 2017-07-29You must ensure that r1's IPv4 loopback address exists in r3 ... redistribute the VPN routes into OSPF. Correct Answer: D ... this route

http://www.gratisexam.com/

ge-0/0/1.512 (vc 1) rmt OL

[edit] user@PE-1# show protocols ldp interface ge-0/0/2.0;

[edit] user@PE-1# show protocols l2circuit neighbor 4.4.4.4 { interface ge-0/0/1.512 { virtual-circuit-id 1; } }

[edit] user@PE-1# show interfaces ge-0/0/1 vlan-tagging; encapsulation vlan-ccc; unit 512 { encapsulation vlan-ccc; vlan-id 512; }

[edit] uxer@P-1 # show protocols ldp interface all;

[edit] user@P-2# show protocols ldp interface all;

[edit] user@PE-2# run show l2circuit connections Layer-2 Circuit Connections:

Legend For connection status (St) EI - - encapsulation invalid NP - - interface h/w not present MM - - mtu mismatch Dn - - down

EM - - encapsulation mismatch VC-Dn - - Virtual circuit Down CM - - control-word mismatch Up - -

Page 371: JNCIP-SP JN0-661 · PDF file · 2017-07-29You must ensure that r1's IPv4 loopback address exists in r3 ... redistribute the VPN routes into OSPF. Correct Answer: D ... this route

http://www.gratisexam.com/

operational VM - - vlan id mismatch CF - - Call admission control failure OL - - no outgoing label IB - - TDM incompatible bitrate NC - - intf encaps not CCC/TCC TM - - TDM misconfiguration BK - - Backup Connection ST - - Standby Connection CB - - rcvd cell-bundle size bad SP - - Static Psewdowire LD - - Local site signaled down RS - - remote site standby RD - - remote site signaled down XX - - unknown

Legend for interface status UP - - operational DN - - down Neighbor: 1.1.1.1 Interface Type St Time last up #Up trans ge-0/0/1.512 (vc 1) rmt OL

[edit] user@PE-2# show protocols ldp interface ge-0/0/2.0;

[edit] user@PE-2# show protocols l2circuit neighbor 1.1.1.1 { interface ge-0/0/1.512 { virtual-circuit-id 1; } }

[edit] user@PE-2# show interfaces ge-0/0/1 vlan-tagging; encapsulation vlan-ccc; unit 512 { encapsulation vlan-ccc; vlan-id 512; }

Page 372: JNCIP-SP JN0-661 · PDF file · 2017-07-29You must ensure that r1's IPv4 loopback address exists in r3 ... redistribute the VPN routes into OSPF. Correct Answer: D ... this route

http://www.gratisexam.com/

Referring to the exhibit, you have configured an L2 circuit that connects Site-1 and Site-2, but the L2 circuit is not functioning. The topology in this scenario is shown below.

Site-1 > PE-1 > P-1 > P-2 > PE-2 Site-2

Which action will allow communication between Site-1 and Site-2?

A. Change the virtual circuit identifier to 2 for PE-2.

B. Add the family inet statement under the ge-0/0/1.512 interface for PE-1 and PE-2.

C. Add the lo0 interface under the {edit protocols ldp} hierarchy for all routers.

D. Add the lo0 interface under the {edit protocols 12circuit} hierarchy for PE-1 and PE-2

Correct Answer: CSection: Layer 2 VPNsExplanation

Explanation/Reference:LDP is required as the signaling protocol for Layer 2 circuits.

You must include the loopback address in LDP. LDP is required as the signaling protocol for Layer 2 circuits. You must include the loopback address in LDP. We enable ldp on the loopback interfaces.

Incorrect Answers:A: The virtual circuit identifier is correctly set to 1 both at PE-1 and PE-2.

Reference: https://www.juniper.net/techpubs/en_US/junos12.3/topics/example/layer-two-circuits-ethernet-configuring-detailed-solutions.html

QUESTION 4Click the Exhibit button.

user@PE2# run show l2circuit connections Layer-2 Circuit Connections:

Legend for connection status (St) EI - - encapsulation invalid NP - - interface h/w not present MM - - mtu mismatch Dn - - down

EM - - encapsulation mismatch Vc-Dn - -

Page 373: JNCIP-SP JN0-661 · PDF file · 2017-07-29You must ensure that r1's IPv4 loopback address exists in r3 ... redistribute the VPN routes into OSPF. Correct Answer: D ... this route

http://www.gratisexam.com/

Virtual circuit Down CM - - control-word mismatch UP - - operational VM - - vlan id mismatch CF - - Call admission control failure OL - - no outgoing label IB - - TDM incompatible bitrate NC - - intf encaps not CCC/TCC TM - - TDM misconfiguration BK - - Backup Connection ST - - Standby Connection CB - - rcvd cell-bundle size bad SP - - Static Pseudowire LD - - local site signaled down RS - - remote sity standby RD - - remote site signaled down HS - - Hot- standby Connection XX - - unknown

Legend for interface status UP - - operational Dn - - down Neighbor: 10.10.1.1 Interface Type St Time last up #Up trans ge-1/1/1.6 (vc 2) rmt VM

[edit protocols 12circuit] user@PE2# show

neighbor 10.10.1.1. { interface ge-1/1/1.6 { virtual-circuit-id 2; encapsulation-type ethernet-vlan; } }

[edit logical-systems jpe interfaces] user@PE2# show

ge-1/1/1 { unit 6 { encapsulation vlan-ccc;

Page 374: JNCIP-SP JN0-661 · PDF file · 2017-07-29You must ensure that r1's IPv4 loopback address exists in r3 ... redistribute the VPN routes into OSPF. Correct Answer: D ... this route

http://www.gratisexam.com/

vlan-id 6; family ccc; } }

user@PE1# run show 12circuit connections

logical-system kpe Layer-2 Circuit Connections: Legend for connection status (St) EI - - encapsulation invalid NP - - interface h/w not present MM - - mtu mismatch Dn - - down

EM- - encapsulation mismatch VC-Dn - - Virtual -circuit Down CM - - control-word mismatch Up - - operational VM - - vlan id mismatch CF - - Call admission control failure OL - - no outgoing label IB - - TDM incompatible bitrate NC - - intf encaps not CCC/TCC TM - - TDM misconfiguration BK - - Backup connection ST - - Standby Connection CB - - rcvd cell-bundle size bad SP - - Static Pseudowire LD - - local site signaled down RS - - remote site standby RD - - remote site signaled down HS - - Hot- standby Connection XX - - unknown

Legend for interface status Up - - operational Dn - - down Neighbor: 10.10.1.3 Interface Type St Time last up # Up trans ge-1/0/1.5 (vc 2) rmt VM

[edit protocols 12circuit]

Page 375: JNCIP-SP JN0-661 · PDF file · 2017-07-29You must ensure that r1's IPv4 loopback address exists in r3 ... redistribute the VPN routes into OSPF. Correct Answer: D ... this route

http://www.gratisexam.com/

user@PE1# show

neighbor 10.11.1.1 { interface ge-1/0/1.5 { virtual-circuit-id 2; encapsulation-type ethernet-vlan; } }

[edit interfaces] user@PE1#

ge-1/0/1 ( unit 5 { encapsulation vlan-ccc; vlan-id 5; family ccc; } }

An LDP Layer 2 circuit between PE1 and PE2 is not passing traffic. Both PE1 and PE2 show the circuit state as VM - - vlan id mismatch. Referring to the exhibit,which action will solve this problem?

A. Configure interfaces PE1:ge-1/0/1.5 and PE2:ge-1/1/1.6 with the output-vlan-map pop parameter.

B. Configure interfaces PE1:ge-1/0/1.5 or PE2:ge-1/1/1.6 with the output-vlan-map swap parameter.

C. Configure the LDP Layer 2 circuit with the no-control-word command on PE1 and PE2.

D. Configure interfaces PE1:ge-1/0/1.5 and PE2:ge-1/1/1.6 with the output-vlan-map swap parameter.

Correct Answer: DSection: Layer 2 VPNsExplanation

Explanation/Reference:The output-vlan-map swap parameter specifies the VLAN rewrite operation to replace a VLAN tag. The outer VLAN tag of the frame is overwritten with the user-specified VLAN tag information. We do this on both interfaces.

