ccie security lab v5000
-
- 4402 Reviews
MCR and PCR
1. refuse 2. allowed
Configure virtual loopback interface ( loopback interface defaults to UP state ) inerface loopback? Create a loopback interface
Support for multiple network layer protocols through NCP can achieve " authentication ", " compression ", " error detection ", " multi-link " through LCP .
3. Routing Table => Best Route
De discard Eligibility is used in the Frame Relay network to tell the switch if the switch is too
=========================================================== =====================
B#show ip nat translations view translation relationship table
1.Server mode < main > 2.Client mode < time > 3.TransParent mode < transparent >
Table or logical address table.
Create a VLAN
=========================================================== ===============
ESF extended superframe (Extended Superframe) of 24 composed of frames, each frame of 192 bits , the first 193 than
=========================================================== ===============
Advertising ( advertisement ) routing or service update is sent at a given interval, allowing on the network
Medium, indicating the beginning and end of each character. Compare isochronous transmission .
Spanning-tree vlan 1 priority ? Modify the priority of the switch to change the cost cost of the interface
0x2142 bypasses the process of loading startup-config , or : does not load the boot configuration , directly enter the setup mode 0x2102 router default configuration key value , perform the normal boot sequence .
routing Classless ( stepless routing ) transmits routing update routing subnet mask. Stepless road
Connectionless link. It is mainly used to send SMDS packets on the ATM network . See AAL
A connectionless protocol responsible for sending datagrams over an internetwork.
A logical collection of information. IP datagrams have become the main unit of information for the Internet. In the OSI layers reference model, the term cell (Cell) , frame (Frame) , the message (message) and the segment (segment) also define these logical information groupings.
Or hub port duplex.
A device that acts as a destination, source, or both. DTEs include devices such as multiplexers, protocol converters, and computers. A connection to a data network is a data communication device that uses a clock signal generated by the device
Copy tftp: flash:
Note :
The ETA/TIA-232 circuit indicates the state in which the DTE sends or receives data ready.
Network 192.168.1.0 0.0.0.255 area 0
Configure ACL to reject london to access Denver
=========================================================== ===============
=========================================================== ===================
AS AS (autonomous system) a group of networks under the management of another, they share the same
Adopt standard :
And headers and trailers for synchronization and error control, which surround the data contained in the unit.
WAN type and encapsulation protocol :
=========================================================== ===============
enable secret provided in the ciphertext enable password ( in preference to the use plaintext ) service password-encryption of all encryption system cleartext password ( weak )
CER cell error ratio (cell error ratio) ATM cell, a transmission error within a certain time and
16 , 32 , 64 and 128 are used.
bridge. The bridge ID is a combination of bridge priority and base MAC address.
IGRP uses composite metrics to select the best route .
Frame-relay switching
Configuration register starts the configuration key , and modifying it will affect the startup sequence of the Router .
Setup manually enter the setup configuration mode
=========================================================== ===============
Immediate execution , immediate effect
AAL1 ATM Adaptation Layer 1 One of the four AALs recommended by ITU-T for connection-oriented, constant
=========================================================== ===============
Router eigrp 100
UTR Data Terminal Ready (Data Terminal Ready) ----- an activated with DCE communication
The station's HDLC communication mode, where the transmission can start from the primary station or a secondary station.
Media type : twisted pair , coaxial cable , fiber
collapsed backbone ( folded backbone ) all network segments via a network interconnection device connected to each other
BIP bit interleaved parity (Bit Interleaved Parity) ATM are used to monitor the link on the error
The benefits of E3 and T3) are maximized.
OSI seven-layer network model : Protocol data unit
explorer packet ( probes ) of a transmission source of the token ring devices SNA packet for a source found
CHAP: Challenge three-way handshake , the password is transmitted by HASH algorithm , which is stronger than PAP.
