Index

Symbols

{ } (braces), 415

: (colon), 91

# delimiter symbol, 335336

2.4 GHz band, 110

5 GHz band, 110

10 Gig Ethernet, 35

10BASE-T, 35

10GBASE-T, 35

40 Gig Ethernet, 35

40GBASE-LR4, 35

100BASE-T, 35

802.1D Spanning Tree Protocol, 174176

802.11 wireless standards, 110

802.3 Ethernet standards, 35, 3637

1000BASE-LX, 35

1000BASE-T, 35

A

AAA (authentication, authorization, and accounting), 318, 328330

aaa new-model command, 329

Abort indicator, 43

access control. See device access control

access control lists. See ACLs (access control lists)

access layer, 1829

access points (APs), 5, 191192

access-list 1 command, 252

access-list deny command, 359

access-list permit command, 359, 362

ACI (Application Centric Infrastructure), 397

ACLs (access control lists), 318, 353367

ACEs (access control entries), 358

advantages of, 353

extended, 358, 362

named, 360361

numbered, 358359

standard, 358

active routers, 239

active virtual forwarders (AVFs), 240

active virtual gateway (AVG), 240

AD (administrative distance), 206209, 218, 243

Adaptive Security Appliance (ASA), 7

addresses

IPv4, 6587

broadcast, 7475

classes of, 6768

IP parameter verification, 8081

multicast, 7475

online resources for, 87

private, 7778

subnet masks, 6869

subnetting, 6672

unicast, 7475

IPv6, 89107

anycast, 93

configuration of, 9596

global unicast, 9192

link-local unicast, 92

modified EUI-64, 92, 9697

multicast, 92

online resources for, 106107

SLAAC (stateless address autoconfiguration) of, 93, 9798

subnetting, 9192

types of, 9093

unique local, 92

verification of, 9697, 100101

MAC (media access control)

aging, 127

learning, 127

MAC address tables, 128

maximum, 372

sticky MAC address learning, 373374

PAT (Port Address Translation), 253

source addressing, 333

administrative distance (AD), 206209, 218, 243

administrative trustworthiness, 208209

Advanced Encryption Standard (AES), 384

adware, 315

AES (Advanced Encryption Standard), 384

aging MAC (media access control) addresses, 127

AI (artificial intelligence), 8

alignment errors, 43

alternate ports, 181

Amazon Web Services (AWS)

Database Migration Service, 2622

DataSync, 2622

Ansible, 411412

anycast addresses, 93

anycast keyword, 93

APIC-EM (APIC Enterprise Module), 397

APIs (application programming interfaces)

horizontal, 398

northbound, 397

RESTful

characteristics of, 408409

definition of, 398

southbound, 397

Application Centric Infrastructure (ACI), 397

Application layer (OSI model), 55

application programming interfaces. See APIs (application programming interfaces)

application virtualization, 120

APs (access points), 5, 191192

architectures

network topology, 1730

cloud services, 2627

DHCP (dynamic host configuration protocol), 280

NAT (Network Address Translation), 250

online resources for, 2930

OSPFv2 (open shortest path first version 2), 226

point-to-point, 22

on-premises resources, 26

SOHOs (small offices/home offices), 22

Spanning Tree Protocol, 176

three-tier architecture, 1819

two-tier architecture, 1819

two-tier spine-leaf, 1819

WANs (wide-area networks), 2122

software-defined, 396398

artificial intelligence (AI), 8

ASA (Adaptive Security Appliance), 7

asymmetric-key algorithms, 347

attacks

KRACK (Key Reinstallation Attack), 385

types of, 314316

zero-day, 317

authentication, authorization, and accounting (AAA), 318, 328330

authNoPriv level, 299

authPriv level, 299

Auto MDI-X, 35

auto setting (EtherChannel), 155

autoconfiguration, IPv6, 93

Automatic medium-dependent interface crossover (Auto MDI-X), 35

automation, 393405

benefits of, 394395

Cisco DNA (Digital Network Architecture) Center, 400401

controller-based networking, 396398

online resources for, 405

autonomous mode, 191

AVFs (active virtual forwarders), 240

AVG (active virtual gateway), 240

AWS (Amazon Web Services)