Reference: http://www.juniper.net/techpubs/en_US/junos15.1/topics/reference/configuration-statement/swapedit-interfaces.html

QUESTION 5You are asked to deploy VPLS in your network as a new service for several customers, and you must identify the configuration and provisioning requirements for

Page 376: JNCIP-SP JN0-661 · PDF file · 2017-07-29You must ensure that r1's IPv4 loopback address exists in r3 ... redistribute the VPN routes into OSPF. Correct Answer: D ... this route

http://www.gratisexam.com/

your customers.

In this scenario, which two statements are Correct? (Choose two.)

A. CE interfaces facing the service provider must be Ethernet interfaces.

B. VLAN IDs defined on CE interfaces must be the same on both ends unless otherwise negotiated.

C. PE interfaces facing the core must have VPLS encapsulation enabled.

D. CE interfaces facing the service provider must be Layer 3 interfaces.

Correct Answer: ABSection: Layer 2 VPNsExplanation

Explanation/Reference:A: VPLS is an Ethernet-based multipoint-to-multipoint Layer 2 VPN.

B: The Ethernet interface on the first CE must use the same VLAN ID as the second CE.

Incorrect Answers:D: VPLS is an Ethernet-based multipoint-to-multipoint Layer 2 VPN.

Reference: https://www.juniper.net/techpubs/en_US/release-independent/nce/information-products/topic-collections/feature-guide-virtual-private-lan-service/feature-guide-virtual-private-lan-service.pdf

QUESTION 6You are provisioning a new VPLS on your PE router. Your customer needs to send Q-in-Q traffic across the VPLS. In this scenario, which type of encapsulation isrequired on your PE router's VPLS interface?

A. ether-vpls-over-atm-llc

B. extended-vlan-vpls

C. vlan-vpls

D. ethernet-vpls

Correct Answer: CSection: Layer 2 VPNsExplanation

Explanation/Reference:The logical encapsulation vlan-vpls have the valid interfaces type of 802.1Q and Q-in-Q.

Page 377: JNCIP-SP JN0-661 · PDF file · 2017-07-29You must ensure that r1's IPv4 loopback address exists in r3 ... redistribute the VPN routes into OSPF. Correct Answer: D ... this route

http://www.gratisexam.com/

References:

http://www.jnpr.net/techpubs/en_US/junos-space14.2/topics/concept/layer2-provisioning-overview-service-attributes.html

https://www.juniper.net/documentation/en_US/junos/topics/usage-guidelines/vpls-configuring-interface-encapsulation.html

http://forums.juniper.net/t5/Junos/VPLS-and-Q-in-Q-Port/td-p/20107

QUESTION 7Which routing instance type is used with a Layer 2 VPN?

A. l2vpn

B. vrf

C. no-forwarding

D. virtual-switch

Correct Answer: ASection: Layer 2 VPNsExplanation

Explanation/Reference:

Configuring a Layer 2 VPN Routing Instance on a VLAN-Bundled Logical Interface

The following configuration shows that the VLAN-bundled logical interface is the interface over which VPN traffic travels to the CE router and handles traffic for aCCC to which the VPN connects.

[edit routing-instances]red { instance-type l2vpn; interface ge-1/0/5.0; # VLAN-bundled logical interface route-distinguisher 10.255.69.96:100; vrf-target target:1:1; protocols { l2vpn { encapsulation-type ethernet; # For single-tag VLAN logical interface site CE_ultima { site-identifier 1; interface ge-1/0/5.0; } } }

Page 378: JNCIP-SP JN0-661 · PDF file · 2017-07-29You must ensure that r1's IPv4 loopback address exists in r3 ... redistribute the VPN routes into OSPF. Correct Answer: D ... this route

http://www.gratisexam.com/

}

Reference: https://www.juniper.net/documentation/en_US/junos/topics/example/ethernet-802-1q-vlan-bundled-interface-for-ccc-l2vpn-ri-example.html

QUESTION 8Click the Exhibit button.

Referring to the exhibit, which LDP Layer 2 circuit configuration on PE1 maps traffic to an LSP destined to the secondary loopback address of PE2?

A. [edit protocols l2circuit] user@PE1# show neighbor 10.10.10.2 { interface ge-1/1/1.1 { psn-tunnel-endpoint 10.10.10.1; virtual-circuit-id 1; encapsulation-type ethernet-vlan; } }

B. [edit protocols l2circuit] user@PE1# show neighbor 10.10.10.2 { interface ge-1/1/1.1 { virtual-circuit-id 1; encapsulation-type ethernet-vlan; } }

C. [edit protocols l2circuit] user@PE1# show neighbor 10.10.10.2 { interface ge-1/1/1.1 { psn-tunnel-endpoint 10.10.10.2; virtual-circuit-id 1; encapsulation-type ethernet-vlan;

Page 379: JNCIP-SP JN0-661 · PDF file · 2017-07-29You must ensure that r1's IPv4 loopback address exists in r3 ... redistribute the VPN routes into OSPF. Correct Answer: D ... this route

http://www.gratisexam.com/

} }

D. [edit protocols l2circuit] user@PE1# show neighbor 10.10.10.1 { interface ge-1/1/1.1 { psn-tunnel-endpoint 10.10.10.2; virtual-circuit-id 1; encapsulation-type ethernet-vlan; } }

Correct Answer: CSection: Layer 2 VPNsExplanation

Explanation/Reference:

QUESTION 9What are two characteristics of L2 circuits? (Choose two.)

http://www.gratisexam.com

A. Routing instance configuration is required for L2 circuits to function Correctly.

B. Routing instance configuration is not required for L2 circuits to function Correctly.

C. BGP is required for L2 circuits to function Correctly.

D. BGP is not required for L2 circuits to function Correctly.

Correct Answer: BDSection: Layer 2 VPNsExplanation

Explanation/Reference:B: You configure Layer 2 VPNs in a routing instance. As a result, Layer 2 VPNs have unique site and VPN identifiers. However, Layer 2 circuits do not require arouting instance configuration and instead use an alternate method of identifying circuits.

Page 380: JNCIP-SP JN0-661 · PDF file · 2017-07-29You must ensure that r1's IPv4 loopback address exists in r3 ... redistribute the VPN routes into OSPF. Correct Answer: D ... this route

http://www.gratisexam.com/

D: Layer 2 VPNs, like Layer 3 VPNs, require Border Gateway Protocol (BGP) for transport of traffic between PE routers. In contrast, Layer 2 circuits do not requireBGP. Instead, Layer 2 circuits rely on LDP and MPLS for their operation.

Reference: http://www.juniper.net/techpubs/en_US/junos12.3/topics/concept/layer-two-circuits-overview-solutions.html

QUESTION 10An L2VPN (draft-kompella-mpls-l2vpn) is established between two PE routers to provide connectivity between two customer sites.

Which two statements related to this deployment are true? (Choose two.)

A. BGP must be used for the control plane communications.

B. Kompella encapsulation is used in the data plane communications.

C. LDP must be used for the control plane communications.

D. Martini encapsulation is used in the data plane communications.

Correct Answer: ABSection: Layer 2 VPNsExplanation

Explanation/Reference:Junos OS substantially supports t RFC 4447, Pseudowire Setup and Maintenance Using the Label Distribution Protocol (LDP).

Martini uses directed LDP to signal the VPN label between the PE devices, Kompella uses BGP to signal the VPN label between the PE devices.

Reference: https://www.juniper.net/documentation/en_US/junos15.1/topics/reference/standards/layer-2-circuit.html

QUESTION 11You work for a service provider and need to build EVPN service which provides an active/active multihoming topology using a single CE at each site.

In this scenario, which two statements are true? (Choose two.)

A. An Ethernet segment appears as a LAG to the CE device.

B. A backup designated forwarder is elected for forwarding BUM traffic to the CE device.

C. The Ethernet segment identifier must be an all zeros identifier.

D. A designated forwarder is elected for forwarding BUM traffic to the CE device.

Correct Answer: ADSection: Layer 2 VPNsExplanation

Page 381: JNCIP-SP JN0-661 · PDF file · 2017-07-29You must ensure that r1's IPv4 loopback address exists in r3 ... redistribute the VPN routes into OSPF. Correct Answer: D ... this route

http://www.gratisexam.com/

Explanation/Reference:1. BUM traffic—This type of traffic is sent to multiple destinations, including broadcast traffic, unknown unicast traffic that is broadcast in the Ethernet segment, and

multicast traffic.2. DF—When a CE device is multihomed to two or more PE routers, either one or all of the multihomed PE routers are used to reach the customer site depending

on the multihoming mode of operation. The PE router that assumes the primary role for forwarding BUM traffic to the CE device is called the designatedforwarder (DF).