=========================================================== ================
Access control list (ACL)
ACL two actions :
congestion avoidance ( congestion avoidance ) to minimize latency, the ATM network for controlling the system into
No * do the reverse operation of the configuration
Interface Serial1 no ip address
AAL2 ATM Adaptation Layer ----- ITU-T 2 recommendations four AAL one , to support variable bit rate connection-oriented traffic, such as voice traffic see AAL
ISL 's main road agreement created an 802.1Q main road in 2950
Network 192.168.1.0 0.0.0.3
HUB Hub : A broadcast domain, a collision domain. Flooding forwarding . Shared bandwidth . Straight line : the host and switch or HUB connected
Extended Setup ( extended set ) used in the setting mode to configure the router, it is more than the basic setting mode
destination address ( destination address ) receiving a data packet network device address.
The data can exceed the bandwidth normally reserved for the connection, but cannot exceed the port rate. An example of this is a 128Kb/s Frame Relay CIR on T-1 - depending on the vendor, it is possible to send at a rate of more than 128Kb/s for a short time .
Application layer : user interface DATA
------------------------------------------------
Data rate between 622Mb/s and higher. See BRI , ISDN, and PRI .
0x0 indicates that the router is going to enter the Rom monitor mode.
NetMask: target network subnet mask
Address mapping ( address mapping ) by converting a network address from one format to another, this
Network layer :
Network 192.168.1.4 0.0.0.3
OSPF area :
VLAN characteristics
CSMA / CD carrier with Collision Detection Sense Multiple Access (Carrier Sense Multiple Access / Collision Detect ) Ethernet IEEE802.3 a technology committee defined. Every device is sending
A feature that changes routing.
FECN: Forward Explicit Congestion Notice
Target port : None
Show ip route eigrp to see the best route for all EIGRP ( stored in the routing table )
bridge priority ( bridge priority ) disposed bridge STP priority. By default all bridges take precedence
congestion collapse ( congestion collapse ) the ATM results in the packet network due to retransmission, wherein little or no
FECN forward explicit explicit notification (Forward Explicit Congestion Notification) by Frame Relay Network
No * do the reverse operation of the configuration
Fallback (in the fall ) ATM network, this mechanism is used to get a path,ccie security lab v5000, if it can not use the regular side
There are two types of ACLs :
=========================================================== ===============
BIP bit interleaved parity (Bit Interleaved Parity) ATM are used to monitor the link on the error
ARA AppleTalk Remote Access (AppleTalk Remote Access) is built for Macintosh users
System Autonomous ( AS ) refer to the AS .
Ip address 1.1.1.1 255.0.0.0 Configure the IP address of the interface
CPCS CPCS layer (Common Part Convergence Sublayer) two business
Blocking -> Listening -> Learning -> Forwarding
DCE data communication device ( by JIA defined ) or a data circuit-terminating equipment ( according to ITU-T defined ) constituted by
(PDU) Add header information. For example, in Internet terminology. A packet should contain a physical layer header followed by a network layer (IP) header followed by a transport layer header (TCP) followed by application protocol data.
Bit ( bit, bit ) A number ; a 1 or a 0 . 8 bits make up one byte.
No * do the reverse operation of the configuration
=========================================================== ===============
FRAME-RELAY LMI Signaling
Fast Ethernet ( Fast Ethernet ) ---- speed lOOMb / s Ethernet specification. Fast Ethernet ratio
Set a user password or authentication protocol
floodming ( diffusion ) an interface when receiving traffic it will be transmitted to the originating communication interfaces in addition to the amount of
Bit, Frame, Packet, and Segment are all called : PDU (Protocol Data Unit)
=========================================================== ===============
Frame-relay route 120 interface Serial0 110
Access-list 1 deny host 10.3.3.1 access-list 1 permit any
Exit returns to the upper mode
VTP is a messaging system . Ensures that all of the switches in the same management domain below network VLAN
B8ZS binary 8 replacement - a line coding, explained at the far end of the connection, when transmitting eight zeros continuously on the link of the T-1 and E-1 circuits, it uses a special Code replacement. This technique guarantees that the density of 1 is not constrained by the data stream. Also known as bipolar 8 zero replacement. Compare AMI . See ones density .
