🎤 CCIE Enterprise Infrastructure — Interview Q&A

❓ Type-7 LSA Type-5 کیسے بنتا ہے، اور کیا reachable ہونا چاہیے؟Type-7 LSA Type-5 kaise banta hai, aur kya reachable hona chahiye?How does a Type-7 LSA become a Type-5, and what must be reachable?

Type-7 NSSA سے نکلتے وقت ABR پر Type-5 میں translate ہوتا ہے۔ Type-5 normal area میں ASBR براہ راست بناتا ہے۔ Forwarding address reachable ہونا ضروری ہے ورنہ OSPF route install نہیں کرتا۔Type-7 NSSA se nikalte waqt ABR par Type-5 mein translate hota hai. Type-5 normal area mein ASBR direct banata hai. Forwarding address reachable hona zaroori hai warna OSPF route install nahi karta.Type-7 is translated to Type-5 by the ABR as it leaves the NSSA. Type-5 is generated directly by an ASBR in a normal area. The forwarding address must be reachable, or OSPF won't install the route.

❓ MED کب compare ہوتا ہے، اور outbound vs inbound ٹریفک کون سے attributes کنٹرول کرتے ہیں؟MED kab compare hota hai, aur outbound vs inbound traffic kaun se attributes control karte hain?When is MED compared, and which attributes control outbound vs inbound traffic?

MED ڈیفالٹ صرف اسی neighbor AS کے paths کے درمیان compare ہوتا ہے، جبکہ AS-path length globally apply ہوتی ہے۔ Outbound ٹریفک کے لیے Local Preference AS-wide سب سے مضبوط knob ہے؛ inbound ٹریفک کے لیے AS-path prepending۔MED default sirf usi neighbor AS ke paths ke darmiyan compare hota hai, jabke AS-path length globally apply hoti hai. Outbound traffic ke liye Local Preference AS-wide sab se mazboot knob hai; inbound traffic ke liye AS-path prepending.MED is compared only between paths from the same neighboring AS by default, while AS-path length applies globally. Local Preference is the strongest AS-wide knob for outbound traffic; AS-path prepending influences inbound traffic.

❓ RD vs RT سمجھائیں، اور P روٹر کو VRF یا BGP کیوں نہیں چاہیے؟RD vs RT samjhayein, aur P router ko VRF ya BGP kyun nahi chahiye?Explain RD vs RT, and why the P router needs no VRF or BGP.

RD ہر VPNv4 prefix کو globally منفرد بناتا ہے (overlapping customer IPs کی اجازت)۔ RT VRFs کے درمیان import/export کنٹرول کرتا ہے — matched RTs سے ایک PE VRFs کے درمیان routes leak بھی کر سکتا ہے۔ P روٹر کو نہ VRF چاہیے نہ BGP؛ وہ صرف label-switch کرتا ہے۔RD har VPNv4 prefix ko globally unique banata hai (overlapping customer IPs ki ijazat). RT VRFs ke darmiyan import/export control karta hai — matched RTs se ek PE VRFs ke darmiyan routes leak bhi kar sakta hai. P router ko na VRF chahiye na BGP; wo sirf label-switch karta hai.RD makes each VPNv4 prefix globally unique (allowing overlapping customer IPs). RT controls import/export between VRFs — matched RTs even let one PE leak routes between VRFs. The P router needs neither VRF nor BGP; it only label-switches.

❓ DMVPN Phase 2 vs Phase 3، اور FlexVPN upgrade کیوں سمجھا جاتا ہے؟DMVPN Phase 2 vs Phase 3, aur FlexVPN upgrade kyun samjha jata hai?DMVPN Phase 2 vs Phase 3, and why is FlexVPN considered an upgrade?

Phase 2 میں spokes براہ راست tunnel بناتے ہیں لیکن hub کے ذریعے routing ہوتی ہے؛ Phase 3 NHRP redirect/shortcut سے spokes کو بہترین next-hop براہ راست ملتا ہے۔ FlexVPN IKEv2-based ہے، ایک ہی framework میں site-to-site اور remote-access دیتا ہے، اور اس کی policies زیادہ صاف ماڈیولر ہیں۔Phase 2 mein spokes direct tunnel banate hain lekin hub ke zariye routing hoti hai; Phase 3 NHRP redirect/shortcut se spokes ko behtareen next-hop direct milta hai. FlexVPN IKEv2-based hai, ek hi framework mein site-to-site aur remote-access deta hai, aur is ki policies zyada saaf modular hain.In Phase 2 spokes build direct tunnels but traffic still flows via the hub's routing; Phase 3 uses NHRP redirect/shortcut so spokes learn the optimal next-hop directly. FlexVPN is IKEv2-based, covers site-to-site and remote-access in one framework, and has cleaner modular policies.