A: When a CE device is multihomed to two or more PE routers, the set of Ethernet links constitutes an Ethernet segment. An Ethernet segment appears as a linkaggregation group (LAG) to the CE device .

D: When a CE device is multihomed to two or more PE routers, either one or all of the multihomed PE routers are used to reach the customer site depending on themultihoming mode of operation. The PE router that assumes the primary role for forwarding BUM traffic to the CE device is called the designated forwarder (DF).

Incorrect Answers:C: An Ethernet segment must have a unique nonzero identifier, called the Ethernet segment identifier (ESI). The ESI is encoded as a 10 octet integer.

References:

http://www.juniper.net/documentation/en_US/junos15.1/topics/concept/evpn-bgp-multihoming-overview.html

https://www.juniper.net/documentation/en_US/junos/topics/concept/evpn-bgp-multihoming-overview.html

QUESTION 12A PE provides VLAN VPLS service to a CE attached with two links. You want to prevent Layer 2 loops and provide link redundancy. Which two actions willaccomplish this task? (Choose two.)

A. Place both interfaces in a link aggregation group.

B. Configure different VLANs on each interface.

C. Configure all VLANs on both interfaces, on the PE, and on the CE.

D. Configure Spanning Tree Protocol between the PE and the CE.

Correct Answer: ADSection: Layer 2 VPNsExplanation

Explanation/Reference:D: To prevent the formation of Layer 2 loops between the CE devices and the multihomed PE routers, Juniper recommends that you employ the Spanning TreeProtocol (STP) on your CE devices. Layer 2 loops can form due to incorrect configuration. Temporary Layer 2 loops can also form during convergence after achange in the network topology.

Page 382: JNCIP-SP JN0-661 · PDF file · 2017-07-29You must ensure that r1's IPv4 loopback address exists in r3 ... redistribute the VPN routes into OSPF. Correct Answer: D ... this route

http://www.gratisexam.com/

Reference: http://www.juniper.net/documentation/en_US/junos16.1/topics/topic-map/vpls-bgp-multihoming.html

QUESTION 13Your customer requires a Layer 2 VPN service (draft-kompella-mpls-l2vpn). You are asked to describe the operational requirements on the PE router supportingthis service.

Which two statements are true in this scenario? (Choose two.)

A. The ingress PE router associates multiple MPLS labels with the corresponding traffic flows.

B. The ingress PE router for a traffic flow maintains the data-link connection identifier.

C. The ingress PE router for a traffic flow removes the data-link connection identifier.

D. The ingress PE router associates a single MPLS label with the corresponding traffic flows.

Correct Answer: ACSection: Layer 2 VPNsExplanation

Explanation/Reference:A: When a packet arrives at a PE from a CE in a Layer 2 VPN, the Layer 2 address of the packet identifies to which remote attachment circuit (and thus remote CE) the packet is destined.

The procedure installs a route that maps the Layer 2 address to a tunnel (which identifies the PE to which the destination CE is attached) and a VPN label (which identifies the destination AC).

If the egress PE is the same as the ingress PE, no tunnel or VPN label is needed.

C: In case of IP-only Layer 2 interworking, the Layer 2 header is completely stripped off till the IP header.

Reference: https://tools.ietf.org/html/draft-kompella-l2vpn-l2vpn-10

QUESTION 14Click the Exhibit button.

Page 383: JNCIP-SP JN0-661 · PDF file · 2017-07-29You must ensure that r1's IPv4 loopback address exists in r3 ... redistribute the VPN routes into OSPF. Correct Answer: D ... this route

http://www.gratisexam.com/

Referring to the exhibit, you see the proper BGP, MPLS, and routing instance configuration for PE1 and PE2.

Which configuration on PE1 will allow CE1 to communicate with CE2 over a Layer 2 VPN, assuming PE2 has PPP TCC encapsulation on so-0/0/0.0?

A. [edit interfaces fe-0/2/2 unit 42]family tcc { proxy { inet-address 192.168.1.2; } remote { inet-address 192.168.1.1; }}

B. [edit interfaces fe-0/2/2 unit 42]family tcc { remote { inet-address 192.168.1.2; }}

C. [edit interfaces fe-0/2/2 unit 42]family tcc { proxy { inet-address 192.168.1.1; }}

D. [edit interfaces fe-0/2/2 unit 42]family tcc { proxy { inet-address 192.168.1.1; } remote {

Page 384: JNCIP-SP JN0-661 · PDF file · 2017-07-29You must ensure that r1's IPv4 loopback address exists in r3 ... redistribute the VPN routes into OSPF. Correct Answer: D ... this route

http://www.gratisexam.com/

inet-address 192.168.1.2; }}

Correct Answer: ASection: Layer 2 VPNsExplanation

Explanation/Reference:

QUESTION 15Click the Exhibit button.

Referring to the VPLS network shown in the exhibit, you notice that only one of the two CE sites configured under the VPLS instance forms a connection to theremote site. The other site remains in a forwarding and learning mode.

How does PE1 determine which CE within the VPLS instance forms the connection to the remote site?

A. The site that first distributes the outgoing label to the remote site will form the connection.

Page 385: JNCIP-SP JN0-661 · PDF file · 2017-07-29You must ensure that r1's IPv4 loopback address exists in r3 ... redistribute the VPN routes into OSPF. Correct Answer: D ... this route

http://www.gratisexam.com/

B. The site with a lower interface index value will form the connection.

C. The site with a higher interface index value will form the connection.

D. The site with the lowest site ID will form the connection.

Correct Answer: DSection: Layer 2 VPNsExplanation

Explanation/Reference:Explanation:

QUESTION 16What must you do to use the Layer 2 interworking interface to connect a BGP Layer 2 VPN with an LDP Layer 2 circuit? (Choose two.)

A. You must configure a policy importing the bgp.l2vpn.O routing table into the inet.0 routing table.

B. You must enable the I2iw protocol.

C. You must have a Tunnel Services PIC installed to used the L2 interworking interface.

D. You must include the iw0 statement under the [edit interfaces] hierarchy.

Correct Answer: BDSection: Layer 2 VPNsExplanation

Explanation/Reference:

QUESTION 17What are two requirements of Layer 2 VPN BGP route reflectors? (Choose two.)

A. Routes are kept in the bgp.l2vpn.0 table.

B. Route reflectors must support the l2vpn family.

C. Route reflectors must support the inet-vpn family.

D. Routes are kept in the inet.2 table.

Correct Answer: ABSection: Layer 2 VPNsExplanation

Explanation/Reference:

Page 386: JNCIP-SP JN0-661 · PDF file · 2017-07-29You must ensure that r1's IPv4 loopback address exists in r3 ... redistribute the VPN routes into OSPF. Correct Answer: D ... this route

http://www.gratisexam.com/

QUESTION 18You are asked to implement a BGP-signaled VPLS network for a new customer. Which two statements are correct regarding this implementation? (Choose two.)

A. A full mesh of LDP sessions between PEs must be configured.

B. The PE routers distribute VPLS-to-label mapping using MP-IBGP.

C. These MP-BGP sessions must be configured to support the I2vpn signaling address family.

D. These MP-BGP sessions must be configured to support the inet-vpn signaling address family.

Correct Answer: BCSection: Layer 2 VPNsExplanation

Explanation/Reference:

QUESTION 19Refer to the exhibit.

Page 387: JNCIP-SP JN0-661 · PDF file · 2017-07-29You must ensure that r1's IPv4 loopback address exists in r3 ... redistribute the VPN routes into OSPF. Correct Answer: D ... this route

http://www.gratisexam.com/

Page 388: JNCIP-SP JN0-661 · PDF file · 2017-07-29You must ensure that r1's IPv4 loopback address exists in r3 ... redistribute the VPN routes into OSPF. Correct Answer: D ... this route

http://www.gratisexam.com/

In a newly configured VPLS network, you see the output shown in the exhibit. The remote PE is 10.1.1.2. What is the cause for the OL status?

