Index

SYMBOLS

3DES (Triple DES), 338

10BASE-2, 3335

10BASE-5, 3335

10BASE-T, 35

pin pairs, 36

10GBASE-S, 35

10GBASE-T, 35

100BASE-TX, 35

pin pairs, 36

802.1X, 179181

802.1X/EAP, 160

802.11 standards, 151152

802.3. See Ethernet

1000BASE-LX, 35

1000BASE-T, 35

A

AAA (authentication, authorization, and accounting), 178179

access attacks, 290

access control, 175

802.1X, 179181

AAA, 178179

local authentication, 175176

SSH configuration, 176177

switch port hardening, 178

access layer (hierarchical campus design), 25

access layer switches, 14

ACI (Application Centric Infrastructure), 386

ACLs (access control lists)

defining, 295

design guidelines, 299

extended named IPv4

adding comments, 306

configuring, 306

verifying, 307308

extended numbered IPv4

adding comments, 306

configuring, 303305

verifying, 307308

identification, 298299

inbound/outbound, 295296

IPv6 ACLs

configuring, 309311

IPv4 ACLs versus, 308309

verifying, 311313

list logic, 296297

operational overview, 295

standard named IPv4

adding comments, 306

configuring, 305306

verifying, 307308

standard numbered IPv4

adding comments, 306

configuring, 301303

verifying, 307308

troubleshooting, 313314

types of, 298

ad hoc mode, 154

addressing (Ethernet), 3738

addressing (IPv4). See IPv4 addressing

addressing (IPv6). See IPv6 addressing

administrative distance, 201203

advanced certifications, 410

adware, 288

AES (Advanced Encryption Standard), 161, 338

AF (Assured Forwarding), 346347

aging port security, 183184

AH (Authentication Header), 340

allowing. See permitting

AMP (Advanced Malware Protection), 173

amplification and reflection attacks, 292

Ansible, 403

anycast addresses, 75

AP architectures, 155157

APIC (Application Policy Infrastructure Controller), 386

APIC-EM (APIC Enterprise Module), 387388

APIs, RESTful, 400402

Application Centric Infrastructure (ACI), 386

application layer (OSI), 2

application layer (TCP/IP), 3, 5

Application Policy Infrastructure Controller (APIC), 386

APs (wireless access points), 1820

ARP (Address Resolution Protocol), 4

attack mitigation, 191193

types of attacks, 190191

assets, 285

assigned multicast addresses, 7374

Assured Forwarding (AF), 346347

asymmetric switching, 32

attack vectors, 286

attacks. See also threat mitigation

access attacks, 290

DoS and DDoS attacks, 291

IP attacks, 291292

reconnaissance attacks, 289

social engineering attacks, 290291

transport layer attacks, 292

types of, 287288

authentication

802.1X, 179181

AAA, 178179

local, 175176

VPNs, 340

WLANs, 158161

Authentication Header (AH), 340

auto-cost reference-bandwidth command, 269

automation. See network automation

auto-MDIX, 4748

autonomous AP architecture, 155

B

backing up Cisco IOS images, 376

baiting, 291

band of frequencies, 150151

bandwidth, 343

bandwidth command, 270

banner command, 210

BDR (backup designated router), 259, 279281

BID (bridge ID)

configuring and verifying, 108110

PVST+, 104105

binary, converting to/from decimal, 57

black hole VLANs, 8485

botnet, 291

BPDU Guard, configuring, 110111

BRI (Basic Rate Interface), 328

bridges, 29

broadcast addresses, 38

listing, 6061

broadcast domains, 31

BSA (basic service area), 153

BSS (basic service set), 153

BSSID (basic service set identifier), 153

buffer overflow attacks, 290

C

cable modems, 331

cabling

connection guidelines, 22

copper, 21

fiber-optic, 21

standards, 22

UTP, 3637

wireless, 21

CAPWAP (Control and Provisioning of Wireless Access Points), 157158

career options, 409410

CBWFQ (Class-Based Weighted Fair Queueing), 347

CDP (Cisco Discovery Protocol)

configuring, 352354

operational overview, 351352

verifying, 354356

cdp holdtime command, 354

cdp time command, 354

cellular service, 332

certificate, receiving, 409

certifications

advanced, 410

on resumé, 409410

certified score report, 407

channels, 150151

Chef, 405

choosing

network media, 21

routers, 15

switches, 14

WAN connections, 332

circuit-switched WAN connections, 328329

Cisco DNA Center

network management platform, 394395

purpose of, 391392

SDA and, 392393

Cisco ESA, 173174

Cisco IOS

basic configuration commands, 4547

command history, 44

console error messages, 43

EXEC sessions, 42

help facilities, 4243

IFS (Integrated File System), 371

commands, 371373

configuration file management, 374375

URL prefixes, 373374

images, 375

backing up, 376

restoring, 376377

navigating and editing commands, 4344

show commands, 4445

subconfiguration modes, 45

Cisco WSA, 174175

Class-Based Weighted Fair Queueing (CBWFQ), 347

classes (IPv4 addressing), 5657

classful routing protocols, 200

classification, 344347

classless routing protocols, 200

clear ip nat translation command, 323

clear ip ospf process command, 281, 283

clients (DHCPv4), configuring, 133134

cloud computing

benefits of, 379

services, 381382

virtual network infrastructure, 382383

cloud-based AP architecture, 155156

collision domains, 31

commands (Cisco IOS)