bridge group ( bridging group ) in a bridge configuration of the router, bridge group number determined by a unique
Rip Version 2 :
Port Console ( control port opening ) the Cisco a typical routers and switches on the RJ-45 ports, with
Apply application related configuration
=========================================================== ===============
bit-oriented protocol ( bit oriented protocol ) regardless of the content of the frame, the data link layer communication protocol such
Any device connected between. See Cisco FRAD and FRAS .
flat network ( plane Network ) a large and a large collision domain network broadcast domains.
Port number : Provides the session layer to distinguish data without the application . Identity service .
System Autonomous ( AS ) refer to the AS .
=========================================================== ================
Ethernet cable type for switch or switch to hub.
BGP neighbors (BGP neighbor ) starts a communication process to exchange routing information dynamically two
Interface s 1.??? point-to-point enables a peer -to- peer subinterface . ??? is the interface number . ip add 10.1.1.1 255.255.255.0 configures the ip for the subinterface
Directed broadcast (a direct broadcast ) a data frame or packet is transmitted to a remote network segment specific
connection-oriented ( connection-oriented ) to establish a virtual circuit data before any data transmission
=========================================================== ===============
Used to " fused " the capabilities of various routers and switch sets .
A(config-if)#ip rip authentication mode md5 ciphertext authentication
NextHopIP: Next hop IP
=========================================================== ===============
Ip route 4.0.0.0 255.0.0.0 s0
EIGRP external routing management distance : 170 EIGRP internal routing management distance : 90 show ip eigrp neighbors to view EIGRP neighbors
destination address ( destination address ) receiving a data packet network device address.
accounting ( statistics ) ----- AAA one of the three components. Statistics provide auditing and recording skills for security models
CER cell error ratio (cell error ratio) ATM cell, a transmission error within a certain time and
10.1.1.0/255.255.255.0
The path is activated on an analog modem.
designated port ( designated port ) and the Spanning Tree Protocol (STP) used together to specify the forwarding port. If
3. Routing Table => Best Route
1. Transmission area ( backbone area ) 2. Common area ( non-backbone area )
Address mapping .
Set a user password or authentication protocol
FRAS FR access support (Frame Relay Access Support) ----- Cisco IOS a characteristic of the software, which allows the SDLC , Ethernet, Token Ring and Frame Relay connections IBM upper frame relay network equipment can Other
Negotiation.
The bit, that is, a number cannot be divisible by 8 . Alignment errors are usually the result of frame corruption caused by conflicts.
Discover the best route for traffic from the source to its destination.
=========================================================== =====================
access rate ( access speed ) ----- bandwidth rate defined circuit. For example, the access rate of the T-1 circuit is
Autoreconfiguration ( automatic reconfiguration ) token ring domain failure of a process performed by the node,
degree.
Source : 10.3.3.1
lOBaseT is ten times faster, while retaining properties like MAC mechanism, MTU and frame format. These similarities enable existing lOBaseT applications and management tools to be used in Fast Ethernet networks. Fast Ethernet is an extension (IEEE 802.3U) based on the IEEE802.3 specification . Compare Ethemnet . See lOOBaseT , IOOBaseTX, and IEEE .
Transmission method. Use acknowledgments and flow control for reliable data transfer. Contrast connectionless . See virtual circuit .
Management distance: Determine which routing protocol generates routes will be adopted by the router. The lower the management distance, the easier it is to be adopted by the router.
Numbered recommended standards in ISDN , SMDS, and BISDN . 2) A flag for the field in the ATM address containing the E.164 format number .
Packaging method. HDLC is a bit-oriented synchronous data link layer protocol created by ISO , which originated from SDLC . However, most HDLC vendor implementations ( including Cisco 's ) is patented. See SDLC .
