1+X雲計算平台運維與開發(中級)eNSP A~E卷 試題+答案


1+X雲計算平台運維與開發(中級)eNSP A~E卷 試題+答案
A卷
路由器管理(40分)
41
配置R1和R2路由器(路由器使用R2220),R1路由器配置端口g0/0/1地址為192.168.1.1/30,端口g0/0/1連接R2路由器。配置端口g0/0/2地址為192.168.2.1/24,作為內部PC1機網關地址。R2路由器配置端口g0/0/1地址為192.168.1.2/30,端口g0/0/1連接R1路由器,配置端口g0/0/2地址為192.168.3.1/24,作為內部PC2機網關地址。R1和R2路由器啟用OSPF動態路由協議自動學習路由。使PC1和PC2可以相互訪問。(所有配置命令使用完整命令)將上述所有操作命令及返回結果以文本形式提交到答題框。
參考答案:
[Huawei]interface GigabitEthernet 0/0/1
[Huawei-GigabitEthernet0/0/1]ip address 192.168.1.1 30
[Huawei-GigabitEthernet0/0/1]quit
[Huawei]interface GigabitEthernet 0/0/2
[Huawei-GigabitEthernet0/0/2]ip address 192.168.2.1 24
[Huawei-GigabitEthernet0/0/2]quit
[Huawei]ospf 1
[Huawei-ospf-1]area 0
[Huawei-ospf-1-area-0.0.0.0]network 192.168.1.0 0.0.0.3
[Huawei-ospf-1-area-0.0.0.0]network 192.168.2.0 0.0.0.255
[Huawei]interface GigabitEthernet 0/0/1
[Huawei-GigabitEthernet0/0/1]ip address 192.168.1.2 30
[Huawei-GigabitEthernet0/0/1]quit
[Huawei]interface GigabitEthernet 0/0/2
[Huawei-GigabitEthernet0/0/2]ip address 192.168.3.1 24
[Huawei-GigabitEthernet0/0/2]quit
[Huawei]ospf 1
[Huawei-ospf-1]area 0
[Huawei-ospf-1-area-0.0.0.0]network 192.168.1.0 0.0.0.3
[Huawei-ospf-1-area-0.0.0.0]network 192.168.3.0 0.0.0.255

無線AC管理(40分)
42
配置無線AC控制器(型號使用AC6005),開啟dhcp功能,設置vlan20網關地址為172.16.20.1/24,並配置vlan20接口服務器池,設置dhcp分發dns為114.114.114.114、223.5.5.5。將上述所有操作命令及返回結果以文本形式提交到答題框。
參考答案:
[SW1]vlan batch 20
[SW1]dhcp enable
[SW1]interface vlanif 20
[SW1-Vlanif20]ip address 172.16.20.1 24
[SW1-Vlanif20]dhcp select interface #給接口配置
[SW1-Vlanif20]dhcp server dns-list 114.114.114.114 223.5.5.5

B卷
交換機管理(40分)
41
在eNSP中使用S5700交換機進行配置,通過一條命令划分vlan 2、vlan 3、vlan 1004,通過端口組的方式配置端口1-5為access模式,並添加至vlan2中。配置端口10為trunk模式,並放行vlan3。創建三層vlan 2,配置IP地址為:172.16.2.1/24,創建三層vlan1004,配置IP地址為:192.168.4.2/30。通過命令添加默認路由,下一跳為192.168.4.1。(使用完整命令)將上述操作命令及返回結果以文本形式提交到答題框。
參考答案:
[Huawei]vlan batch 2 3 1004
[Huawei]port-group 1
[Huawei-port-group-1]group-member GigabitEthernet 0/0/1 to GigabitEthernet 0/0/5
[Huawei-port-group-1]port link-type access
[Huawei-port-group-1]port default vlan 2
[Huawei]interface GigabitEthernet 0/0/10
[Huawei-GigabitEthernet0/0/10]port link-type trunk
[Huawei-GigabitEthernet0/0/10]port trunk allow-pass vlan 3
[Huawei]interface Vlanif 2
[Huawei-Vlanif2]ip address 172.16.2.1 24
[Huawei]interface Vlanif 1004
[Huawei-Vlanif1004]ip address 192.168.4.2 30
[Huawei]ip route-static 0.0.0.0 0 192.168.4.1