basic configuration commands, 4547

command history, 44

navigating and editing, 4344

show commands, 4445

subconfiguration modes, 45

comments, adding to IPv4 ACLs, 306

community clouds, 382

compromised-key attacks, 288

configuration management tools, 402

Ansible, 403

Chef, 405

comparison of, 405

Puppet, 403404

configure terminal command, 45

configuring

ACLs

extended named IPv4, 306

extended numbered IPv4, 303305

IPv6, 309311

standard named IPv4, 305306

standard numbered IPv4, 301303

CDP, 352354

default routing

IPv4, 245248

IPv6, 252

DHCP snooping, 189190

DHCPv4

as client, 133134

options, 128

to relay requests, 132133

as server, 128132

DHCPv6

options, 137

as stateful server, 139

as stateless server, 137139

dynamic ARP inspection (DAI), 192193

dynamic NAT, 320321

EtherChannel, 116117

HSRP, 122123

Layer 3 routed ports, 240

LLDP, 357358

multilayer switching, 238

NAT overload, 321322

NTP, 370371

OSPFv2, 275277

port security, 181183

Rapid PVST+, 111

router on a stick, 235238

routers

command syntax, 210, 217218

EUI-64 configuration, 218

with IPv4, 209217

with IPv6, 217220

link-local addresses, 219

verification, 212217

single-area OSPF, 265270

metrics, 268270

network command, 267268

passive interfaces, 268

router ID, 266267

router ospf command, 266

SNMP, 364

SSH, 176177

static NAT, 319320

static routing

IPv4, 242243

IPv6, 251

STP, 108

bridge ID (BID), 108110

PortFast and BPDU Guard, 110111

summary routing

IPv4, 248249

IPv6, 253

switches, 41

auto-MDIX, 4748

basic configuration commands, 4547

command history, 44

EXEC sessions, 42

half duplex, full duplex, port speed, 47

help facilities, 4243

navigating and editing commands, 4344

show commands, 4445

subconfiguration modes, 45

verifying connectivity, 4851

syslog, 367369

trunking, 9294

VLANs, 8892, 185186

WLANs, 165

RADIUS server, 166

virtual interface, 166168

WPA2 Enterprise, 168171

congestion management, 347

connecting to switches, 4142

connection establishment (TCP), 9

connection termination (TCP), 9

connectionless protocols, 910

connections

for VPNs, 337340

for WANs, 23, 326327

choosing, 332

circuit-switched, 328329

dedicated, 327328

Internet, 330332

packet-switched, 329330

connectivity, verifying, 4851, 220223

console error messages, 43

control plane, 383384

controllers, 384385

convergence

with link-state protocols, 206207

in STP, 101102

converting binary/decimal numbers, 57

copper cable, 20, 21

copy command, 374375

copy run start command, 212

copy running-config startup-config command, 210, 212

core layer (hierarchical campus design), 25

core layer switches, 1415

CSMA/CD, 3435

cut-through switching, 31

D

DAI (dynamic ARP inspection), 191193

data encapsulation. See encapsulation

Data Encryption Standard (DES), 338

data exfiltration, 286

data formats

comparison of, 397398

JSON, 398399

data link layer (OSI), 2

data modification attacks, 287

data plane, 383384

data VLANs, 84

DDoS (distributed denial of service) attacks, 291

dead intervals, modifying, 278

debug ip nat command, 323324

debuggers, 287

decimal, converting to/from binary, 57

dedicated WAN connections, 327328

default gateways, troubleshooting, 224225

default IEEE port costs, 101102

default routing

IPv4, configuring, 245248

IPv6, configuring, 252

operational overview, 241

redistribution, 277

default VLANs, 84

default-information originate command, 277

denial of service (DoS) attacks, 287, 291

denying

FTP, 304

hosts, 302, 305306

SSH, 303

subnets, 303

Telnet, 303, 304305

DES (Data Encryption Standard), 338

description command, 210

designated router (DR), 259, 279281

device hardening. See security

devices

connection guidelines, 22

firewalls, 16

hubs versus switches, 13

IDS/IPS, 17

next-generation firewalls, 1718

physical connections, 20

routers. See routers

switches. See switches

wireless access points/LAN controllers, 1820

DHCP (Dynamic Host Configuration Protocol), 3

attacks

mitigation, 188190

types of, 188

troubleshooting, 140

DHCPv4

configuring

as client, 133134

options, 128

to relay requests, 132133

as server, 128132

operational overview, 127128

DHCPv6

stateful, 136

configuring, 139

operational overview, 136137

stateless, 136

configuring, 137139

operational overview, 136137

Differentiated Services Code Point (DSCP), 345346

Digital Subscriber Line (DSL), 330331

Dijkstra algorithm, 205206

dir command, 372373, 376377

disabling VLANs, 96

distance vector protocols, 198199

administrative distance, 201203

IGP comparison summary, 203

metrics, 200201

distributed denial of service (DDoS) attacks, 291

distribution layer (hierarchical campus design), 25

distribution layer switches, 14

distribution system (DS), 153

DMVPN (Dynamic Multipoint VPN), 335336

DNS (Domain Name System), 3

operational overview, 140142

troubleshooting, 142143

DoS (denial of service) attacks, 287, 291

DR (designated router), 259, 279281

DS (distribution system), 153

DSCP (Differentiated Services Code Point), 345346

DSL (Digital Subscriber Line), 330331

DTP (Dynamic Trunking Protocol), 8788

dual-homed WANs, 325

dual-stacking, 8081

dumpster diving, 291

duplex command, 47, 52

duplicate IP addresses, troubleshooting, 225

dynamic ARP inspection (DAI), 191193

Dynamic Host Configuration Protocol. See DHCP (Dynamic Host Configuration Protocol)