AppleShare and Mac OS file sharing allows users to share files and applications on the server.
bit-oriented protocol ( bit oriented protocol ) regardless of the content of the frame, the data link layer communication protocol such
=========================================================== ===============
CPCS CPCS layer (Common Part Convergence Sublayer) two business
Ppp chap password cisco sends local password in CHAP mode
Frame-relay switching
1900 only supports ISL trunk protocol 2950 only supports 802.1Q trunk protocol 3550 supports 802.1Q and
ISDN channel. Compare B channel , E channel and H channel . 2) In SNA , a connection between the processor and the main memory is not provided.
B(config)#inte s 1
Frame Relay switching ( Frame Relay switching ) service provider router frame relay packets provided
Autoreconfiguration ( automatic reconfiguration ) token ring domain failure of a process performed by the node,
It uses two pairs of twisted-pair cable (3 class 4 class or 5 classes ) , one pair for transmitting data to the other for receiving data.
Is a point-to-multipoint connection. See control directVCC .
authentication ( authentication ) AAA first component model. Users generally pass the username and port
ELAP EtherTalk Link Access Protocol (EtherTralk Link Access Protocol) on EtherTalk Network
ISL 's main road agreement created an 802.1Q main road in 2950
!
Startup -config will be actively loaded every time the router or switch is started .
FRAD Frame Relay access device (Frame Relay access device) to provide LAN and Frame Relay WAN
Rip management distance : 120
" The main explanation is B , C words that begin with. (ChinaITLab)
Classical IP over ATM ( classical IP over ATM) is defined in RFC 1577 to make ATM features
Endpoint ATM (ATM endpoint ) beginning or end of an ATM network is connected. ATM endpoints include
Used to determine the duplex mode and speed that can be used.
Adapt to traffic or buried
Please refer to the second part of the CCNA Professional English Vocabulary Collection : Classic Recommendations ; CCNA Professional English Vocabulary Collection
ATCP AppleTalk control program (the AppleTalk Control Program) : establishing and configuring AppleTalk over
data compression ( data compression ) See compression .
In user mode and privileged mode.
Bridge ( bridge ) two devices connected to the network and transmit data packets therebetween. Both paragraphs must use the same
=========================================================== ==============
8 bits are used to define the network, and 24 bits are used to define hosts on the network.
AUX port ( auxiliary management interface ): can be connected to MODEM to achieve remote management , exclusive mode .
ARM asynchronous response mode (Asynchronous Response Mode) uses a master station and at least one auxiliary
An octet divided into four points, followed by a forward slash and the number of the masked bit ( abbreviation of the subnet symbol ) . See
The amount of time. By default, the cdp timer is 90 seconds.
There is a command line interface function.
Ways allow different protocols to alternate
IOS Cisco Cisco Internetwork Operating System Software (Cisco Internetwork Operating System software) ----- as CiscoFusion provide the functionality shared by all products in the off-line configuration, scalability and security of Cisco core routers and switches series. See CiscoFusion .
AAL5 ATM Adaptation Layer 5 One of the four AALs recommended by ITU-T , mainly used to support inter-face connection
IGPs: Internal Gateway Routing Protocol , which maintains routes within an autonomous system
The ISDN interface for communication , which consists of two B channels ( each 64 Kb/s) and one D channel (16 Kb/s) . Compare PRT . See BISDN .
B (config-if) #ip nat inside configured S0 interface inside the network
FDDI Fiber Distributed Data Interface (Fiber Distributed Data Interface) ANSIX3T9.5 defined
connection-oriented ( connection-oriented ) to establish a virtual circuit data before any data transmission
Each network elects a root bridge BridgeID Lowest
Owned and running network.
