A field engineer is troubleshooting a newly configured Inter-AS L3VPN Option B link between two service providers. The MP-eBGP session between the ASBRs is up, but customer VPN routes are not being exchanged. The engineer confirms that the neighbor send-community both command is configured. Which of the following is the most probable cause for the failure?
Answer and explanation
Correct answer: B
In an Inter-AS L3VPN Option B scenario, the ASBRs exchange VPNv4 routes via MP-eBGP. The next-hop for these routes is typically the PE router in the originating AS. Without the next-hop-self command, the receiving ASBR will not change the next-hop attribute, making the route unreachable for PEs in its own AS. While send-community is required for route-targets, the lack of next-hop-self is a common and critical error that directly prevents route propagation. An IGP does not run between ASBRs of different providers, and LDP is not required directly between ASBRs in Option B.
Question 2
A junior engineer has applied a complex BGP policy change on a production IOS-XR router. To mitigate risk, the senior engineer wants to ensure the configuration automatically reverts if connectivity is lost. Which command sequence correctly applies the new configuration with a 5-minute automatic rollback timer?
Answer and explanation
Correct answer: D
The commit confirmed command in IOS-XR is a safety mechanism that applies a configuration change but requires a second, confirming commit command within the specified time. If the confirmation is not received (e.g., because the change caused a loss of management access), the router automatically rolls back to the previous configuration. The value is specified in minutes, so commit confirmed 5 sets a 5-minute timer.
Question 3
Multiple answers
Following a recent link flap in an MPLS core, an engineer notices that LDP convergence is taking longer than expected, causing a brief service outage. The engineer needs to investigate why LDP is slow to re-establish its session and re-learn labels from its neighbor. Which TWO commands are most effective for diagnosing LDP session establishment issues and label exchange timing on an IOS-XR router? (Select TWO)
Answer and explanation
Correct answers: A, C
This command is crucial for viewing the LDP discovery process, including hello intervals and the state of adjacency with neighbors. It helps determine if the routers can even see each other at the LDP level, which is the first step in session establishment.
This debug command provides real-time information about the LDP TCP transport session events. It allows the engineer to see the session setup, keepalives, and any errors that might be occurring during the TCP handshake, which is a common point of failure or delay.
Question 4
Within the Cisco IOS-XR architecture, which core process is responsible for managing the lifecycle (starting, stopping, and monitoring) of all other processes running on a Route Processor?
Answer and explanation
Correct answer: D
The System Manager (sysmgr) is a critical mandatory process in the IOS-XR operating system. Its primary function is to manage the lifecycle of all other processes. It reads the system configuration to determine which processes should be running, starts them, monitors their health, and restarts them if they fail.
Question 5
A service provider, 'GlobalNet', is designing an MPLS L3VPN service for two enterprise clients, 'AlphaCorp' and 'BetaLogistics'. AlphaCorp requires access to a shared logging server hosted within a separate VRF called 'SHARED_SERVICES'. BetaLogistics needs standard internet access and must be completely isolated from AlphaCorp and the shared services. Both clients have multiple sites that need full mesh connectivity amongst themselves.
The lead architect has proposed the following high-level design:
AlphaCorp sites will be in the 'ALPHA_VRF'.
BetaLogistics sites will be in the 'BETA_VRF'.
The logging server is in the 'SHARED_SERVICES_VRF'.
To meet these specific requirements, what is the optimal route-target (RT) import/export strategy that should be configured on the PE routers?
This configuration correctly implements the requirements. 1) ALPHA_VRF imports its own RT (RT_ALPHA) for full mesh connectivity and imports RT_SHARED to learn the route to the logging server. 2) BETA_VRF only imports its own RT (RT_BETA), ensuring complete isolation. 3) SHARED_SERVICES_VRF exports its routes with RT_SHARED and critically, only needs to import RT_ALPHA to learn the return path to AlphaCorp clients. It does not need to import its own routes or Beta's routes, ensuring one-way access initiation from AlphaCorp.
Question 6
True or False: In a redundant Cisco IOS-XR system, when an administrator makes configuration changes on the active Route Processor (RP), these changes are immediately synchronized and applied to the running configuration of the standby RP even before the commit command is issued.
Answer and explanation
Correct answer: B
This statement is false. In IOS-XR's two-stage configuration model, changes made in configuration mode are held in a target or 'scratchpad' configuration. They are not applied to the active running configuration, nor are they synchronized to the standby RP, until the commit command is executed. The commit operation is what validates the changes, applies them to the active RP, and then synchronizes the new running configuration to the standby RP.
Question 7
When designing an Inter-AS L3VPN solution using Option C, what is the fundamental requirement to allow the PE routers in different Autonomous Systems to resolve the BGP next-hop of the remote PE?
Answer and explanation
Correct answer: C
Inter-AS Option C's main characteristic is that it extends the MPLS LSP from the ingress PE in one AS to the egress PE in another AS. To achieve this, the PE loopback addresses must be reachable across AS boundaries. This is accomplished by exchanging these loopbacks as labeled-unicast routes between the ASBRs (e.g., using address-family ipv4 labeled-unicast). This allows the PEs to build a recursive LSP to the remote PE's next-hop. Redistributing into the IGP would be a massive scalability and security issue.
Question 8
A field engineer must apply a critical security patch via a Software Maintenance Upgrade (SMU) to a live Cisco ASR 9000 router running IOS-XR. Before proceeding with the installation, the engineer needs to verify the SMU's integrity and ensure that all prerequisite packages are present on the system. Which command should be used to perform these checks without initiating the actual installation?
Answer and explanation
Correct answer: D
In IOS-XR, the install add source test command is specifically designed for pre-installation checks. It performs a dry run of the installation process, which includes verifying the package's integrity, checking for dependencies and prerequisites, and ensuring there are no conflicts, all without making any changes to the system. This is a critical best practice before applying any software update to a production device.
Question 9
A network operations center has detected a CPU hog condition on an IOS-XR router, where the bgp process is consistently consuming over 90% of the CPU. An engineer must troubleshoot the issue without causing a service-impacting router reload. What is the most appropriate first step to gather detailed information about the BGP process's activity?
Answer and explanation
Correct answer: D
When a process like BGP shows high CPU usage, it's often a single thread within that process causing the issue. The show processes detail command is the best first step as it breaks down the process into its individual threads and shows the CPU time consumed by each. This allows the engineer to pinpoint the specific function (e.g., scanner, router, I/O) that is misbehaving, which is essential for targeted debugging. Restarting the process is a last resort, and simply confirming the high usage doesn't provide new diagnostic data.
flowchart TD
A[Observe High CPU for 'bgp' process] --> B{What is the first diagnostic step?};
B --> C[show processes bgp detail];
C --> D{Identify high-CPU thread};
D --> E[Analyze thread function, e.g., 'BGP Scanner'];
E --> F[Apply specific debugs for that function];
F --> G[Resolve underlying issue, e.g., route-policy loop];
Question 10
In Cisco IOS-XR, multiple administrators can be in configuration mode simultaneously. What is the key difference between an administrator using the lock command versus another administrator starting a session with the configure exclusive command?
Answer and explanation
Correct answer: C
The configure exclusive command provides a system-wide lock, preventing any other user from entering configuration mode until the current user exits. The lock command is less restrictive; it is issued from within an existing configuration session and allows other users to enter configuration mode and make changes in their own sessions, but it prevents anyone from committing their changes until the lock is released.