交換機管理(40分)
42
交換機配置:交換機g0/0/1端口連接R1路由器,所屬vlan1001,配置地址192.168.1.2/30,與路由器通信。配置g0/0/2連接PC1機,所屬vlan101,配置PC1機網關地址為172.16.101.254/24。配置默認路由下一跳為路由器地址。路由器配置:R1路由器g0/0/1端口配置地址12.12.12.1/30,配置端口多路復用PAT配置。R1路由器g0/0/2端口配置地址192.168.1.1/30,連接交換機。路由器配置默認路由訪問外部網絡,配置靜態路由訪問PC機網絡。(所有配置命令使用完整命令)將上述操作命令及返回結果以文本形式提交到答題框。
參考答案:
[Huawei]vlan batch 101 1001
[Huawei]interface GigabitEthernet 0/0/1
[Huawei-GigabitEthernet0/0/1]port link-type access
[Huawei-GigabitEthernet0/0/1]port default vlan 1001
[Huawei-GigabitEthernet0/0/1]quit
[Huawei]interface vlan 1001
[Huawei-Vlanif1001]ip address 192.168.1.2 30
[Huawei]interface GigabitEthernet 0/0/2
[Huawei-GigabitEthernet0/0/2]port link-type access
[Huawei-GigabitEthernet0/0/2]port default vlan 101
[Huawei-GigabitEthernet0/0/2]quit
[Huawei]interface vlan 101
[Huawei-Vlanif101]ip address 172.16.101.254 24
[Huawei-Vlanif101]quit
[Huawei]ip route-static 0.0.0.0 0 192.168.1.1
[Huawei]acl number 2000
[Huawei-acl-basic-2000]rule 1 permit
[Huawei-acl-basic-2000]quit
[Huawei]interface GigabitEthernet 0/0/1
[Huawei-GigabitEthernet0/0/1]ip add
[Huawei-GigabitEthernet0/0/1]ip address 12.12.12.1 30
[Huawei-GigabitEthernet0/0/1]nat outbound 2000
[Huawei-GigabitEthernet0/0/1]quit
[Huawei]interface GigabitEthernet 0/0/2
[Huawei-GigabitEthernet0/0/2]ip address 192.168.1.1 30
[Huawei-GigabitEthernet0/0/2]quit
[Huawei]ip route-static 0.0.0.0 0 GigabitEthernet 0/0/1
[Huawei]ip route-static 172.16.101.0 255.255.255.0 192.168.1.2

C卷
防火牆牆管理(40分)
41
配置防火牆g0/0/2端口添加至trust域,g0/0/1端口添加至untrust域。配置trust域到untrust域規則,放行內部地址172.16.105.0/24網段。配置NAT規則,匹配內部地址172.16.105.0/24網段,使用g0/0/1端口的地址進行轉換。(所有配置命令使用完整命令)將上述所有操作命令及返回結果以文本形式提交到答題框。
參考答案:
[SRG]firewall zone trust
[SRG-zone-trust]add interface GigabitEthernet 0/0/2
[SRG-zone-trust]quit
[SRG]firewall zone untrust
[SRG-zone-untrust]add interface GigabitEthernet 0/0/1
[SRG-zone-untrust]quit
[SRG]policy interzone trust untrust outbound
[SRG-policy-interzone-trust-untrust-outbound]policy 0
[SRG-policy-interzone-trust-untrust-outbound-0]action permit
[SRG-policy-interzone-trust-untrust-outbound-0]policy source 172.16.105.0 0.255.255.255
[SRG-policy-interzone-trust-untrust-outbound-0]quit
[SRG-policy-interzone-trust-untrust-outbound]quit
[SRG]nat-policy interzone trust untrust outbound
[SRG-nat-policy-interzone-trust-untrust-outbound]policy 1
[SRG-nat-policy-interzone-trust-untrust-outbound-1]action source-nat
[SRG-nat-policy-interzone-trust-untrust-outbound-1]policy source 172.16.105.0 0.255.255.255
[SRG-nat-policy-interzone-trust-untrust-outbound-1]easy-ip GigabitEthernet 0/0/1