Database Migration Service, 2622

DataSync, 2622

B

babbles, 43

Baby Giant frames, 42

backup designated router (BDR), 231

backup ports, 181

bands, 110

banner login # command, 335336

banner motd command, 336

banners

login, 335336

MOTD (message-of-the-day), 336

BDR (backup designated router), 231

BE (best effort) quality of service, 301

BID (bridge ID), 175

bidirectional NAT (Network Address Translation), 250

binary numbers, converting decimals to, 67

bogons, 77

braces ({ }), 415

bridge ID (BID), 175

bridge mode, 191

bridges

BID (bridge ID), 175

definition of, 175

root, 175

broadband PPPoE (Point-to-Point Protocol over Ethernet), 22

broadcast networks, 231

broadcasts, 43, 7475

buffer logging, 298

C

cabling, 3349

Ethernet, 3436

Auto MDI-X, 35

fiber-optic media, 3536

frames, 42

point-to-point links, 36

shared media, 36

standards for, 35

UTP (unshielded twisted pair), 35

online resources for, 49

PoE (Power over Ethernet), 3637

serial connections, 3738

troubleshooting

potential errors and problems, 4044

show interface command, 41, 43

CAPWAP (Control and Provisioning of Wireless Access Points), 191

carrier-sense multiple access with collision avoidance (CSMA/CA), 5, 42

Cat 1-Cat 7 cables, 35

CBWFQ (class-based weighted fair queueing), 303

CCMP (Counter Cipher Mode with Block Chaining Message Authentication Code Protocol), 385