A. There is not a proper label-switched path to the remote PE, so there is no MPLS path to the remote PE.

B. The VPLS site identifiers are not contiguous, causing label block allocation to run out of labels.

C. The MPLS protocol family is not configured for interface fe-0/1/2.2, so the LDP adjacency is in an error state.

D. The remote PE is using the wrong route distinguisher, so the outgoing labels are incorrect.

Correct Answer: BSection: Layer 2 VPNsExplanation

Page 389: JNCIP-SP JN0-661 · PDF file · 2017-07-29You must ensure that r1's IPv4 loopback address exists in r3 ... redistribute the VPN routes into OSPF. Correct Answer: D ... this route

http://www.gratisexam.com/

Explanation/Reference:

QUESTION 20You are asked to deploy VPLS in your network as a new service for several customers and must identify the configuration and provisioning requirements. Which twostatements are correct? (Choose two.)

A. PE routers must include a VRF routing instance.

B. PE interfaces facing customers must have family VPLS configured.

C. PE routers must create a unique site ID for each CE device.

D. CE routers must be configured with their assigned route target.

Correct Answer: BCSection: Layer 2 VPNsExplanation

Explanation/Reference:

QUESTION 21You are asked to implement an LDP-signaled VPLS network for a new customer. Which two statements are correct regarding this implementation? (Choose two.)

A. A full mesh of LDP sessions between PEs must be configured.

B. The PE routers distribute VPLS to label mapping using MP-IBGP.

C. The same NLRI as Layer 2 VPNs is used.

D. The PE router advertises a label for each remote PE configured.

Correct Answer: ADSection: Layer 2 VPNsExplanation

Explanation/Reference:

QUESTION 22You are configuring a Layer 2 circuit. Which two configuration steps are required? (Choose two.)

Page 390: JNCIP-SP JN0-661 · PDF file · 2017-07-29You must ensure that r1's IPv4 loopback address exists in r3 ... redistribute the VPN routes into OSPF. Correct Answer: D ... this route

http://www.gratisexam.com/

http://www.gratisexam.com

A. Configure LDP on the interfaces between PE and CE routers.

B. Configure circuit or translational cross-connects between PE routers and between PE and P routers.

C. Configure circuit or translational cross-connects between PE and CE routers.

D. Configure LDP on the interfaces between PE routers and between PE and P routers.

Correct Answer: CDSection: Layer 2 VPNsExplanation

Explanation/Reference:

QUESTION 23You are asked to provision a BGP-signaled Layer 2 VPN for a new customer.

What information is required for the VPN routing instance that is connected to the CE device? (Choose three.)

A. the logical interfaces provisioned to the local CE device

B. the logical interfaces provisioned to the remote PE device

C. the Layer 2 encapsulation type

D. the local site ID

E. the circuit identifier

Correct Answer: ACDSection: Layer 2 VPNsExplanation

Explanation/Reference:

QUESTION 24Refer to the exhibit.

Page 391: JNCIP-SP JN0-661 · PDF file · 2017-07-29You must ensure that r1's IPv4 loopback address exists in r3 ... redistribute the VPN routes into OSPF. Correct Answer: D ... this route

http://www.gratisexam.com/

[edit routing-instances vpn-a]user@PE2# showinstance-type l2vpn;interface ge-1/0/4.513;interface ge-1/0/4.512;route-distinguisher 192.168.1.2:1;vrf-import import-vpn-a;vrf-export export-vpn-a;protocols { l2vpn { encapsulation-type ethernet-vlan; site ce-A { interface ge-1/0/4.512; interface ge-1/0/4.513; }}

You have the Layer 2 VPN configuration shown in the exhibit. You have been asked to determine the remote site ID for ge-1/0/4.512. What is the remote site ID?

A. 1

B. 3

C. 4

D. unspecified

Correct Answer: ASection: Layer 2 VPNsExplanation

Explanation/Reference:

QUESTION 25Two of your customers have just merged into a single company. Because of time constraints, you have been asked to connect Customer A's BGP-signaled Layer 2VPN with Customer B's LDP- signaled Layer 2 circuit using the interworking interface.

Which two statements are true? (Choose two).

A. You must have a tunnel PIC to create the interworking interface.

B. You must configure the Layer 2 interworking protocol.

C. The logical interworking interfaces must specify their logical peer units.

Page 392: JNCIP-SP JN0-661 · PDF file · 2017-07-29You must ensure that r1's IPv4 loopback address exists in r3 ... redistribute the VPN routes into OSPF. Correct Answer: D ... this route

http://www.gratisexam.com/

D. The Junos OS automatically links the interworking interface units.

Correct Answer: BCSection: Layer 2 VPNsExplanation

Explanation/Reference:

QUESTION 26Which two configuration parameters are required to configure an LDP-signaled VPLS service? (Choose two.)

A. vpls-id

B. site-identifier

C. route-distinguisher

D. instance-type vpls

Correct Answer: ADSection: Layer 2 VPNsExplanation

Explanation/Reference:

QUESTION 27You are provisioning a new customer for an LDP Layer 2 circuit. You have assigned them VLAN 600 on interface ge-1/0/0.Which configuration correctly provisionsthe interface?

A. interface { ge-1/0/0 { vlan-tagging; unit 600 { encapsulation vlan-ccc; vlan-id 600; } }}

B. interface { ge-1/0/0 { vlan-tagging;

Page 393: JNCIP-SP JN0-661 · PDF file · 2017-07-29You must ensure that r1's IPv4 loopback address exists in r3 ... redistribute the VPN routes into OSPF. Correct Answer: D ... this route

http://www.gratisexam.com/

encapsulation vlan-ccc; unit 600 { vlan-id 600; } }}

C. interface { ge-1/0/0 { encapsulation vlan-ccc; unit 600 { encapsulation vlan-ccc; vlan-id 600; } }}

D. interface { ge-1/0/0 { vlan-tagging; encapsulation vlan-ccc; unit 600 { encapsulation vlan-ccc; vlan-id 600; } }}

Correct Answer: DSection: Layer 2 VPNsExplanation

Explanation/Reference:

QUESTION 28An LDP Layer 2 circuit is configured for VPN A and VPN B. Which three statements are true regarding LDP Layer 2 circuit signaling? (Choose three.)

A. PE-P LDP sessions use Martini encapsulation.

B. PE-PE LDP sessions can be extended or adjacent.

C. VRF tables are needed on the PEs.

D. TCC encapsulation is needed to interconnect different interface types.

E. The VC type field in the LDP header specifies the encapsulation type.

Page 394: JNCIP-SP JN0-661 · PDF file · 2017-07-29You must ensure that r1's IPv4 loopback address exists in r3 ... redistribute the VPN routes into OSPF. Correct Answer: D ... this route

http://www.gratisexam.com/

Correct Answer: BDESection: Layer 2 VPNsExplanation

Explanation/Reference:

QUESTION 29You are asked to design a Layer 2 VPN service for a service provider network that supports Ethernet and ATM transport. Which two Layer 2 VPN technologies willmeet this requirement? (Choose two.)

A. LDP-signaled VPLS, using draft martini encapsulation

B. BGP-signaled VPLS, using the RFC 4448 Layer 2 frame format

C. LDP Layer 2 circuit, using the RFC 4448 Layer 2 frame format

D. BGP Layer 2 VPN, using draft-Martini encapsulation

Correct Answer: CDSection: Layer 2 VPNsExplanation

Explanation/Reference:

QUESTION 30Click the Exhibit button.

Page 395: JNCIP-SP JN0-661 · PDF file · 2017-07-29You must ensure that r1's IPv4 loopback address exists in r3 ... redistribute the VPN routes into OSPF. Correct Answer: D ... this route

http://www.gratisexam.com/

Referring to the exhibit, which statement is true assuming BGP Layer 2 VPN signaling?

A. PE1 receives two BGP NLRI updates, each containing a remote site ID, a label base, and Layer 2 encapsulation.

B. PE2 receives one BGP NLRI update containing a remote site ID, a label base, and Layer 2 encapsulation.

C. PE2 receives two BGP NLRI updates, each containing a remote site ID, label vc, and Layer 2 encapsulation.

D. PE1 receives one BGP NLRI for VPN A containing only a remote site ID and a label offset value.

Correct Answer: ASection: Layer 2 VPNsExplanation

Explanation/Reference:

QUESTION 31Click the Exhibit button.

My_VPLS2 { instance-type vpls; interface ge-1/0/1.0; protocols { vpls { no-tunnel-services; vpls-id 100; neighbor 192.168.1.1; } }}

Referring to the exhibit, which two statements are true? (Choose two.)