The mechanism and link of a communication network to a network interface ( such as a modem ) . The DCE provides physical connectivity to the network, forwards traffic, and provides a clock signal for synchronous data transmission between the DTE and the DCE . Compare DTE .
firewall ( firewall ) intentionally a barrier between any public network and a private network settings from a
Ping 1.1.1.1 detects the validity of the interface
ATMARP server (ATMAPR server ) provides a logical subnet to run the address resolution service.
The fixed length enables cells to be processed and exchanged in hardware at high rates, making this technology the basis for ATM and other high-speed network protocols. See cell .
Vtp server configures this switch to enable pruning for server mode [server|client |transparent] vtp pruning
Interface Serial1 no ip address
Spanning-tree vlan 1 priority ? Modify the priority of the switch to change the cost cost of the interface
The interface interface processor card provides lOMb/s AUI port support for Ethernet version 1 and Ethernet version 2 or IEEE 802.3 interface with high speed data path to other interface processors .
Serial1 is administratively down, Line protocol is down
FRAME-RELAY is a non-broadcast multi-access type network that does not support broadcasting.
Endpoints ( endpoint ) see BGP neighbors .
Control direct VCC .
A(config-keychain)#key 1Configure key 1 A(config-keychain-key)#key-string cisco define password A(config-keychain-key)#exit
1. Control network traffic 2. Implement packet filtering
It enables two socket (Socket) can be reliably performed between transactions, wherein a request for another execution of a given task and to report the results. ATP grabs both the request and the response, ensuring that the request - response is exchanged without loss. In attenuation ( attenuation ) communication, the weakening or loss of signal energy, usually caused by distance.
The designated router is in case of failure.
automatic call reconnect ( automatic call reconnection ) of the automatic call can avoid failure of the relay line
=========================================================== ===============
If the source address and destination address of the data frame are from the same port , the switch will discard the data frame by default .
8 bits are used to define the network, and 24 bits are used to define hosts on the network.
=========================================================== ===============
FEIP Fast Ethernet Interface Processor (Fast Ethernet Interface Processor) Cisco7000 Series Routing
The traffic " rounds and goes to the router.
Data Link Control layer ( data link control layer ) the SNA first architecture model 2 layer, which is responsible for
Ppp chap password cisco sends local password in CHAP mode
NetMask: target network subnet mask
CISCO router , the serial interface defaults cisco HDLC encapsulation in practical applications , Cisco HDLC incompatible standard hdlc.
A service-related sublayer of the AAL ATM adaptation layer data link layer, data link layer from other applications
expedited delivery ( accelerated delivery ) may be the same or other layers of protocol of a different network device in
ELAN emulation LAN (emulated LAN) emulates Ethernet or commands using a client / server model
VTP Vlan Trunk Protocol
Interface Serial1 no ip address
VTP has three modes :
=========================================================== ===============
Router eigrp 100
Port Auxiliary ( auxiliary port ) the Cisco console port on the router backplane, which allows the call routing
Sended and is not reliable. Compare connection-oriented . See virtual circuit .
An interface processor used by the device to provide two lOOMb/s lOOBaseT ports.
Use more than one metric to find the best path to a remote network. By default, both IGRP and EIGRP use the bandwidth and latency of the line. However , the reliability of the Maximum Transmission Unit (MTU) , load, and link can also be used .
Frame-relay switching
Surgery. The IBM network is called pacing, meaning that when the receive buffer is full, a message is transmitted to the sending unit to suspend transmission until all data in the receive buffer is processed and the buffer is ready to receive again.
!
Owned and running network.
Setup manually enter the setup configuration mode
frame identification (frame tagging) ( frame identifier, frame flag ) the VLAN can span multiple connections
The protocol layer of the layer communication specifies an option that requires the identified data to be located faster.
A(config-keychain)#key 1Configure key 1 A(config-keychain-key)#key-string cisco define password A(config-keychain-key)#exit
=========================================================== ===============
Access-list 100 permit IP any any
Note :
The device has the hardware address of all devices on the internetwork. The server will then dynamically allocate the used VLANs .