Dynamic Multipoint VPN (DMVPN), 335336

dynamic NAT, 318

configuring, 320321

dynamic routing

administrative distance, 201203

classful protocols, 200

classless protocols, 200

convergence, 206207

Dijkstra algorithm, 205206

distance vector protocols, 198199

IGP and EGP, 198

IGP comparison summary, 203

link-state protocols, 199, 204207

LSDB, building, 204205

metrics, 200201

protocol types, 198

routing loop prevention, 203204

static routing versus, 197

Dynamic Trunking Protocol (DTP), 8788

E

eavesdropping attacks, 287

edge ports, RSTP, 107

editing Cisco IOS commands, 4344

EF (Expedited Forwarding), 346347

EGP (exterior gateway protocols), 198

EIGRP (Enhanced Interior Gateway Routing Protocol), 203

enable secret command, 210

encapsulation, 45, 12

encryption

tools, 287

VPNs, 338

WLANs, 161162

endpoint security, 173

Cisco ESA, 173174

Cisco WSA, 174175

error recovery, 78

ESP (Encapsulating Security Payload), 341

ESS (extended service set), 154

EtherChannel

benefits of, 114

configuring, 116117

operational overview, 113114

protocols, 115116

restrictions, 114

troubleshooting, 119

verifying, 117119

Ethernet, 4

addressing, 3738

current technologies, 35

framing, 3839

legacy technologies, 3335

operational overview, 3233

switches. See switches

UTP cabling, 3637

EUI-64 configuration, 7879, 218

exam

after completion, 407

certified score report, 407

failed, 410

receiving certificate, 409

what to bring, 407

EXEC sessions, 42

exit-interface parameter, IPv4 static routing, 244245

Expedited Forwarding (EF), 346347

exploits, 285

extended IPv6 ACLs, configuring, 310311

extended named IPv4 ACLs

adding comments, 306

configuring, 306

verifying, 307308

extended numbered IPv4 ACLs

adding comments, 306

configuring, 303305

verifying, 307308

extended service set (ESS), 154

extended system ID, PVST+, 104105

exterior gateway protocols (EGP), 198

F

fabric, 390

failed exam, 410

Fast Ethernet, 35

FHRPs (first-hop redundancy protocols), 119120

fiber-optic cable, 20, 21

firewalls, 16

next-generation, 1718

flow control, 8

forensic tools, 287

fragment-free mode, 32

frame forwarding, 3132

framing (Ethernet), 3839

FTP (File Transfer Protocol), 3

denying, 304

full duplex, 47

full mesh WANs, 325

G

GCMP (Galois/Counter Mode Protocol), 161

Gigabit Ethernet, 35

GLBP (Gateway Load Balancing Protocol), 120

global unicast addresses, 6870

GRE (Generic Routing Encapsulation), 334

H

hacking operating systems, 287

half duplex, 47

hashes, 338340

header (TCP), 6

header format (IPv4), 55

hello intervals, modifying, 278

help facilities in Cisco IOS, 4243

hierarchical campus designs, 2527

host ID (IPv4), 55

host IP settings, 143

on Linux, 146148

on macOS, 145146

on Windows, 143145

host ranges, listing, 6061

hostname command, 210

hosts, denying, 302, 305306

hot keys for Cisco IOS commands, 4344

HSRP (Hot Standby Router Protocol), 120

configuring and verifying, 122123

load balancing, 123125

operational overview, 121

priority and preemption, 122

troubleshooting, 126

versions, 121

HTTP (Hypertext Transfer Protocol), 3

HTTP methods, RESTful APIs and, 400

hub-and-spoke WANs, 325

hubs

limitations, 29

switches versus, 13

hybrid clouds, 382

I

IaaS (Infrastructure as a Service), 382

IBSS (Independent Basic Service Set), 154

ICMP (Internet Control Message Protocol), 4

ICMP attacks, 292

icons for networking diagrams, 13

IDS (intrusion detection systems), 17

IFS (Integrated File System), 371

commands, 371373

configuration file management, 374375

URL prefixes, 373374

IGP (interior gateway protocols), 198, 203

IMAP (Internet Message Access Protocol), 3

impersonation, 291

inbound ACLs, 295296

infrastructure mode, 152154

interface ACLs, 295296

interface command, 210

interface IDs, subnetting, 78

interface rance command, 47

interface status codes, 52, 213214

Internet layer (TCP/IP), 3, 10

Internet Protocol (IP), 4

Internet WAN connections, 330332

internetworks, 23

inter-VLAN routing

Layer 3 routed port configuration, 240

legacy inter-VLAN routing, 233234

multilayer switching, 235

configuring and verifying, 238

router on a stick, 234

configuring and verifying, 235238

SVIs, creating, 238240

types of, 233

intranets, 23

intrusion detection systems (IDS), 17

intrusion prevention systems (IPS), 17

IP (Internet Protocol), 4

ip address command, 210

IP address spoofing attacks, 287, 292

IP attacks, 291292

ip helper-address command, 132133

IP host settings. See host IP settings

ip ospf cost command, 270

ip ospf priority command, 279

ip route command, 242

ipconfig command, 4849

IPP (IP Precedence), 345346

IPS (intrusion prevention systems), 17

IPSec, 340341

IPv4 addressing

ACLs

adding comments, 306