A. The VPN uses LDP signaling for VPLS services.

B. The VPN uses BGP signaling for VPLS services.

C. The PE and directly attached CE are multihomed.

D. There are only 2 PEs with VPN membership in the network.

Correct Answer: ADSection: Layer 2 VPNsExplanation

Page 396: JNCIP-SP JN0-661 · PDF file · 2017-07-29You must ensure that r1's IPv4 loopback address exists in r3 ... redistribute the VPN routes into OSPF. Correct Answer: D ... this route

http://www.gratisexam.com/

Explanation/Reference:

QUESTION 32You are asked to design a Layer 2 VPN service between service provider networks that needs Ethernet transport capabilities. The VPN should support two or threeendpoints. Which Layer 2 VPN technology should you propose?

A. LDP-signaled VPLS

B. BGP-signaled VPLS, using the RFC 4448 Layer 2 frame format

C. LDP Layer 2 circuit, using the RFC 4448 Layer 2 frame format

D. BGP Layer 2 VPN

Correct Answer: BSection: Layer 2 VPNsExplanation

Explanation/Reference:

QUESTION 33Click the Exhibit button.

Customer A is complaining that CE1 and CE2 cannot form an OSPF adjacency across your LDP Layer 2 circuit. The physical topology of the network is CE1-PE1-P-PE2-CE2. PE1's loopback is 192.168.5.1, P's loopback is 192.168.6.1, and PE2's loopback is 192.168.7.1.

Referring to the output in the exhibit, what is the problem?

A. mismatched virtual circuit ID values

B. mismatched interface encapsulations

C. incorrect PE-CE interface configuration

D. extended LDP neighbor not established

Correct Answer: ASection: Layer 2 VPNsExplanation

Explanation/Reference:

Page 397: JNCIP-SP JN0-661 · PDF file · 2017-07-29You must ensure that r1's IPv4 loopback address exists in r3 ... redistribute the VPN routes into OSPF. Correct Answer: D ... this route

http://www.gratisexam.com/

QUESTION 34Click the Exhibit button.

You are provisioning a full-mesh BGP Layer 2 VPN for Customer A. The customer has four remote sites in their network. Using best practices, you assignedinterface unit numbers matching the assigned VLAN numbers. Which Layer 2 VPN configuration is correct for PE2?

A. l2vpn { encapsulation-type ethernet-vlan; site CE2 { site-identifier 2; interface ge-0/0/0.523; interface ge-0/0/0.512; interface ge-0/0/0.524; }}

B. l2vpn { encapsulation-type ethernet-vlan; site CE2 {

Page 398: JNCIP-SP JN0-661 · PDF file · 2017-07-29You must ensure that r1's IPv4 loopback address exists in r3 ... redistribute the VPN routes into OSPF. Correct Answer: D ... this route

http://www.gratisexam.com/

site-identifier 2; interface ge-0/0/0.523; interface ge-0/0/0.524; interface ge-0/0/0.512; }}

C. l2vpn { encapsulation-type ethernet-vlan; site CE2 { site-identifier 2; interface ge-0/0/0.512; interface ge-0/0/0.523; interface ge-0/0/0.524; }}

D. l2vpn { encapsulation-type ethernet-vlan; site CE2 { site-identifier 2; interface ge-0/0/0.512; interface ge-0/0/0.524; interface ge-0/0/0.523; }}

Correct Answer: CSection: Layer 2 VPNsExplanation

Explanation/Reference:

QUESTION 35Click the Exhibit button.

Page 399: JNCIP-SP JN0-661 · PDF file · 2017-07-29You must ensure that r1's IPv4 loopback address exists in r3 ... redistribute the VPN routes into OSPF. Correct Answer: D ... this route

http://www.gratisexam.com/

Your IT manager asks you to describe a benefit of migrating from LDP VPLS towards BGP VPLS considering the operational network shown in the exhibit. Whatcan you tell your manager?

A. Using BGP signaling improves scaling, because a full mesh of transport LSPs is not needed.

B. MAC addresses are learned through BGP instead of LDP, which improves scaling.

C. Ingress PE replication can be reduced, because BGP VPLS supports P2MP LSPs.

D. Configuration overhead is reduced when adding new sites or new VPNs.

Correct Answer: DSection: Layer 2 VPNsExplanation

Explanation/Reference:

QUESTION 36Which two configuration parameters are required to configure a BGP-signaled VPLS service? (Choose two.)

A. vpls-id

B. site-identifier

C. route-distinguisher

D. site-address

Correct Answer: BCSection: Layer 2 VPNsExplanation

Page 400: JNCIP-SP JN0-661 · PDF file · 2017-07-29You must ensure that r1's IPv4 loopback address exists in r3 ... redistribute the VPN routes into OSPF. Correct Answer: D ... this route

http://www.gratisexam.com/

Explanation/Reference:

QUESTION 37Click the Exhibit button.

Customer A is complaining that CE1 and CE2 cannot form an OSPF adjacency across your LDP Layer 2 circuit. The physical topology of the network is CE1-PE1-

Page 401: JNCIP-SP JN0-661 · PDF file · 2017-07-29You must ensure that r1's IPv4 loopback address exists in r3 ... redistribute the VPN routes into OSPF. Correct Answer: D ... this route

http://www.gratisexam.com/

P-PE2-CE2. PE1's loopback is 192.168.5.1, P's loopback is 192.168.6.1, and PE2's loopback is 192.168.7.1.

Referring to the output in the exhibit, what is the problem?

http://www.gratisexam.com

A. mismatched virtual circuit ID values

B. mismatched interface encapsulations

C. incorrect PE-CE interface configuration

D. extended LDP neighbor not established

Correct Answer: BSection: Layer 2 VPNsExplanation

Explanation/Reference:

QUESTION 38Click the Exhibit button.

Page 402: JNCIP-SP JN0-661 · PDF file · 2017-07-29You must ensure that r1's IPv4 loopback address exists in r3 ... redistribute the VPN routes into OSPF. Correct Answer: D ... this route

http://www.gratisexam.com/

A LDP Layer 2 circuit is shown for VPN A and VPN B. LDP tunneling over RSVP is activated on P1 and P2. Referring to the exhibit, which statement is true aboutthe LDP Layer 2 circuit?

A. MAC learning is needed and using the inner VPN label between PE1 and PE2 for VPN A or VPN B.

B. Targeted LDP sessions are established between PE1, P1 and P2, PE2.

C. Label stitching must be configured on P1 and P2 for end to end transport LSPs.

D. LDP must be enabled on the loopback interfaces of PE1 and PE2.

Correct Answer: DSection: Layer 2 VPNsExplanation

Explanation/Reference:

QUESTION 39Click the Exhibit button.

CE1, CE2, and CE3 are part of a single VPLS VPN. R1, R2, and R3 are PEs in the provider network, and have just been powered on. The VPLS domain hasconverged, and frames have passed between all CEs in the last minute. An Ethernet frame has just arrived at R3 from CE3. It has a source MAC address of CE3and a destination MAC address of CE1.What does R3 do with the Ethernet frame?

A. Drops the packet as the destination MAC address is not for R3.

B. Drops the packet as the destination MAC address is not in R3's MAC table.

C. Forwards the packet to R1 only.

Page 403: JNCIP-SP JN0-661 · PDF file · 2017-07-29You must ensure that r1's IPv4 loopback address exists in r3 ... redistribute the VPN routes into OSPF. Correct Answer: D ... this route

http://www.gratisexam.com/

D. Forwards the packet to R1 and R2.

Correct Answer: CSection: Layer 2 VPNsExplanation

Explanation/Reference:

QUESTION 40Click the Exhibit button.

In the exhibit, on which label value does PE1 expect to receive traffic from CE3 for VPN A?

A. 2002

B. 3001

C. 3002

D. 2001

Correct Answer: ASection: Layer 2 VPNsExplanation

Page 404: JNCIP-SP JN0-661 · PDF file · 2017-07-29You must ensure that r1's IPv4 loopback address exists in r3 ... redistribute the VPN routes into OSPF. Correct Answer: D ... this route

http://www.gratisexam.com/

Explanation/Reference:

QUESTION 41You have assigned target:65432:100 as the route target for Customer A's BGP Layer 2 VPN. The PE1 router VRF is configured with vrf-target exporttarget:65432:100.Which configuration on PE2 correctly assigned Customer A's routes to their VRF?

A. vrf-target target:65432:100

B. route-target target:65432:100

C. vrf-target export target:65432:100

D. route-target export target:65432:100

Correct Answer: ASection: Layer 2 VPNsExplanation

Explanation/Reference:

QUESTION 42In which two ways does VPLS populate the MAC table? (Choose two.)