無線AC網絡管理(40分)
42
配置無線AC控制器,設置安全策略Internet,配置安全認證方式為wpa-wpa2,密碼為a1234567,設置無線ssid為Internet,創建VAP模板名稱為Internet,綁定業務vlan為101,綁定安全策略,綁定SSID模板,創建AP組,名稱為ap-group1,綁定vap模板到射頻卡0、1上。將上述所有操作命令及返回結果以文本形式提交到答題框。
參考答案:
[AC1-wlan-view]security-profile name Internet
[AC1-wlan-sec-prof-Internet]security wpa-wpa2 psk pass-phrase a1234567 aes
[AC1-wlan-sec-prof-Internet]quit
[AC1-wlan-view]ssid-profile name Internet
[AC1-wlan-ssid-prof-Internet]ssid Internet
[AC1-wlan-ssid-prof-Internet]quit
[AC1-wlan-view]vap-profile name Internet
[AC1-wlan-vap-prof-Internet]forward-mode direct-forward
[AC1-wlan-vap-prof-Internet]service-vlan vlan-id 101
[AC1-wlan-vap-prof-Internet]security-profile Internet
[AC1-wlan-vap-prof-Internet]ssid-profile Internet
[AC1-wlan-vap-prof-Internet]quit
[AC1-wlan-view]ap-group name ap-group1
[AC1-wlan-ap-group-ap-group1]vap-profile Internet wlan 1 radio 0
[AC1-wlan-ap-group-ap-group1]vap-profile Internet wlan 1 radio 1
[AC1-wlan-ap-group-ap-group1]quit

D卷
網絡管理(40分)
41
通過一條命令在S1交換機上創建vlan100、vlan101,配置vlan100網關為:172.16.100.254/24。配置vlan101網關為:172.16.101.254/24。配置g0/0/1端口為trunk模式,放行vlan100。配置g0/0/2端口為access模式,所屬vlan101。將上述操作命令及返回結果以文本形式提交到答題框。
參考答案:
[SW1]vlan batch 101 102
[SW1]interface Vlanif 100
[SW1-Vlanif100]ip address 172.16.100.254 24
[SW1]interface Vlanif 101
[SW1-Vlanif101]ip address 172.16.101.254 24
[SW1]interface GigabitEthernet 0/0/1
[SW1-GigabitEthernet0/0/1]port link-type trunk
[SW1-GigabitEthernet0/0/1]port trunk allow-pass vlan 100
[SW1-GigabitEthernet0/0/1]quit
[SW1]interface GigabitEthernet 0/0/2
[SW1-GigabitEthernet0/0/2]port link-type access
[SW1-GigabitEthernet0/0/2]port default vlan 101
[SW1-GigabitEthernet0/0/2]quit

防火牆管理(40分)
42
配置防火牆g0/0/2為trust域,配置g0/0/1為untrust域,配置g0/0/2地址為10.10.5.1/24,配置g0/0/1端口地址為192.168.10.254/24,配置默認路由下一跳為192.168.10.1,配置從trust域到untrust域策略,匹配放行內部地址為172.16.0.0/16網段,配置從trust域到untrust域nat策略,匹配內部地址為172.16.0.0/16網段,使用g0/0/1端口地址。將上述操作命令及返回結果以文本形式提交到答題框。
參考答案:
[SRG]firewall zone trust
[SRG-zone-trust]add interface GigabitEthernet 0/0/2
[SRG-zone-trust]quit
[SRG]firewall zone untrust
[SRG-zone-untrust]add interface GigabitEthernet 0/0/1
[SRG-zone-untrust]quit
[SRG]interface GigabitEthernet 0/0/2
[SRG-GigabitEthernet0/0/2]ip address 10.10.5.1 24
[SRG-GigabitEthernet0/0/2]quit
[SRG]interface GigabitEthernet 0/0/1
[SRG-GigabitEthernet0/0/1]ip address 192.168.10.254 24
[SRG-GigabitEthernet0/0/1]quit
[SRG]ip route-static 0.0.0.0 0 192.168.10.1
[SRG]policy interzone trust untrust outbound
[SRG-policy-interzone-trust-untrust-outbound]policy 0
[SRG-policy-interzone-trust-untrust-outbound-0]action permit
[SRG-policy-interzone-trust-untrust-outbound-0]policy source 172.16.0.0 0.0.255.255
[SRG-policy-interzone-trust-untrust-outbound-0]quit
[SRG-policy-interzone-trust-untrust-outbound]quit
[SRG]nat-policy interzone trust untrust outbound
[SRG-nat-policy-interzone-trust-untrust-outbound]policy 1
[SRG-nat-policy-interzone-trust-untrust-outbound-1]action source-nat
[SRG-nat-policy-interzone-trust-untrust-outbound-1]policy source 172.16.0.0 0.0.255.255
[SRG-nat-policy-interzone-trust-untrust-outbound-1]easy-ip GigabitEthernet 0/0/1
[SRG-nat-policy-interzone-trust-untrust-outbound-1]quit
[SRG-nat-policy-interzone-trust-untrust-outbound]quit