extended named configuration, 306

extended numbered configuration, 303305

IPv6 ACLs versus, 308309

standard named configuration, 305306

standard numbered configuration, 301303

verifying, 307308

classes of addresses, 5657

default routing, configuring, 245248

header format, 55

IPv6 addressing versus, 66

JSON format, 399

migrating to IPv6, 8081

private/public addressing, 58

resolving conflicts, 140

router configuration, 209217

command syntax, 210

verification, 212217

verifying connectivity, 220223

routing table, 229230

static routing

configuring, 242243

exit-interface parameter, 244245

next-hop parameter, 244

subnetting

addressing scheme, listing, 6061

bits to borrow, determining, 5960

examples, 6162

purpose of subnet masks, 5758

steps in, 5859

subnet masks, determining new, 60

subnet multiplier, determining, 60

VLSM, 6264

summary routing, configuring, 248249

troubleshooting, 224225

IPv4 embedded addresses, 7273

ipv6 access-list command, 309

ipv6 address autoconfig command, 138

ipv6 address dhcp command, 139

IPv6 addressing

ACLs

configuring, 309311

IPv4 ACLs versus, 308309

verifying, 311313

address conventions, 76

address types, 6768

anycast addresses, 75

benefits of, 6566

default routing, configuring, 252

EUI-64 configuration, 7879

IPv4 addressing versus, 66

migrating to, 8081

multicast addresses, 7375

assigned, 7374

solicited-node, 7475

prefix conventions, 7677

router configuration, 217220

command syntax, 217218

EUI-64 configuration, 218

link-local addresses, 219

verifying connectivity, 220223

routing table, 230

SLAAC, 7980

static routing

configuring, 251

operational overview, 249250

subnetting, 7778

summary routing, configuring, 253

troubleshooting, 224225

unicast addresses, 6873

global, 6870

IPv4 embedded, 7273

link-local, 71

loopback, 71

unique local, 72

unspecified, 71

ipv6 route command, 251

J

jitter, 343

JSON (JavaScript Object Notation), 398399

L

LACP (Link Aggregation Control Protocol), 115116

LANs (local-area networks)

components of, 23

threat mitigation

ARP, 190193

DHCP, 188190

VLANs, 185187

latency (delay), 343

Layer 1 problem indicators, 54

Layer 2 switching, 32

Layer 3 routed ports, configuring, 240

Layer 3 switching, 32

layers (hierarchical campus design), 2527

layers (OSI)

list of, 23

PDUs, 45

physical, 3940

layers (TCP/IP)

application, 5

encapsulation summary, 12

Internet, 10

list of, 3

network access, 1012

transport, 510

leased lines, 327328

legacy Ethernet technologies, 3335

legacy inter-VLAN routing, 233234

lightweight AP architecture, 156157

line console command, 210

line vty 0 15 command, 210

Link Aggregation Control Protocol (LACP), 115116

link-local addresses, 71, 219

link-state advertisements (LSAs), 258261, 278279

link-state database (LSDB), 204205

link-state protocols, 199, 204207

convergence, 206207

Dijkstra algorithm, 205206

LSDB, building, 204205

link-state routing process, OSPF, 260261

Linux, verifying host IP settings, 146148

list logic of ACLs, 296297

LLC (Logical Link Control) sublayer, 3233

LLDP (Link Layer Discovery Protocol)

configuring, 357358

operational overview, 357

verifying, 358360

lldp holdtime command, 357

lldp reinit command, 357

lldp run command, 357

lldp timer command, 357

LLQ (Low Latency Queueing), 347

load balancing HSRP, 123125

local authentication, 175176

local-area networks. See LANs (local-area networks)

logging into WLC, 163165

logical topologies, 2425

login command, 210

login local command, 210

longest match, 227228

loopback addresses, 71

loss, 343

LSAs (link-state advertisements), 258261, 278279

LSDB (link-state database), 204205

M

MAC (Media Access Control) sublayer, 32, 33

macOS, verifying host IP settings, 145146

malware, 288289

management plane, 383384

management VLANs, 85, 185186

man-in-the-middle attacks, 288, 290, 292

marking, 344347

media issues, troubleshooting, 5152

memory buffering, 32

mesh topology, 154

messages (SNMP), 361362

metrics

dynamic routing, 200201

single-area OSPF, 268270

Metro Ethernet, 329

MIB (Management Information Base), 362363

mitigation. See threat mitigation

modifying OSPFv2

default route redistribution, 277

DR/BDR election, 279281

hello and dead intervals, 278

Moran, Matthew, 409410

MPLS (Multiprotocol Label Switching), 330

MST (Multiple Spanning Tree), 102

MSTP (Multiple Spanning Tree Protocol), 102

multiarea OSPF, 262

design, 262264

performance, 264

multicast addresses, 38, 7375

assigned, 7374

solicited-node, 7475

multilayer switching, 235

configuring and verifying, 238

municipal Wi-Fi, 332

N

named IPv4 ACLs

adding comments, 306

extended configuration, 306

standard configuration, 305306

verifying, 307308

NAT (Network Address Translation)