A. dynamically using BGP

B. dynamically using the source MAC address on received frames

C. dynamically using LDP

D. statically using CLI

Correct Answer: BDSection: Layer 2 VPNsExplanation

Explanation/Reference:

QUESTION 43Which routing instance type is used with a Layer 2 VPN?

A. 12vpn

B. vrf

Page 405: JNCIP-SP JN0-661 · PDF file · 2017-07-29You must ensure that r1's IPv4 loopback address exists in r3 ... redistribute the VPN routes into OSPF. Correct Answer: D ... this route

http://www.gratisexam.com/

C. no-forwarding

D. virtual-switch

Correct Answer: DSection: Layer 2 VPNsExplanation

Explanation/Reference:You can configure three types of routing instances (instance-types) in Layer 2 networks on MX Series routers: layer2-control, virtual-switch, and vpls.

Incorrect:The other five types of routing instances are configured only for Layer 3 networks: forwarding, no-forwarding, vrf, l2vpn, and virtual-router.

References: https://www.juniper.net/documentation/en_US/junos15.1/topics/concept/layer-2-services-routing-instance-types.html

QUESTION 44What are two characteristics of L2 circuits? (Choose two.)

A. Routing instance configuration is required for L2 circuits to function correctly.

B. Routing instance configuration is not required for L2 circuits to function correctly.

C. BGP is required for L2 circuits to function correctly.

D. BGP is not required for L2 circuits to function correctly.

Correct Answer: BDSection: Layer 2 VPNsExplanation

Explanation/Reference:B: You configure Layer 2 VPNs in a routing instance. As a result, Layer 2 VPNs have unique site and VPN identifiers. However, Layer 2 circuits do not require arouting instance configuration and instead use an alternate method of identifying circuits.D: Layer 2 VPNs, like Layer 3 VPNs, require Border Gateway Protocol (BGP) for transport of traffic between PE routers. In contrast, Layer 2 circuits do not requireBGP. Instead, Layer 2 circuits rely on LDP and MPLS for their operation.

References: http://www.juniper.net/techpubs/en_US/junos12.3/topics/concept/layer-two-circuits-overview-solutions.html

QUESTION 45An L2VPN (draft-kompella-mpls-l2vpn) is established between two PE routers to provide connectivity between two customer sites.

Which two statements related to this deployment are true? (Choose two.)

Page 406: JNCIP-SP JN0-661 · PDF file · 2017-07-29You must ensure that r1's IPv4 loopback address exists in r3 ... redistribute the VPN routes into OSPF. Correct Answer: D ... this route

http://www.gratisexam.com/

A. BGP must be used for the control plane communications.

B. Kompella encapsulation is used in the data plane communications.

C. LDP must be used for the control plane communications.

D. Martini encapsulation is used in the data plane communications.

Correct Answer: ABSection: Layer 2 VPNsExplanation

Explanation/Reference:Junos OS substantially supports t RFC 4447, Pseudowire Setup and Maintenance Using the Label Distribution Protocol (LDP).

Martini uses directed LDP to signal the VPN label between the PE devices, Kompella uses BGP to signal the VPN label between the PE devices.

References: https://www.juniper.net/documentation/en_US/junos15.1/topics/reference/standards/layer-2-circuit.html

QUESTION 46You work for a service provider and need to build EVPN service which provides an active/active multihoming topology using a single CE at each site.

In this scenario, which two statements are true? (Choose two.)

A. An Ethernet segment appears as a LAG to the CE device.

B. A backup designated forwarder is elected for forwarding BUM traffic to the CE device.

C. The Ethernet segment identifier must be an all zeros identifier.

D. A designated forwarder is elected for forwarding BUM traffic to the CE device.

Correct Answer: ABSection: Layer 2 VPNsExplanation

Explanation/Reference:A: When a CE device is multihomed to two or more PE routers, the set of Ethernet links constitutes an Ethernet segment. An Ethernet segment appears as a linkaggregation group (LAG) to the CE device .

B: When a CE device is multihomed to two or more PE routers, either one or all of the multihomed PE routers are used to reach the customer site depending on themultihoming mode of operation. The PE router that assumes the primary role for forwarding BUM traffic to the CE device is called the designated forwarder (DF).

Incorrect Answers:C: An Ethernet segment must have a unique nonzero identifier, called the Ethernet segment identifier (ESI). The ESI is encoded as a 10 octet integer.

Page 407: JNCIP-SP JN0-661 · PDF file · 2017-07-29You must ensure that r1's IPv4 loopback address exists in r3 ... redistribute the VPN routes into OSPF. Correct Answer: D ... this route

http://www.gratisexam.com/

References: http://www.juniper.net/documentation/en_US/junos15.1/topics/concept/evpn-bgp-multihoming-overview.html

QUESTION 47A PE provides VLAN VPLS service to a CE attached with two links. You want to prevent Layer 2 loops and provide link redundancy.

Which two actions will accomplish this task? (Choose two.)

A. Place both interfaces in a link aggregation group.

B. Configure different VLANs on each interface.

C. Configure all VLANs on both interfaces, on the PE, and on the CE.

D. Configure Spanning Tree Protocol between the PE and the CE.

Correct Answer: BDSection: Layer 2 VPNsExplanation

Explanation/Reference:D: To prevent the formation of Layer 2 loops between the CE devices and the multihomed PE routers, Juniper recommends that you employ the Spanning TreeProtocol (STP) on your CE devices. Layer 2 loops can form due to incorrect configuration. Temporary Layer 2 loops can also form during convergence after achange in the network topology.

References: http://www.juniper.net/documentation/en_US/junos16.1/topics/topic-map/vpls-bgp-multihoming.html

QUESTION 48Click on the exhibit

Page 408: JNCIP-SP JN0-661 · PDF file · 2017-07-29You must ensure that r1's IPv4 loopback address exists in r3 ... redistribute the VPN routes into OSPF. Correct Answer: D ... this route

http://www.gratisexam.com/

In the exhibit, a BGP-signaled VPLS is shown. Which inner label does PE2 calculate for traffic destinated for site 30?

A. 3030

B. 3031

C. 2029

D. 2030

Correct Answer: ASection: Layer 2 VPNsExplanation

Explanation/Reference:

QUESTION 49Click on the exhibit

Page 409: JNCIP-SP JN0-661 · PDF file · 2017-07-29You must ensure that r1's IPv4 loopback address exists in r3 ... redistribute the VPN routes into OSPF. Correct Answer: D ... this route

http://www.gratisexam.com/

CE1, CE2, and CE3 are part of a single VPLS VPN. R1, R2, and R3 are PEs in the provider network, and have just been powered on. The VPLS domain hasconvereged, but no frames have passed between any CE or PE router. An Ethernet frame has just arrived at R3 from CE3. It has a source MAC address of CE3and a destination MAC address of CE1. What does R3 do with the Ethernet frame?

A. Forwards the packet to R1 and R2.

B. Drops the packet because the destination MAC address is not in R3's MAC table.

C. Drops the packet because the destination MAC address is not for R3.

D. Forward the packet to router R1 only.

Correct Answer: ASection: Layer 2 VPNsExplanation

Explanation/Reference:

QUESTION 50You build a four site full-mesh BGP Layer 2 VPN for a customer and determine that routes exist in the bgp.l2vpn.0 table on the PE2 router. The routes areadvertised from the PE1 router. Why is this occurring?

A. There is a route target mismatch.

B. "family l2vpn signaling" is missing on PE1.

C. The LSP from PE2 to PE1 is not operational.

D. There is an encapsulation mismatch

Correct Answer: C

Page 410: JNCIP-SP JN0-661 · PDF file · 2017-07-29You must ensure that r1's IPv4 loopback address exists in r3 ... redistribute the VPN routes into OSPF. Correct Answer: D ... this route

http://www.gratisexam.com/

Section: Layer 2 VPNsExplanation

Explanation/Reference:

QUESTION 51Your VPLS instance currently uses a VT interface for processing incoming traffic from the backbone. For performance reasons you want to use an LSI interface.Which change to the configuration will make the VPLS instance use an LSI interface?

