A network automation engineer needs to retrieve the BGP neighbor operational state from a Cisco router running IOS-XR using NETCONF. The engineer wants to filter the request to only get information for the neighbor with the IP address '192.0.2.2'. Which XML snippet represents the correct NETCONF filter to use with a operation to achieve this specific request, based on the Cisco-IOS-XR-ipv4-bgp-oper YANG model?
Answer and explanation
Correct answer: B
This XML snippet correctly represents a subtree filter for a NETCONF operation. It navigates the YANG model hierarchy for BGP operational data on IOS-XR. The structure bgp/instances/instance/instance-active/default-vrf/neighbors/neighbor is the correct path. The is a key in the neighbor list, and by specifying its value as '192.0.2.2', the filter precisely targets the operational data for that single BGP neighbor, making the query efficient and specific.
Question 2
Multiple answers
A service provider offers Carrier Supporting Carrier (CSC) services. A customer carrier (Carrier B) is peering with the backbone carrier (Carrier A). Carrier B wants to run MPLS within its own network and transport its labeled VPN traffic across Carrier A's backbone. Which two protocols or features are essential on the PE routers of the backbone carrier (Carrier A) to support this CSC model? (Select TWO)
Answer and explanation
Correct answers: B, C
In a CSC model, the backbone carrier (Carrier A) needs to exchange MPLS labels with the customer carrier (Carrier B) for the customer's IGP routes. This is typically achieved by running LDP between Carrier A's PE router and Carrier B's CE router.
The backbone carrier needs to advertise the customer carrier's IGP routes across its core to the egress PE. To carry the label information for these routes, the MP-BGP ipv4 label unicast address family (SAFI 4) is used. This allows BGP to distribute an MPLS label along with the IPv4 prefix.
Question 3
True or False: In a standard MPLS L3VPN deployment, the BGP Extended Community 'SoO' (Site of Origin) is primarily used to prevent routing loops when a customer site is dual-homed to two different PE routers.
Answer and explanation
Correct answer: A
True. The Site of Origin (SoO) extended community is a BGP attribute used to identify the site from which a route originated. When a customer site is connected to two PEs for redundancy, SoO is applied to the routes learned from the CE at each PE. This SoO value is carried with the VPNv4 route across the MPLS core. A PE router will not advertise a VPNv4 route back to a CE if the route's SoO value matches the SoO configured on the PE-CE link. This effectively prevents routes learned from one link to a site from being advertised back to the same site via the other link, thus preventing routing loops.
Question 4
A service provider is deploying a multicast VPN (mVPN) solution using NG-mVPN with mLDP as the transport protocol. An engineer is troubleshooting an issue where a customer receiver in VRF 'CUST_A' is not receiving a multicast stream from a source in the same VRF. The P-tunnel status is up. Which command on a PE router is most effective for verifying that the customer's PIM join message is being correctly mapped to an upstream mLDP label for transport across the provider core?
Answer and explanation
Correct answer: D
The show mpls mldp database vrf command is the most direct way to verify the mapping between a customer multicast (C-multicast) flow and the provider's mLDP label switched path (LSP). This command displays the mLDP Forwarding Equivalence Class (FEC) information, including the multicast source/group, the upstream PE router, the opaque value identifying the C-flow, and the assigned upstream label. If the customer's PIM join has been successfully processed by the PE, an entry for that (S,G) or (*,G) should appear in this database, confirming the C-flow to P-tunnel mapping.
Question 5
A financial services company, 'FinSecure', is migrating its legacy VPLS services to a more scalable EVPN-MPLS solution. A key requirement is to prevent Layer 2 loops and control broadcast, unknown unicast, and multicast (BUM) traffic flooding between different segments of the same EVI. The network topology consists of a central hub site and multiple spoke sites. Spoke sites should be able to communicate with the hub but not directly with each other at Layer 2. Which EVPN feature must be implemented to meet this specific requirement?
Answer and explanation
Correct answer: B
EVPN E-Tree is a service specifically designed for hub-and-spoke Layer 2 topologies. It categorizes attachment circuits as either 'root' (hub) or 'leaf' (spoke). The forwarding logic of E-Tree allows root-to-leaf, leaf-to-root, and root-to-root communication, but explicitly blocks leaf-to-leaf communication at Layer 2. This perfectly matches the requirement to allow spokes to talk to the hub but not to each other, effectively preventing loops and controlling BUM traffic between spoke sites.
Question 6
A consultant is designing a QoS policy for a service provider network that uses MPLS. The provider wants to ensure that customer IP Precedence markings are preserved and used for queuing decisions within the MPLS core, but they do not want to trust the full DSCP value. The provider has standardized on mapping IP Precedence values directly to MPLS EXP bits. Which QoS configuration model should be implemented on the ingress PE routers?