❓ بڑے multicast deployments میں MSDP کو Anycast-RP کے ساتھ کیوں جوڑا جاتا ہے؟Bare multicast deployments mein MSDP ko Anycast-RP ke saath kyun jora jata hai?Why do large multicast deployments pair MSDP with Anycast-RP?

MSDP مختلف ڈومینز کے RPs کے درمیان active-source info share کرتا ہے تاکہ کوئی source miss نہ ہو۔ Anycast-RP سے receivers قریبی RP سے جڑتے ہیں اور ایک shared RP address سے redundancy ملتی ہے۔MSDP mukhtalif domains ke RPs ke darmiyan active-source info share karta hai taake koi source miss na ho. Anycast-RP se receivers qareebi RP se jurte hain aur ek shared RP address se redundancy milti hai.MSDP shares active-source information between RPs of different domains so no source is missed. Anycast-RP lets receivers join the nearest RP and gives redundancy with one shared RP address.

❓ MQC flow اور policing vs shaping ایک جواب میں سمجھائیں۔MQC flow aur policing vs shaping ek jawab mein samjhayein.Explain MQC flow and policing vs shaping in one answer.

Class-map ٹریفک کو match کرتا ہے (ACL/DSCP/NBAR)، policy-map ہر class کا عمل طے کرتا ہے (police/shape/bandwidth)، service-policy انٹرفیس پر لگاتا ہے۔ Policing اضافی ٹریفک فوری drop کرتا ہے (inbound کے لیے)؛ shaping queue کرتا ہے اور آہستہ بھیجتا ہے (outbound کے لیے)۔Class-map traffic ko match karta hai (ACL/DSCP/NBAR), policy-map har class ka action tay karta hai (police/shape/bandwidth), service-policy interface par lagata hai. Policing extra traffic fori drop karta hai (inbound ke liye); shaping queue karta hai aur dheere bhejta hai (outbound ke liye).Class-map matches the traffic (ACL/DSCP/NBAR), policy-map defines per-class actions (police/shape/bandwidth), service-policy applies it to the interface. Policing drops excess immediately (best inbound); shaping queues it and sends slower (best outbound).

❓ CoPP اور uRPF ایک دوسرے کو کیسے support کرتے ہیں؟CoPP aur uRPF ek doosre ko kaise support karte hain?How do CoPP and uRPF complement each other?

CoPP control-plane ٹریفک کو rate-limit کرتا ہے تاکہ حملے میں CPU بچ جائے اور routing چلتی رہے۔ uRPF source کی routing table سے تصدیق کر کے spoofed packets drop کرتا ہے — strict mode میں receiving interface ضروری، loose mode میں کوئی بھی انٹرفیس جہاں route ہو۔CoPP control-plane traffic ko rate-limit karta hai taake attack mein CPU bach jaye aur routing chalti rahe. uRPF source ki routing table se tasdeeq kar ke spoofed packets drop karta hai — strict mode mein receiving interface zaroori, loose mode mein koi bhi interface jahan route ho.CoPP rate-limits traffic destined for the control plane so the CPU survives attacks and routing stays up. uRPF drops spoofed-source packets by verifying the source against the routing table — strict mode requires the receiving interface, loose mode allows any interface with a route.

❓ Automation کے لیے NETCONF/RESTCONF CLI scraping سے کیوں بہتر ہے؟Automation ke liye NETCONF/RESTCONF CLI scraping se kyun behtar hai?What makes NETCONF/RESTCONF better than CLI scraping for automation?

YANG models سے defined structured XML/JSON — screen-scraping کی ضرورت نہیں۔ NETCONF operation-oriented (XML over SSH)؛ RESTCONF resource-oriented (JSON کے ساتھ HTTP verbs)۔YANG models se defined structured XML/JSON — screen-scraping ki zaroorat nahi. NETCONF operation-oriented (XML over SSH); RESTCONF resource-oriented (JSON ke saath HTTP verbs).Structured XML/JSON defined by YANG models — no screen-scraping. NETCONF is operation-oriented (XML over SSH); RESTCONF is resource-oriented (HTTP verbs with JSON).