A. Configure "no-tunnel-services" under the routing-instance.

B. Configure "interface lsi.0" under the routing.instance.

C. Configure "instance-type vpls" under the routing-instance.

D. Configure "vrf-table-label" under the routing-instance

Correct Answer: ASection: Layer 2 VPNsExplanation

Explanation/Reference:

QUESTION 52What are two characteristics of L2 circuits? (Choose two.)

http://www.gratisexam.com

A. Routing instance configuration is required for L2 circuits to function correctly

B. Routing instance configuration is not required for L2 circuits to function correctly

C. BGP is required for L2 circuits to function correctly

D. BGP is not required for L2 circuits to function correctly

Correct Answer: BDSection: (none)Explanation

Page 411: JNCIP-SP JN0-661 · PDF file · 2017-07-29You must ensure that r1's IPv4 loopback address exists in r3 ... redistribute the VPN routes into OSPF. Correct Answer: D ... this route

http://www.gratisexam.com/

Explanation/Reference:

QUESTION 53Which routing instance type is used with a Layer 2 VPN?

A. l2vpn

B. vrf

C. no-forwarding

D. virtual-switch

Correct Answer: ASection: (none)Explanation

Explanation/Reference:

QUESTION 54Referring to the exhibit, you have configured an L2 circuit that connects Site-1 and Site-2, but circuit is not functioning. The topology in this scenario is shown below.

Site-1 > PE-1 > P-1 > P-2 > PE-2 > Site-2

Which action will allow communication between Site-1 and Site-2?

Exhibit:

Page 412: JNCIP-SP JN0-661 · PDF file · 2017-07-29You must ensure that r1's IPv4 loopback address exists in r3 ... redistribute the VPN routes into OSPF. Correct Answer: D ... this route

http://www.gratisexam.com/

Page 413: JNCIP-SP JN0-661 · PDF file · 2017-07-29You must ensure that r1's IPv4 loopback address exists in r3 ... redistribute the VPN routes into OSPF. Correct Answer: D ... this route

http://www.gratisexam.com/

A. Change the virtual circuit to 2 for PE-2

B. Add the family inet statement under the ge-0/0/1 512 interface for PE-1 and PE-2

C. Add the lo0 interface under the {edit protocols ldp} hierarchy for all routers

D. Add the lo0 interface under the {edit protocol l2circuit} hierarchy for PE-1 and PE-2

Correct Answer: CSection: (none)Explanation

Explanation/Reference:

QUESTION 55An L2VPN (draft-kompella-mpls-l2vpn) is established between two PE routers to provide connectivity between two customer sites.

Which two statements related to this deployment are true? (Choose two.)

A. BGP must be used for the control plane communications.

B. Kompella encapsulation is used in the data plane communications.

C. LDP must be used for the control plane communications.

D. Martini encapsulation is used in the data plane communications.

Correct Answer: ABSection: (none)Explanation

Explanation/Reference:

QUESTION 56

Page 414: JNCIP-SP JN0-661 · PDF file · 2017-07-29You must ensure that r1's IPv4 loopback address exists in r3 ... redistribute the VPN routes into OSPF. Correct Answer: D ... this route

http://www.gratisexam.com/

Referring to the exhibit, which LDP Layer 2 circuit configuration on PE1 maps traffic to an LSP destined to the secondary loopback address of PE2?

A. [edit protocols l2circuit] user@PE1# show neighbor 10.10.10.2 { interface ge-1/1/1.1 { psn-tunnel-endpoint 10.10.10.1; virtual-circuit-id 1; encapsulation-type ethernet-vlan; } }

B. [edit protocols l2circuit] user@PE1# show neighbor 10.10.10.2 { interface ge-1/1/1.1 { virtual-circuit-id 1; encapsulation-type ethernet-vlan; } }

C. [edit protocols l2circuit]user@PE1# show neighbor 10.10.10.2 { interface ge-1/1/1.1 { psn-tunnel-endpoint 10.10.10.2; virtual-circuit-id 1; encapsulation-type ethernet-vlan; } }

D. [edit protocols l2circuit] user@PE1# show neighbor 10.10.10.1 { interface ge-1/1/1.1 { psn-tunnel-endpoint 10.10.10.2; virtual-circuit-id 1; encapsulation-type ethernet-vlan; } }

Correct Answer: CSection: (none)Explanation

Page 415: JNCIP-SP JN0-661 · PDF file · 2017-07-29You must ensure that r1's IPv4 loopback address exists in r3 ... redistribute the VPN routes into OSPF. Correct Answer: D ... this route

http://www.gratisexam.com/

Explanation/Reference:

QUESTION 57A PE provides VLAN VPLS service to a CE attached with two links. You want to prevent Layer 2 loops and provide link redundancy.

Which two actions will accomplish this task? (Choose two.)

A. Place both interfaces in a link aggregation group

B. Configure different VLANs on each interface.

C. Configure all VLANs on both interfaces, on the PE, and on the CE.

D. Configure Spanning Tree Protocol between the PE and the CE.

Correct Answer: ADSection: (none)Explanation

Explanation/Reference:

QUESTION 58PE1 and PE2 provide a BGP-signaled VPLS service name VPN Blue. PE1 has site ID 2, label based 2500, and label offset 1. PE2 has site ID 4, label base 3000,and label offset 1.

Which label does PE2 expect to receive on VPLS VPN Blue traffic from PE1 site ID 2?

A. 2505

B. 5499

C. 2503

D. 3001

Correct Answer: CSection: Layer 2 VPNsExplanation

Explanation/Reference:The formula used is VPN label = label-base-remote + local-site-id - label-offset-remote, which 2500+4-1=2503

Reference: https://inetzero.com/verifying-a-bgp-signaled-vpls/

Page 416: JNCIP-SP JN0-661 · PDF file · 2017-07-29You must ensure that r1's IPv4 loopback address exists in r3 ... redistribute the VPN routes into OSPF. Correct Answer: D ... this route

http://www.gratisexam.com/

http://www.gratisexam.com

Page 417: JNCIP-SP JN0-661 · PDF file · 2017-07-29You must ensure that r1's IPv4 loopback address exists in r3 ... redistribute the VPN routes into OSPF. Correct Answer: D ... this route

http://www.gratisexam.com/

Misc

QUESTION 1Refer to the exhibit.

[edit system scripts commit]user@R1# showfile script.slax { source scp://2.2.2.2/etc/script.slax;}

The configuration shown in the exhibit displays a configuration for a commit script. However, you are unable to automatically retrieve the script from the remoteserver.

How do you retrieve the commit script from a different remote server without adding to the configuration?

http://www.gratisexam.com

A. Use the refresh-from feature.

B. Use the refresh feature.

C. Issue the direct-access feature.

D. Use the allow-transients feature.

Correct Answer: ASection: MiscExplanation

Explanation/Reference:

QUESTION 2Refer to the exhibit.

Page 418: JNCIP-SP JN0-661 · PDF file · 2017-07-29You must ensure that r1's IPv4 loopback address exists in r3 ... redistribute the VPN routes into OSPF. Correct Answer: D ... this route

http://www.gratisexam.com/

A. [edit policy-options policy-statement RIP-redist]user@router# showterm 1 { from { protocol rip; route-filter 50.50.1.0/24 exact; } then accept;

Page 419: JNCIP-SP JN0-661 · PDF file · 2017-07-29You must ensure that r1's IPv4 loopback address exists in r3 ... redistribute the VPN routes into OSPF. Correct Answer: D ... this route

http://www.gratisexam.com/

}term 2 { from { protocol rip; route-filter 50.50.0.0/24 upto 27; } then reject;}term 3 { from protocol rip; then accept;}

B. [edit policy-options policy-statement RIP-redist]user@router# showterm 1 { from { protocol rip; route-filter 50.50.1.0/24 upto /27; } then reject;}term 2 { from { protocol rip; route-filter 50.50.1.0/24 exact; } then accept;}term 3 { from protocol rip; then accept;}

C. [edit policy-options policy-statement RIP-redist]user@router# showterm 1 { from { protocol rip; route-filter 50.50.0.0/16 prefix-length-range /24-/26; } then reject;}term 2 {

Page 420: JNCIP-SP JN0-661 · PDF file · 2017-07-29You must ensure that r1's IPv4 loopback address exists in r3 ... redistribute the VPN routes into OSPF. Correct Answer: D ... this route

http://www.gratisexam.com/

from { protocol rip; route-filter 50.50.1.0/24 exact; } then accept;}

D. [edit policy-options policy-statement RIP-redist]user@router# showterm 1 { from { protocol rip; route-filter 50.50.0.0/24 exact; } then accept;}term 2 { from { protocol rip; route-filter 50.50.0.0/16 prefix-length-range /24-/26; } then reject;}

Correct Answer: DSection: MiscExplanation

Explanation/Reference:

QUESTION 3Refer to exhibit.

user@router# show interfaces ge-1/0/0unit 0 { family inet { address 10.42.0.1/30; } family iso;}

user@router# show system scripts

Page 421: JNCIP-SP JN0-661 · PDF file · 2017-07-29You must ensure that r1's IPv4 loopback address exists in r3 ... redistribute the VPN routes into OSPF. Correct Answer: D ... this route

http://www.gratisexam.com/

commit { file forget-me-not.slax;}

Referring to the script and configuration shown in the exhibit, what would be the output after committing the configuration?