benefits of, 319

dynamic, 318

configuring, 320321

limitations, 319

overloading, 318319

configuring, 321322

process overview, 317

static, 318

configuring, 319320

terminology, 315317

troubleshooting, 323324

verifying, 322323

native VLANs, 85, 185186

navigating Cisco IOS commands, 4344

Neighbor Solicitation (NS) messages, 134

network access layer (TCP/IP), 3, 1012

Network Address Translation. See NAT (Network Address Translation)

network attacks, 289

access attacks, 290

DoS and DDoS attacks, 291

IP attacks, 291292

reconnaissance attacks, 289

social engineering attacks, 290291

transport layer attacks, 292

network automation

configuration management tools, 402

Ansible, 403

Chef, 405

comparison of, 405

Puppet, 403404

data formats

comparison of, 397398

JSON, 398399

RESTful APIs, 400402

network command, 267268

network ID (IPv4), 55

network layer (OSI), 2

network media, 2022

choosing, 21

copper, 21

fiber-optic, 21

standards, 22

wireless, 21

network scanning/hacking tools, 286

networking icons, 13

networks, permitting, 302

next-hop parameter, IPv4 static routing, 244

NGFWs (next-generation firewalls), 1718

no cdp enable command, 353354

no cdp run command, 353

no lldp receive command, 357

no lldp transmit command, 357

no service dhcp command, 130

no shutdown command, 210

NS (Neighbor Solicitation) messages, 134

NTP (Network Time Protocol), 370371

ntp server command, 370

numbered IPv4 ACLs

adding comments, 306

extended configuration, 303305

standard configuration, 301303

verifying, 307308

O

Open Shortest Path First. See OSPF (Open Shortest Path First)

open system authentication, 159

OpenDaylight, 385386

OpenFlow, 385386

OpFlex, 386

OSI (Open Systems Interconnection) model, 12

layers

list of, 23

physical, 3940

PDUs, 45

OSPF (Open Shortest Path First), 203

multiarea, 262

design, 262264

performance, 264

network types, 278279

OSPFv2, OSPFv3 versus, 261262

single-area, 255

algorithm, 259260

configuring, 265270

DR and BDR, 259

link-state advertisements, 258261

link-state routing process, 260261

message format, 255256

neighbor establishment, 256258

packet types, 256

verifying, 270274

troubleshooting, 281283

OSPFv2

configuration example, 275277

modifying

default route redistribution, 277

DR/BDR election, 279281

hello and dead intervals, 278

OSPFv3 versus, 261262

single-area

configuring, 265270

verifying, 270274

OSPFv3, OSPFv2 versus, 261262

outbound ACLs, 295296

overlay, 390, 391

overloading NAT, 318319, 321322

P

PaaS (Platform as a Service), 382

packet crafting tools, 287

packet forwarding, 195, 228

longest match, 227228

path determination and switching functions, 196197

packet sniffers, 287

packet-switched WAN connections, 329330

PAgP (Port Aggregation Protocol), 115

passive interfaces, OSPF, 268

passive-interface command, 268

password command, 210

password crackers, 286

password recovery, 377378

password-based attacks, 287, 290

path determination and switching functions, 196197

PDUs (protocol data units), 45

penetration testing tools, 286287

permitting

networks, 302

SSH, 310

web traffic, 310311

Per-VLAN Spanning Tree Plus. See PVST+ (Per-VLAN Spanning Tree Plus)

phishing, 290

physical connections, 20

troubleshooting, 5152

physical layer (OSI), 2, 3940

physical topologies, 2425

ping command, 48, 4950

successful, 220221

unsuccessful, 221

Platform as a Service (PaaS), 382

point-to-point WANs, 325

policing, 347349

POP3 (Post Office Protocol), 3

Port Aggregation Protocol (PAgP), 115

port hardening, 178

port numbers, 7

port redirection, 290

port roles, RSTP, 106107

port security, 181

aging, 183184

configuring, 181183

restoration, 184185

port speed, 47

port states

PVST+, 104

RSTP, 105106

port-based memory, 32

PortFast, configuring, 110111

positive acknowledgment, 7

positive acknowledgment with retransmission, 8

Post Office Protocol (POP3), 3

preemption, HSRP, 122

prefixes (IPv6), 7677

presentation layer (OSI), 2

pretexting, 290

PRI (Primary Rate Interface), 328

priority, HSRP, 122

private clouds, 382

private IP addressing, 58

protocol data units (PDUs), 45

protocols (TCP/IP), list of, 34

public clouds, 382

public IP addressing, 58

Puppet, 403404

PVST+ (Per-VLAN Spanning Tree Plus), 102

extended system ID, 104105

operational overview, 103104

port states, 104

Q

QoS (quality of service)

classification and marking, 344347

congestion management, 347

policing and shaping, 347349

TCP discards, 349

tools, 344

traffic types, 343344

quid pro quo attacks, 291

R

RA (Router Advertisement) messages, 134

radio frequencies. See RF spectrum

RADIUS (Remote Authentication Dial-In User Service), 178179

RADIUS server, configuring, 166

ransomware, 288

Rapid PVST+, 102

configuring, 111

edge ports, 107

interface behavior, 105

operational overview, 105

port roles, 106107

port states, 105106

Rapid STP. See RSTP (Rapid STP)