ABR area border router ----- located in one or more OSPF area boundary OSPF routers, ABR is used to OSPF connection region to the OSPF backbone area
Free Fragment Forwarding (cisco private technology ): between pass-through forwarding and storage forwarding performance .
CiscoView GUI management software for Cisco network devices that provides dynamic status, statistics, and full
=========================================================== ===============
OSPF area :
ATP AppleTalk transaction protocol (AppleTalk Transaction Protocol) a transport layer protocol,
Packet Exchange : X.25, Frame-Relay, ATM
Different frequency and phase relationships. Asynchronous transfers typically encapsulate a single character in control bits ( called start and stop bits )
Sending CDP packets every 60 seconds ( every 60 transmits second cdp packet ) HoldTime 180 seconds ( per CDP information is saved 180 [ seconds )
Layer and Transport layer .
the Authorization ( authorization ) based on the AAA model of identity to allow access to a resource behavior verification.
Serial1 is down, Line protocol is down
=========================================================== ===============
buffer ( Buffer ) designed to store data processed in the transmission. Buffer for receiving / storage
switchport access vlan 10 Add this port to 10 VLAN in .
EIGRP external routing management distance : 170 EIGRP internal routing management distance : 90 show ip eigrp neighbors to view EIGRP neighbors
DHCP Dynamic Host Configuration Protocol (Dynamic Host Configuration Protocol) ----- DHCP is
=========================================================== ===============
border gateway ( border gateway ) to facilitate a communication router routers in different autonomous systems with.
access rate ( access speed ) ----- bandwidth rate defined circuit. For example, the access rate of the T-1 circuit is
=========================================================== =============== HDLC:
=========================================================== ===============
B(config-if)#ip nat outside configure S1 interface for the outside network to specify which hosts can NAT
Governing system path.
=========================================================== ================
There is traffic successfully reaching the destination. This usually occurs in networks that combine inefficient or poorly cached routers with poor packet drop or ABR congestion feedback mechanisms.
Routers running BGP ; they use a TCP port on layer 4 of the OSI Reference Model . Especially using TCP
CPCS CPCS layer (Common Part Convergence Sublayer) two business
1. Connected to a service . 2. Connection based on virtual link PVC: permanent virtual link
CO central office (central office) , all circuits in a certain area are connected here, is the subscriber line
DSAP destination point energize business (Destination Service Access Point) a network node of business
VLAN; all switches in the end-to-end \VLAN understand all configured VLANs . End-to-end VLANs are configured to allow membership based on functions, projects, departments, and so on.
Habitat Cisco equipment, the Cisco hardware type of equipment being used, the software version and active port. It uses SNAP frames between devices and is not routable.
Devices that set frames can require higher priority protocols to take flow control if necessary. See BECN .
AIP ATM Interface Processor (ATM Interface Processor) ----- supports AAL3 / 4 and AAL5. Cisco
=========================================================== ================
AAL3/4 ATM Adaptation Layer 3/4 One of the four AALs recommended by ITU-T , supporting connection-oriented and also support
Data link layer :
Link state type routing protocol:
10Mbps 100
Information can be used to determine if the network has recently caused a change in the problem.
Set a user password or authentication protocol
Thus, the switch has exited the switch at the leading edge of the output before the packet is fully entered into the input port. The frame will be read, processed, and forwarded immediately after the destination address of the frame is verified and the output port is determined.
!
interface fastethernet 0/1 enter fa0 / 1 interface
=========================================================== ===============
The program accepts the data and brings it into the 48- byte payload segment of the ATM layer . CS and SAR are the two sublayers of AAL . Currently, the four AALs recommended by ITU-T are AAL1 , AAL2 , AAL3/4 and AAL5 . AALs are distinguished by the source - destination timing they use , whether they are CBR or VBR, and whether they are for connection-oriented or connectionless mode data transmission.