exam questions

Exam 300-410 All Questions

View all questions & answers for the 300-410 exam

Exam 300-410 topic 1 question 218 discussion

Actual exam question from Cisco's 300-410
Question #: 218
Topic #: 1
[All 300-410 Questions]


Refer to the exhibit. In an attempt to increase the network security, the administrator applied the Gi3-in ACL to the Gi3 interface. After the ACL was applied, clients in the network connected to Gi3 lost their ability to obtain IP settings from DHCP.
Which two configuration commands must be added to the Gi3-in ACL to reinstate the DHCP service for the clients? (Choose two.)

  • A. 74 permit udp 192.168.30.0 0.0.0.255 eq bootpc host 192.168.255.3 eq bootps
  • B. 71 permit udp host 0.0.0.0 eq bootps host 255.255.255.255 eq bootpc
  • C. 73 permit udp host 0.0.0.0 eq bootpc host 192.168.255.3 eq bootps
  • D. 72 permit udp host 192.168.255.3 eq bootps 192.168.30.0 0.0.0.255 eq bootpc
  • E. 75 permit udp host 0.0.0.0 eq bootpc host 255.255.255.255 eq bootps
Show Suggested Answer Hide Answer
Suggested Answer: A 🗳️

Comments

Chosen Answer:
This is a voting comment (?). It is better to Upvote an existing comment if you don't have anything to add.
Switch to a voting comment New
Huntkey
Highly Voted 2 years, 6 months ago
For first time DHCP client, the discover and request messages would all be from 0.0.0.0 to 255.255.255.255. So E is needed. https://wiki.wireshark.org/uploads/__moin_import__/attachments/DHCP/dhcp-ws.png For renewing with DHCP request, the source is the current assigned IP and the destination is server itself. So A is needed. Other packets like inform is from the assigned IP to the 255.255.255.255. The existing ACL entry allows for it already. I will go with AE.
upvoted 16 times
...
JingleJangus
Highly Voted 2 years, 10 months ago
Selected Answer: A
A and E To get this question, you MUST be comfortable with the DHCP-DORA Exchange. Discover: Src: 0.0.0.0 Dest: 255.255.255.255 Offer: Src: <DHCP Server Address> Dest: <Relay Address> OR 255.255.255.255 Request: Src: 0.0.0.0 Dest: 255.255.255.255 Ack: Src: <DHCP Server Address> Dest: <Relay Address> OR 255.255.255.255 Given the Inbound ACL applied to the Client-Facing Interface, AT A MINIMUM, E is required. DHCP will also use Unicast for other operations and upkeep, so A is also important. https://community.cisco.com/t5/switching/concerning-acl-with-dhcp/td-p/1239487
upvoted 8 times
t1s
2 years, 4 months ago
Yes, A & E is correct. E > for DORA A > for renew https://www.cloudshark.org/captures/0009d5398f37
upvoted 5 times
...
...
UglaJohn
Most Recent 1 month, 2 weeks ago
Selected Answer: E
AE sounds fair
upvoted 1 times
...
don123t
4 months, 4 weeks ago
Selected Answer: E
choose 2 so DE client always 0.0.0.0 ->255.255.255.255 server sevrip -> broadcast
upvoted 1 times
...
test190502
7 months, 1 week ago
I think you have to choose two from the options, but was there originally one option? In any case, since “host 0.0.0.0” cannot be set, I think the correct answers are A and D.
upvoted 1 times
...
tubirubs
8 months, 2 weeks ago
Selected Answer: C
C. This entry allows DHCP requests from any client (with an IP of 0.0.0.0 because clients don’t have an IP address before getting one from DHCP) using port 68 (bootpc) to the DHCP server at 192.168.255.3 using port 67 (bootps). D. This entry allows DHCP replies from the DHCP server (192.168.255.3) using port 67 (bootps) to the clients in the 192.168.30.0/24 subnet using port 68 (bootpc).
upvoted 1 times
...
[Removed]
9 months, 1 week ago
Selected Answer: A
A & E are correct
upvoted 2 times
...
Commando1664
1 year ago
all you actually need is permit udp any any eq bootps
upvoted 1 times
...
guy276465281819372
1 year, 8 months ago
Selected Answer: E
A & E CORRECT
upvoted 2 times
...
inteldarvid
1 year, 9 months ago
Selected Answer: A
A and E correct https://networkengineering.stackexchange.com/questions/38044/dhcp-bootpc-acl
upvoted 2 times
...
Malasxd
1 year, 11 months ago
Selected Answer: A
A and E are correct.
upvoted 2 times
...
HungarianDish_111
1 year, 11 months ago
Selected Answer: E