receiving certificate, 409

reconnaissance attacks, 289

redundancy, 99100

reference bandwidth, 268269

relaying requests, DHCPv4, 132133

reliability, 78

remote access with SSH, 222223

remote-access VPNs, 334

RESTful APIs, 400402

restoring

Cisco IOS images, 376377

ports, 184185

resumé, certifications on, 409410

RF spectrum, 149150

channels, 150151

RIPv2 (Routing Information Protocol version 2), 203

risk, 285

Rivest, Shamir, and Adleman (RSA), 338

rootkit detectors, 287

rootkits, 289

Router Advertisement (RA) messages, 134

router ID, 266267

router on a stick, 234

configuring and verifying, 235238

router ospf command, 266

Router Solicitation (RS) messages, 134

router-id command, 266267

routers, 15

configuring

command syntax, 210, 217218

EUI-64 configuration, 218

with IPv4, 209217

with IPv6, 217220

link-local addresses, 219

verification, 212217

default routing

IPv4 configuration, 245248

IPv6 configuration, 252

operational overview, 241

redistribution, 277

dynamic routing

administrative distance, 201203

classful protocols, 200

classless protocols, 200

convergence, 206207

Dijkstra algorithm, 205206

distance vector protocols, 198199

IGP and EGP, 198

IGP comparison summary, 203

link-state protocols, 199, 204207

LSDB, building, 204205

metrics, 200201

protocol types, 198

routing loop prevention, 203204

static routing versus, 197

packet forwarding, 195, 228

longest match, 227228

path determination and switching functions, 196197

password recovery, 377378

purpose of, 227

SOHO, 24, 223224

static routing

exit-interface parameter, 244245

IPv4 configuration, 242243

IPv6 configuration, 249251

next-hop parameter, 244

operational overview, 241

summary routing

IPv4 configuration, 248249

IPv6 configuration, 253

verifying connectivity, 220223

Routing Information Protocol version 2 (RIPv2), 203

routing loop prevention, 203204

routing tables

components of, 228231

entry structure, 232

longest match, 227228

principles, 231

RS (Router Solicitation) messages, 134

RSA (Rivest, Shamir, and Adleman), 338

RSTP (Rapid STP), 102

configuring, 111

edge ports, 107

interface behavior, 105

operational overview, 105

port roles, 106107

port states, 105106

S

SaaS (Software as a Service), 382

satellite Internet, 332

SDA (Software-Defined Access)

architecture, 389

Cisco DNA Center and, 392393

fabric, 390

overlay, 391

underlay, 390391

SDN (software-defined networking), 383

ACI, 386

APIC-EM, 387388

controllers, 384385

data, control, management planes, 383384

OpenFlow, 385386

spine and leaf design, 387

Secure Shell. See SSH (Secure Shell)