E卷
網絡管理(40分)
41
在eNSP中使用S5700交換機進行配置,通過一條命令划分vlan 2、vlan 3、vlan 1004,通過端口組的方式配置端口1-5為access模式,並添加至vlan2中。配置端口10為trunk模式,並放行vlan3。創建三層vlan 2,配置IP地址為:172.16.2.1/24,創建三層vlan1004,配置IP地址為:192.168.4.2/30。通過命令添加默認路由,下一跳為192.168.4.1。(使用完整命令)將上述操作命令以文本形式提交到答題框。
參考答案:
[Huawei]vlan batch 2 3 1004
[Huawei]port-group 1
[Huawei-port-group-1]group-member GigabitEthernet 0/0/1 to GigabitEthernet 0/0/5
[Huawei-port-group-1]port link-type access
[Huawei-port-group-1]port default vlan 2
[Huawei]interface GigabitEthernet 0/0/10
[Huawei-GigabitEthernet0/0/10]port link-type trunk
[Huawei-GigabitEthernet0/0/10]port trunk allow-pass vlan 3
[Huawei]interface Vlanif 2
[Huawei-Vlanif2]ip address 172.16.2.1 24
[Huawei]interface Vlanif 1004
[Huawei-Vlanif1004]ip address 192.168.4.2 30
[Huawei]ip route-static 0.0.0.0 0 192.168.4.1

網絡管理(40分)
42
配置SW1交換機vlan20地址為172.17.20.253/24,配置vrrp虛擬網關為172.17.20.254, vrid為1,配置優先級為120。配置vlan17地址為172.17.17.253/24,配置vrrp虛擬網關為172.17.17.254,vrid為2。配置mstp協議,vlan20為實例1,vlan17為實例2,vlan20在SW1上為主,vlan17在SW1上為備。將上述操作命令以文本形式提交到答題框。

參考答案:
[SW1]interface Vlanif 20
[SW1-Vlanif20]ip address 172.17.20.253 24
[SW1-Vlanif20]vrrp vrid 1 virtual-ip 172.17.20.254
[SW1-Vlanif20]vrrp vrid 1 priority 120
[SW1-Vlanif20]vrrp vrid 1 track interface GigabitEthernet 0/0/4 reduced 15
[SW1-Vlanif20]quit
[SW1]interface Vlanif 17
[SW1-Vlanif17]ip address 172.17.17.253 24
[SW1-Vlanif17]vrrp vrid 2 virtual-ip 172.17.17.254
[SW1-Vlanif17]quit
[SW1]stp region-configuration
[SW1-mst-region]region-name RG1
[SW1-mst-region]instance 1 vlan 20
[SW1-mst-region]instance 2 vlan 17
[SW1-mst-region]active region-configuration
[SW1-mst-region]quit
[SW1]stp instance 1 root primary
[SW1]stp instance 2 root secondary
[SW1]stp pathcost-standard legacy
[SW1]stp enable


免責聲明!

本站轉載的文章為個人學習借鑒使用,本站對版權不負任何法律責任。如果侵犯了您的隱私權益,請聯系本站郵箱yoyou2525@163.com刪除。



 
粵ICP備18138465號   © 2018-2025 CODEPRJ.COM