For me E + A. https://community.cisco.com/t5/switching/acl-not-working-as-intended/td-p/4168422 "permit udp host 0.0.0.0 eq boopc host 255.255.255.255 eq bootps. For the DHCP IP renewal, you can configure permit udp 10.20.20.0 0.0.0.255 eq bootpc host 128.1.99.1 eq bootps. Reason why the one you configured would not work for DHCP DORA is because when the client first time tries to get an IP, it sources with 0.0.0.0, and the DHCP request will be broadcasted to the IP 255.255.255.255. However, when the client tries to renew its IP address, it would source from its IP address which will be within the subnet 10.20.20.0/24, and will send the renewal request to the DHCP server IP as unicast." https://www.certforums.com/threads/acl-allow-access-to-dhcp-server.36762/
upvoted 5 times
...
6dd4aa0
2 years ago
Selected Answer: D
From Figure 7-2 (Pg 127 CCNA 200-301 Volume 2) DHCP Client PC-A --(From: 0.0.0.0 To: 255.255.255.255)--> Router ----------------------------------> DHCP Server 192.168.30.1 192.168.255.3 Option E will be correct. =================================================================== From Figure 7-3 (Pg 128 CCNA 200-301 Volume 2) PC-A <------------------------- Router <---(From 192.168.255.3 To:192.168.30.1)--- DHCP Server 192.168.30.1 192.168.255.3 Option D will be correct.
upvoted 1 times
pyrokar
1 year, 11 months ago
It is an inbound ACL, it does not filter answers from the server
upvoted 2 times
pyrokar
1 year, 11 months ago
To be more precise, it is inbound on the interface facing the clients. Since there is a helper-address configured (in another subnet), the dhcp server is on another interface. So this ACL is not applied to answeers from the server. It would if it was applied outbound or on another interface.
upvoted 1 times
...
...
...
Typovy
2 years, 1 month ago
A E is correct. D is pointless because source IP address is DHCP server addres. This ACL is applied to LAN facing interface inbound so DHCP server as source here will have no matches :)
upvoted 2 times
...
TECH3K3
2 years, 9 months ago
I labbed this and none of the combinations worked. B, C and D can't be added to the ACL as I get a message "% % Duplicate sequence number." A and E can be added to the ACL but the PC doesn't get an IP address and you get a syslog message ... list Gi3-in denied udp 192.168.30.2(67) -> 192.168.30.100(68), 2 packets If I removed the ACL the PC gets an IP address
upvoted 1 times
TECH3K3
2 years, 9 months ago
UPDATE!! I moved the ACL from a router interface to a swicth interface and ONLY E was needed for me to obtain an IP address
upvoted 1 times
TECH3K3
2 years, 9 months ago
I also think it's D and E just from looking at past configs for a company I use to work for
upvoted 2 times
...
...
...
johnu329
2 years, 9 months ago
D and E bootpc = udp/68 bootps = udp/67 Client-end port is 68; Server-end port is 67 (http://klamp.works/2016/04/29/dhcp.html) Therefore, correct answers are D and E: --> To server (port 67) E. 75 permit udp host 0.0.0.0 eq bootpc host 255.255.255.255 eq bootps --> To client (port 68) D. 72 permit udp host 192.168.255.3 eq bootps 192.168.30.0 0.0.0.255 eq bootpc
upvoted 2 times
...
piojo
2 years, 10 months ago
Selected Answer: A
LABED it. Correct are A and B. It should be FROM bootpc (client) TO bootps (server). Source is 0.0.0.0 to 255.255.255.255 when first get and IP Source is 192.168.30.X to 192.168.30.3 when renewing.
upvoted 1 times
WAKIDI
2 years, 9 months ago
did you mean A and E ?. the usage of bootc and boots seems to be better in E.
upvoted 2 times
...
piojo
2 years, 10 months ago
Sorry, A and C.
upvoted 1 times
JingleJangus
2 years, 10 months ago
I would disagree; Clients initially send to a Broadcast Destination of 255.255.255.255, not Unicast. Yes, the Relay is going to modify the Destination to Unicast; but since the ACL is applied in the inbound direction, this Destination translation is only going to happen AFTER the ACL has been applied to received traffic. https://community.cisco.com/t5/switching/concerning-acl-with-dhcp/td-p/1239487
upvoted 2 times
...
...
...
Community vote distribution
A (35%)
C (25%)
B (20%)
Other
Most Voted
A voting comment increases the vote count for the chosen answer by one.

Upvoting a comment with a selected answer will also increase the vote count towards that answer by one. So if you see a comment that you already agree with, you can upvote it instead of posting a new comment.

SaveCancel
Loading ...
exam
Someone Bought Contributor Access for:
SY0-701
London, 1 minute ago