Secure Socket Layer (SSL), IPSec versus, 340

security

access control, 175

802.1X, 179181

AAA, 178179

local authentication, 175176

SSH configuration, 176177

switch port hardening, 178

attack types, 287288

attack vectors, 286

data exfiltration, 286

endpoint security, 173

Cisco ESA, 173174

Cisco WSA, 174175

IPSec, 340341

malware types, 288289

network attacks, 289

access attacks, 290

DoS and DDoS attacks, 291

IP attacks, 291292

reconnaissance attacks, 289

social engineering attacks, 290291

transport layer attacks, 292

password recovery, 377378

penetration testing tools, 286287

port security, 181

aging, 183184

configuring, 181183

restoration, 184185

programs, 293

terminology, 285

VPN connections, 337340

WLANs, 158

authentication, 158161

encryption, 161162

selecting. See choosing

server virtualization, 379381

servers (DHCPv4), configuring, 128132

servers (DHCPv6), configuring stateless, 137139

service sequence-numbers command, 367

service set identifier (SSID), 153

service timestamps command, 367

service-password encryption command, 211

session hijacking, 292

session layer (OSI), 2

shaping, 347349

shared key authentication, 159160

shared memory, 32

shortcut keys for Cisco IOS commands, 4344

shoulder surfing, 291

show access-lists command, 307, 312

show cdp command, 353

show cdp interface command, 352, 354

show cdp neighbors command, 353

show cdp neighbors detail command, 354356

show cdp traffic command, 356

show commands (Cisco IOS), 4445

show etherchannel summary command, 117118

show file systems command, 371

show flash: command, 372, 376377

show history command, 44

show interface command output, 215217

show interface gigabitethernet 0/0 command, 214215

show interface GigabitEthernet0/0/0 command, 398

show interface status command, 95

show interface switchport command, 118119

show interfaces command, 210

duplex and speed mismatches, 5254

interface status codes, 52

interface VLAN assignment, 9192

show interfaces status command, 5254

show interfaces switchport command, 95, 98

show interfaces trunk command, 9394, 97

show ip dhcp binding command, 130

show ip dhcp conflict command, 140

show ip dhcp server statistics command, 130

show ip interface brief command, 210, 213, 237238, 270272

show ip interface command, 307

show ip nat statistics command, 323

show ip nat translations command, 322

show ip ospf command, 266, 273274, 283

show ip ospf interface brief command, 274

show ip ospf interface command, 283

show ip ospf interfaces command, 266

show ip ospf neighbor command, 272, 282

show ip protocols command, 202, 266, 270272, 282

show ip route command, 200201, 210, 212213, 237238, 270272

show ip route ospf command, 283

show ipv6 access-list command, 312

show ipv6 interface command, 138, 313

show ipv6 interface gigabitethernet 0/0 command, 220

show ipv6 route command, 251

show lldp command, 358360

show lldp interface command, 358360

show lldp neighbors command, 358360

show lldp neighbors detail command, 358360

show lldp traffic command, 358360

show logging command, 367369

show mac address-table command, 95

show ntp associations command, 370371

show ntp status command, 370371

show port-security command, 182183

show port-security interface command, 184

show run command, 117, 311312, 323

show running-config command, 210, 212, 307308

show snmp command, 364365

show snmp community command, 365

show spanning-tree active command, 111

show spanning-tree bridge command, 111

show spanning-tree command, 110, 111

show spanning-tree detail command, 111

show spanning-tree interface command, 111

show spanning-tree summary command, 111

show spanning-tree vlan command, 111

show standby command, 122123

show version command, 375

show vlan brief command, 8889, 90, 91, 95

show vlan command, 95, 96

show vlan id command, 95

show vlans command, 237238

Simple Mail Transfer Protocol (SMTP), 3

Simple Network Management Protocol. See SNMP (Simple Network Management Protocol)

single-area OSPF, 255

algorithm, 259260

configuring, 265270

metrics, 268270

network command, 267268

passive interfaces, 268

router ID, 266267

router ospf command, 266

DR and BDR, 259

link-state advertisements, 258261

link-state routing process, 260261

message format, 255256

neighbor establishment, 256258

packet types, 256

verifying, 270274

site-to-site VPNs, 333

SLAAC (stateless address autoconfiguration), 7980, 134135

SMTP (Simple Mail Transfer Protocol), 3

sniffer attacks, 288

SNMP (Simple Network Management Protocol), 3, 361

components of, 361

configuring, 364

messages, 361362

MIB, 362363

verifying, 364365

versions, 362

snmp-server community command, 364

snooping (DHCP), 188190

social engineering attacks, 290291

Software as a Service (SaaS), 382

Software-Defined Access. See SDA (Software-Defined Access)

software-defined networking. See SDN (software-defined networking)

SOHO (small office/home office), 2324, 223224

solicited-node multicast addresses, 7475

something for something attacks, 291

spam, 290

Spanning Tree Protocol. See STP (Spanning Tree Protocol)

spanning-tree mode rapid-pvst command, 111

spear phishing, 290

speed command, 47, 52

spine and leaf design, 387

split-MAC architecture, 157158

spoofing attacks (DHCP), 188, 290

spyware, 289

SSH (Secure Shell)

configuring, 176177

denying, 303

permitting, 310

remote access with, 222223

SSID (service set identifier), 153

SSL (Secure Socket Layer), IPSec versus, 340

standard IPv6 ACLs, configuring, 310

standard named IPv4 ACLs

adding comments, 306

configuring, 305306

verifying, 307308

standard numbered IPv4 ACLs

adding comments, 306

configuring, 301303

verifying, 307308

starvation attacks (DHCP), 188

stateful DHCPv6, 136

configuring, 139

operational overview, 136137

stateless address autoconfiguration (SLAAC), 7980, 134135

stateless DHCPv6, 136

configuring, 137139

operational overview, 136137

static IP addresses, testing connectivity, 140

static NAT, 318

configuring, 319320

static routing. See also default routing; summary routing

dynamic routing versus, 197

IPv4

configuring, 242243

exit-interface parameter, 244245

next-hop parameter, 244

IPv6

configuring, 251

operational overview, 249250

operational overview, 241

store-and-forward switching, 31

STP (Spanning Tree Protocol)

