A service provider upgraded its core routers to CRS-1. The service provider connects the CRS-1
to an internal network via CRS-1 management ports. This internal network is configured with
private IP addresses. All SSH access from a service provider workstation that is incoming to the
management ports of the CRS-1 routers was tested and was found to be working properly. The
routers were configured for AAA by using the Cisco Secure Access Control Server, and AAA was
working as desired. Furthermore, SNMP traffic used the inband 10-Gigabit Ethernet ports, and all
SNMP functionality was properly configured and tested prior to the rollout. After CRS-1 routers
were placed in production, a need arose to engage Cisco TAC to perform troubleshooting and
diagnosis on the routers. It was noted that while all service provider operations staff could access
the routers from the private IP-based management network, Cisco TAC could not access the
router because its connection was coming in on the inband 10-Gigabit Ethernet ports. The VTY
line ACLs were configured to allow the Cisco TAC source IP address, but that did not fix the
problem.
What is a possible cause for the lack of connectivity? (Choose one.)
A.
Local packet transport service is misconfigured.
B.
The Cisco IOS XR administration plane is misconfigured.
C.
The Cisco IOS XR IPv4 virtual address is not configured to be used as a source address.
D.
Management plane protection is misconfigured.
E.
WDSysMon is monitoring the incoming connection and disallowing it.