Answer and explanation
Correct answer: B
The Pipe Model (also known as the Uniform Model) in MPLS DiffServ provides a single, consistent QoS treatment from end-to-end. In this model, the IP Precedence or DSCP value is mapped to the MPLS EXP bits at the ingress PE. This EXP value is then used for queuing and scheduling decisions across the MPLS core. Crucially, at the egress PE, the EXP value is mapped back to the IP header's ToS byte. This ensures that any QoS remarking done in the core (if any) is reflected in the IP packet, maintaining a uniform QoS policy. The requirement to map IP Precedence to EXP and use it throughout the core is the definition of the Pipe/Uniform model.
Question 7
During the implementation of BGP FlowSpec on an IOS-XR router to mitigate a DDoS attack, a network operator defines a FlowSpec rule to drop traffic destined for a specific victim IP. The operator applies the service policy to the BGP process. However, the malicious traffic is still reaching the destination. What is a critical missing configuration step required to activate BGP FlowSpec traffic filtering on the router's data plane?
Answer and explanation
Correct answer: B
In IOS-XR, BGP FlowSpec has a separate control plane and data plane component. While the rules are received and programmed into BGP via the address-family configuration, they are not enforced in the data plane until a specific flowspec service policy is attached to the physical or logical ingress interfaces. This action instructs the forwarding plane (FIB) to program the dynamic ACLs generated by the FlowSpec rules onto the interface hardware. Without this step, the router knows about the rule but does not actively filter traffic based on it.
Question 8
A service provider is configuring IS-IS in a large, multi-level network. To improve scalability and reduce the size of the Link-State Database (LSDB) on Level 1 routers, the network architect decides to use route summarization at the L1/L2 border. The following command is configured on the L1/L2 router:
summary-address 10.10.0.0 255.255.0.0 level-1
What is the effect of this command on the IS-IS operation?
Answer and explanation
Correct answer: D
In IS-IS, summarization is performed as routes are advertised into an area or level. The command summary-address 10.10.0.0 255.255.0.0 level-1 on an L1/L2 router instructs it to advertise a single summary route (10.10.0.0/16) down into the Level 1 area. This summary represents routes that the L1/L2 router has learned from other sources, such as the Level 2 backbone or redistributed routes. This prevents the more specific prefixes from being flooded into the Level 1 area, thus reducing the LSDB size on L1-only routers.
Question 9
Case Study: GlobalTrans Logistics MPLS Network Upgrade
Company Background: GlobalTrans Logistics is a worldwide shipping and logistics company that operates a large private MPLS network connecting its regional headquarters, distribution centers, and major port facilities. The network is built on Cisco hardware and currently uses LDP for label distribution and OSPF as the IGP. The network is divided into three major geographical regions: North America (NA), Europe (EU), and Asia-Pacific (APAC), each running as a separate OSPF Area 0, interconnected via an Inter-AS MPLS backbone.
Current Situation: The company is experiencing significant growth, leading to increased traffic and more complex application requirements. The current network design is facing challenges with traffic engineering and meeting strict SLAs for latency-sensitive applications like real-time cargo tracking and automated port machinery control. The network operations team finds it difficult to steer specific traffic types over non-default paths to avoid congestion. They are also preparing to deploy 5G services at their smart port facilities, which will require network slicing capabilities.
Requirements:
Traffic Engineering: Implement a solution that allows for granular, policy-based traffic steering for critical applications without the complexity of a full-mesh of RSVP-TE tunnels.
Scalability: The new solution must be highly scalable and simplify the control plane, reducing the protocol state that needs to be maintained on core routers.
Future-Proofing: The architecture must provide a clear path towards network slicing and service function chaining for future 5G and IoT deployments.
Simplified Operations: Reduce the operational overhead associated with path management and provisioning.
Problem: As the lead network architect, you are tasked with recommending a core technology upgrade to meet these requirements. The solution must integrate with the existing MPLS data plane and OSPF IGP with minimal disruption. Which solution best addresses all of GlobalTrans's requirements?
Answer and explanation
Correct answer: B
Segment Routing (SR-MPLS) is the ideal solution. 1) It provides powerful source-based traffic engineering by allowing the headend router to specify an explicit path as a stack of labels (SIDs), meeting the granular steering requirement without the state and complexity of RSVP-TE. 2) It simplifies the control plane by removing LDP and RSVP, relying only on IGP extensions (in this case, for OSPF), which significantly improves scalability. 3) SR is the foundational technology for network slicing and service function chaining, directly addressing the future-proofing requirement for 5G. 4) By centralizing path control at the source or a controller, it simplifies operations compared to hop-by-hop provisioning.