algorithm, 100101

benefits of, 99100

configuring, 108

bridge ID (BID), 108110

PortFast and BPDU Guard, 110111

convergence, 101102

varieties, 102103

verifying, 111

subconfiguration modes (Cisco IOS), 45

subnet addresses, listing, 6061

subnet IDs, subnetting, 78

subnet masks

determining new, 60

purpose of, 5758

subnets, denying, 303

subnetting

examples, 6162

in IPv6 addressing, 7778

steps in, 5859

addressing scheme, listing, 6061

bits to borrow, determining, 5960

subnet masks, determining new, 60

subnet multiplier, determining, 60

VLSM, 6264

summary routing

IPv4, configuring, 248249

IPv6, configuring, 253

SVIs (switch virtual interfaces), creating, 238240

switches

access layer, 14

benefits of, 37

choosing, 14

collision/broadcast domains, 31

configuring, 41

auto-MDIX, 4748

basic configuration commands, 4547

command history, 44

EXEC sessions, 42

half duplex, full duplex, port speed, 47

help facilities, 4243

navigating and editing commands, 4344

show commands, 4445

subconfiguration modes, 45

verifying connectivity, 4851

connecting to, 4142

core layer, 1415

distribution layer, 14

evolution to, 29

frame forwarding, 3132

hubs versus, 13

Layer 2/Layer 3, 32

memory buffering, 32

operational overview, 3031

password recovery, 377378

port hardening, 178

symmetric/asymmetric, 32

troubleshooting, 5154

duplex and speed mismatches, 5254

interface status codes, 52

Layer 1 problem indicators, 54

media issues, 5152

verifying port configuration, 140

switchport port-security aging command, 183

switchport port-security violation command, 181

symmetric switching, 32

syslog

configuring and verifying, 367369

message format, 367

operational overview, 365367

severity levels, 366

T

TACACS+ (Terminal Access Controller Access Control System Plus), 178179

tailgating, 291

TCP (Transmission Control Protocol), 3

attacks, 292

connection establishment/termination, 9

error recovery, 78

flow control, 8

header, 6

port numbers, 7

QoS and, 349

TCP/IP (Transmission Control Protocol/Internet Protocol) model, 12

layers

application, 5

encapsulation summary, 12

Internet, 10

list of, 3

network access, 1012

transport, 510

protocols, list of, 34

Telnet, 3

denying, 303, 304305

terminal history command, 44

terminal history size 50 command, 44

terminal no history command, 44

terminal no history size command, 44

threat mitigation, 285

ARP, 190193

DHCP, 188190

VLANs, 185187

threats, 285

TKIP (Temporal Key Integrity Protocol), 161

topologies, 2425

WANs, 325

traceroute command

successful, 221

unsuccessful, 222

tracert command, 5051

traffic types, 84

Transmission Control Protocol. See TCP (Transmission Control Protocol)

transport input ssh command, 210

transport layer attacks, 292

transport layer (OSI), 2

transport layer (TCP/IP), 3, 510

Triple DES (3DES), 338

Trojan horses, 288

troubleshooting

ACLs, 313314

DHCP, 140

DNS, 142143

EtherChannel, 119

HSRP, 126

IP addressing, 224225

NAT, 323324

OSPF, 281283

switches, 5154

duplex and speed mismatches, 5254

interface status codes, 52

Layer 1 problem indicators, 54

media issues, 5152

trunking, 9698

VLANs, 9495

trunking

configuring, 9294

DTP, 8788

troubleshooting, 9698

verifying, 9294

VLANs, 8687

trust exploitation, 290

tunneling, 8081

VPNs, 337338

U

UDP (User Datagram Protocol), 4

attacks, 292

as connectionless, 910

port numbers, 7

ULAs (unique local addresses), 72

underlay, 390391

unicast addresses, 6873

global, 6870

IPv4 embedded, 7273

link-local, 71

loopback, 71

unique local, 72

unspecified, 71

unspecified unicast addresses, 71

URIs (uniform resource identifiers), 400401

User Datagram Protocol. See UDP (User Datagram Protocol)

username password command, 210

username secret command, 175176

UTP (unshielded twisted pair) cabling, 3637

V

variable-length subnet masking (VLSM), 6264

verifying

bridge ID (BID), 108110

CDP, 354356

DHCP snooping, 189190

EtherChannel, 117119

host IP settings

on Linux, 146148

on macOS, 145146

on Windows, 143145

HSRP, 122123

IPv4 ACLs, 307308

IPv6 ACLs, 311313

LLDP, 358360

multilayer switching, 238

NAT, 322323

network connectivity, 220223

NTP, 370371

router configuration with IPv4, 212217

router on a stick, 235238

single-area OSPF, 270274

SNMP, 364365

STP, 111

switch connectivity, 4851

switch port configuration, 140

syslog, 367369

trunking, 9294

VLANs, 8892

virtual local-area networks. See VLANs (virtual local-area networks)

virtual machines (VMs), 380381

virtual network infrastructure, 382383

virtual private networks. See VPNs (virtual private networks)

Virtual Router Redundancy Protocol (VRRP), 120

virtualization, 379381

viruses, 288

VLANs (virtual local-area networks). See also inter-VLAN routing

attacks

mitigation, 187

types of, 186

benefits of, 8384

configuring, 8892, 185186

disabling, 96

traffic types, 84

troubleshooting, 9495

trunking, 8687

types of, 8485

verifying, 8892

VLSM (variable-length subnet masking), 6264

VMs (virtual machines), 380381

voice VLANs, 85

VPNs (virtual private networks), 333

benefits of, 333

components of, 336337

secure connections, 337340

types of access, 333336

VRRP (Virtual Router Redundancy Protocol), 120

vulnerability, 285

vulnerability explotation tools, 287

vulnerability scanners, 287

W

WANs (wide-area networks)

connections, 23, 326327

choosing, 332

circuit-switched, 328329

dedicated, 327328

Internet, 330332

packet-switched, 329330

topologies, 325

web traffic, permitting, 310311

WEP (Wired Equivalent Privacy), 159

Wi-Fi Protected Access (WPA), 159, 160

WiMAX, 332

windowing, 8

Windows, verifying host IP settings, 143145

wireless access points (APs), 1820

wireless hacking tools, 286

wireless LAN controller. See WLC (wireless LAN controller)

wireless LANs. See WLANs (wireless LANs)

wireless network media, 20, 21

wireless protocols, 4

wireless standards

802.11 standards, 151152

channels, 150151

RF spectrum, 149150

wireless topologies

AP architectures, 155157

CAPWAP, 157158

IBSS, 154

infrastructure mode, 152154

mesh, 154

wireless WAN connections, 332

WLANs (wireless LANs), 1820

configuring

RADIUS server, 166

virtual interface, 166168

WPA2 Enterprise, 168171

security, 158

authentication, 158161

encryption, 161162

WLC (wireless LAN controller)

configuring with WLAN, 165

RADIUS server, 166

virtual interface, 166168

WPA2 Enterprise, 168171

logging into, 163165

worms, 288

WPA (Wi-Fi Protected Access), 159, 160

WPA2, 160

WPA2 Enterprise WLANs, configuring, 168171

WPA3, 160161

Z

zombies, 291

..................Content has been hidden....................

You can't read the all page of ebook, please click here login for view all page.
Reset
18.188.181.163