A. [edit interfaces interface ge-1/0/0 unit 0] warning: ge-1/0/0 does not have MPLS.commit complete

B. [edit interfaces interface ge-1/0/0 unit 0] warning: You forgot something.commit complete

C. [edit interfaces interface ge-1/0/0 unit 0] warning: ge-1/0/0 does not have MPLS.

D. [edit interfaces interface ge-1/0/0 unit 0] warning: You forgot something.commit completecommit complete

Correct Answer: CSection: MiscExplanation

Explanation/Reference:

QUESTION 4Which configuration parameter would be used by a commit script to use custom syntax and simplify the configuration?

A. Apply-groups

B. Allow-transients

C. Direct-access

D. Apply-macro

Correct Answer: DSection: MiscExplanation

Explanation/Reference:

Page 422: JNCIP-SP JN0-661 · PDF file · 2017-07-29You must ensure that r1's IPv4 loopback address exists in r3 ... redistribute the VPN routes into OSPF. Correct Answer: D ... this route

http://www.gratisexam.com/

QUESTION 5What does an operation (op) script do?

A. Instructs the Junos OS to perform a set of actions whenever the script is run manually or called by another script

B. Instructs the Junos OS to perform a set of actions based on its location in the configuration.

C. Instructs the Junos OS to perform a set of actions during the process of activating configuration changes.

D. Instructs the Junos OS to perform a set of actions automatically based on operational status of the device.

Correct Answer: ASection: MiscExplanation

Explanation/Reference:

QUESTION 6Click the Exhibit button.

interfaces { ge-0/0/0 { disable; }}

Which choice shows the configuration in the exhibit in SLAX format?

A. <interfaces> { <interface> { <name="ge-0/0/0">; <disable>; }}

B. <interfaces> { <interface> { <name>ge-0/0/0</name> <disable/> </interface></interfaces>

C. interfaces { interface {

Page 423: JNCIP-SP JN0-661 · PDF file · 2017-07-29You must ensure that r1's IPv4 loopback address exists in r3 ... redistribute the VPN routes into OSPF. Correct Answer: D ... this route

http://www.gratisexam.com/

name "ge-0/0/0"; disable; }}

D. <interfaces> { <interface> { <name> "ge-0/0/0"; <disable>; }}

Correct Answer: DSection: MiscExplanation

Explanation/Reference:

QUESTION 7Click the Exhibit button.

Page 424: JNCIP-SP JN0-661 · PDF file · 2017-07-29You must ensure that r1's IPv4 loopback address exists in r3 ... redistribute the VPN routes into OSPF. Correct Answer: D ... this route

http://www.gratisexam.com/

In the exhibit, Customer A uses private RFC1918 addresses within its network. The customer wants to have all Internet access for its organization transit throughthe main office for security and NAT purposes. Each of the PE routers in your network contains Internet routes in the main instance routing table and is capable ofprovisioning both a VRF and a non-VRF interface to its attached CE router. Which router should be configured to accomplish the administrative goal of thecustomer?

A. P

B. PE1

C. PE2

D. PE3

Correct Answer: BSection: MiscExplanation

Explanation/Reference:

QUESTION 8Junos scripts can be written in which two languages? (Choose two.)

A. XLS

B. XML

C. XSLT

D. SLAX

Correct Answer: CDSection: MiscExplanation

Explanation/Reference:

QUESTION 9What are three Junos automation scripts? (Choose three.)

A. op scripts

B. pulse scripts

C. commit scripts

Page 425: JNCIP-SP JN0-661 · PDF file · 2017-07-29You must ensure that r1's IPv4 loopback address exists in r3 ... redistribute the VPN routes into OSPF. Correct Answer: D ... this route

http://www.gratisexam.com/

D. event scripts

E. action scripts

Correct Answer: ACDSection: MiscExplanation

Explanation/Reference:

QUESTION 10You have been asked to make a configuration which inherits the statements in a predefined configuration group. What will accomplish this?

A. groups { group-name { configuration-data; }}

B. apply-groups <apply-group-name>;

C. apply-macro <apply-macro-name>;

D. event-options { event-script { file file-name; }}

Correct Answer: BSection: MiscExplanation

Explanation/Reference:

http://www.gratisexam.com

QUESTION 11Click on the Exhibit button.

Page 426: JNCIP-SP JN0-661 · PDF file · 2017-07-29You must ensure that r1's IPv4 loopback address exists in r3 ... redistribute the VPN routes into OSPF. Correct Answer: D ... this route

http://www.gratisexam.com/

user@router> show route receive-protocol rip 2.2.2.2inet.0: 15 destinations, 15 routes (15 active, 0 holddown, 0 hidden)+ = Active Route, - = Last Active, * = Both50.50.0.0/26 *[RIP/100] 00:09:12, metric 2, tag 0> to 2.2.2.2 via fe-3/0/0.250.50.1.0/24 *[RIP/100] 00:32:24, metric 2, tag 0> to 2.2.2.2 via fe-3/0/0.250.50.2.0/24 *[RIP/100] 00:32:24, metric 2, tag 0> to 2.2.2.2 via fe-3/0/0.250.50.3.0/25 *[RIP/100] 00:32:24, metric 2, tag 0> to 2.2.2.2 via fe-3/0/0.250.50.4.0/25 *[RIP/100] 00:32:24, metric 2, tag 0> to 2.2.2.2 via fe-3/0/0.250.50.4.128/25 *[RIP/100] 00:32:24, metric 2, tag 0> to 2.2.2.2 via fe-3/0/0.250.50.5.0/26 *[RIP/100] 00:32:24, metric 2, tag 0> to 2.2.2.2 via fe-3/0/0.250.50.5.64/26 *[RIP/100] 00:32:24, metric 2, tag 0> to 2.2.2.2 via fe-3/0/0.250.50.5.128/26 *[RIP/100] 00:32:24, metric 2, tag 0> to 2.2.2.2 via fe-3/0/0.2

Referring to the exhibit, how should an export policy be configured to export only the 50.50.1.0/24 RIP summary route into OSPF?

A. [edit policy-options policy-statement RIP-redist]user@router# showterm 1 { from { protocol rip; route-filter 50.50.1.0/24 exact; } then accept;}term 2 { from { protocol rip; route-filter 50.50.0.0/24 upto /27; } then reject;}term 3 {

Page 427: JNCIP-SP JN0-661 · PDF file · 2017-07-29You must ensure that r1's IPv4 loopback address exists in r3 ... redistribute the VPN routes into OSPF. Correct Answer: D ... this route

http://www.gratisexam.com/

from protocol rip; then accept;}

B. [edit policy-options policy-statement RIP-redist]user@router# showterm 1 { from { protocol rip; route-filter 50.50.0.0/24 upto /27; } then reject;}term 2 { from { protocol rip; route-filter 50.50.1.0/24 exact; } then accept;}term 3 { from protocol rip; then accept;}

C. [edit policy-options policy-statement RIP-redist]user@router# showterm 1 { from { protocol rip; route-filter 50.50.0.0/16 prefix-length-range /24-/26; } then reject;}term 2 { from { protocol rip; route-filter 50.50.1.0/24 exact; } then accept;}

D. [edit policy-options policy-statement RIP-redist]user@router# showterm 1 {

Page 428: JNCIP-SP JN0-661 · PDF file · 2017-07-29You must ensure that r1's IPv4 loopback address exists in r3 ... redistribute the VPN routes into OSPF. Correct Answer: D ... this route

http://www.gratisexam.com/

from { protocol rip; route-filter 50.50.1.0/24 exact; } then accept;}term 2 { from { protocol rip; route-filter 50.50.0.0/16 prefix-length-range /24-/26; } then reject;}

Correct Answer: DSection: MiscExplanation

Explanation/Reference:

http://www.gratisexam.com