CCX (Cisco Compatible Extensions), 190

CDP (Cisco Discovery Protocol), 144, 164166

cdp enable command, 165

cdp run command, 165

CEF (Cisco Express Forwarding), 201

channel-group 2 mode desirable, 155

channel-group 3 mode active command, 156

channel-group command, 154

channels, 110

Chef, 412413

Cisco APIC Enterprise Module (APIC-EM), 397

Cisco Catalyst 9800-L wireless controller, 188189

Cisco Compatible Extensions (CCX), 190

Cisco Discovery Protocol (CDP), 144, 164166

Cisco DNA (Digital Network Architecture) Center, 1011, 400401

Cisco Express Forwarding (CEF), 201

Cisco Firepower NGFW (next-generation firewalls), 8

Cisco Identity Services Engine (ISE), 346

Cisco Mobility AnyConnect, 345

Cisco Open SDN Controller, 397

Cisco wireless architectures, 187195

AP (access point) modes, 191192

CAPWAP (Control and Provisioning of Wireless Access Points), 191

LAG (link aggregation), 189

online resources for, 195

quality of service (QoS) settings, 190

WLAN security profiles, 189191

class-based weighted fair queueing (CBWFQ), 303

classes, IPv4 address, 6768

clients

DHCP (dynamic host configuration protocol), 282

DNS (Domain Name System), troubleshooting, 275278

ip domain-lookup command, 278

ip domain-name command, 278

ip name-server command, 278

ipconfig /all command, 275276

nslookup command, 278

ping command, 276277

IP (Internet Protocol) parameters for, 8081

NTP (Network Time Protocol), 263

cloaking, network, 111

cloud services

online resources for, 2930

overview of, 2627

virtualization and, 119

CloudFormation, 395

CNAME (domain name aliases), 273

collapsed core network designs, 19

collisions, 41, 43

colon (:), 91

commands, 98, 375

aaa new-model, 329

access-list 1, 252

access-list deny, 359

access-list permit, 359, 362

banner login # 335336

banner motd, 336

cdp enable, 165

cdp run, 165

channel-group, 154

channel-group 2 mode desirable, 155

channel-group 3 mode active, 156

crypto key generate rsa, 304, 334335

default-router, 281

dhcp excluded-address, 281

dns-server, 281

enable, 330

enable password, 331332

errdisable recovery, 372

exit, 329

hostname, 142, 304

ifconfig, 101

interface fa0/0 overload, 253254

interface range, 154

ip access-group, 360

ip access-list standard, 360

ip address dhcp, 282

ip arp inspection, 375

ip dhcp excluded-address, 281

ip dhcp pool, 281

ip dhcp snooping, 375

ip domain-lookup, 278

ip domain-name, 278, 304

ip domain-name lab.ajsnetworking.com, 334335

ip helper-address, 283

ip name-server, 278

ip nat inside, 251

ip nat inside source, 253254

ip nat inside source list 1 pool MYNATPOOL, 253

ip nat inside source static, 251, 254

ip nat outside, 251

ip nat pool MYNATPOOL, 253

ip ospf hello-interval, 229

ip route, 216218

ip ssh version 2, 304, 334335

ipconfig, 8081

ipconfig /all, 100101, 275276

ipv6 address, 95

ipv6 address autoconfig, 98

ipv6 enable, 97

ipv6 route, 216

ipv6 unicast-routing, 96, 98

lldp receive, 167

lldp run, 167

lldp transmit, 167

login local, 329

network, 226227, 281

no shutdown, 154

nslookup, 278

ntp master, 262263

ntp server, 263

option, 281

ping, 228, 251, 276277

router ospf 1, 227

router-id, 230

security passwords min-length 10, 330331

service password-encryption, 331332, 333

show access-list, 359, 361, 362

show cdp, 165

show cdp interface, 165

show cdp neighbors detail, 165

show controllers, 38

show etherchannel 1 summary, 154

show etherchannel 3 summary, 157

show etherchannel summary, 155

show interface, 41, 43

show interface gi0/2 switchport, 144

show interface gi1/0 switchport, 149

show interface trunk, 150

show ip dhcp binding, 282, 288

show ip dhcp conflict, 282

show ip interface, 361

show ip interface brief, 283, 288

show ip nat translation, 251, 254

show ip ospf neighbor, 227228, 230

show ip route, 204, 209, 217218, 228

show ipv6 interface, 96

show ipv6 interface brief, 97

show ipv6 route, 218

show lldp, 168

show lldp interface, 168

show lldp neighbors detail, 168

show ntp associations, 264

show ntp status, 264

show port-security interface, 374

show run | include nat, 252

show spanning-tree, 176179, 180

show vlan brief, 142, 143, 144

show vtp status, 141142

shutdown, 154

snmp-server source-interface traps loopback 1, 333

switchport access vlan 20, 143

switchport mode trunk, 149

switchport port-security, 371373

switchport voice vlan 50, 144

transport input, 335

transport input none, 304

transport input ssh, 304, 334335

username JOHNS privilege 15 secret 1L0v3C1sc0Systems, 329

configuration

ACLs (access control lists)

extended, 362

named, 360361

numbered, 358359

online resources for, 367

device access control, 325342

AAA (authentication, authorization, and accounting), 328330

local authentication, 328329

login banners, 335336

MOTD (message-of-the-day) banners, 336

online resources for, 341342

password security policy, 330332

physical security, 332

RADIUS (Remote Authentication Dial-In User Service), 330

source addressing, 333

SSH (Secure Shell), 334335

TACACS+, 330

Telnet, 333334

DHCP (dynamic host configuration protocol), 280282

DNS (Domain Name System) client connectivity, 275278

ip domain-lookup command, 278

ip domain-name command, 278

ip name-server command, 278

ipconfig /all command, 275276

nslookup command, 278

ping command, 276277

EtherChannel

Layer 2, 155157

Layer 3, 157158

static, 153154

interswitch connectivity, 148150

IPv4 (Internet Protocol version 4)

addresses, 7478

IP parameter verification, 8081

online resources for, 87

private addresses, 7778

static routing, 215216

subnet masks, 6869

subnetting, 6672

IPv6 (Internet Protocol version 6), 89107

address types, 9093

anycast, 93

examples of, 9596

global unicast, 9192

link-local unicast, 92

modified EUI-64, 92, 9697

multicast, 92

online resources for, 106107

SLAAC (stateless address autoconfiguration) of, 93, 9798

static routing, 215216

subnetting, 9192

unique local, 92

verification of, 9697, 100101

NAT (Network Address Translation)

dynamic, 252253

static, 250251

NTP (Network Time Protocol), 262263

OSPFv2 (open shortest path first version 2), 227, 229230

PAT (Port Address Translation), 253

port security, 371373

PortFast, 181

Spanning Tree Protocol

classic Spanning Tree Protocol, 178179

PortFast, 181

RPVST+ (Rapid Per VLAN Spanning Tree Plus), 179

syslog

default configuration, 296

example of, 299

SNMP security levels, 299

timestamps, 296

trunking, 148150

VLANs (virtual local-area networks), 140145

CDP (Cisco Discovery Protocol), 144

examples of, 142143

interfaces for, 143

voice VLANs, 143145

VTP (VLAN Trunking Protocol), 141142

WPA (Wi-Fi Protected Access), 385

configuration management, 411413

congestion avoidance tools, 303

congestion management tools, 303

connectivity, IP. See IP (Internet Protocol) connectivity

console logging, 296

containers, 120

Control and Provisioning of Wireless Access Points (CAPWAP), 191

controller-based networking, 396398

controllers

Cisco DNA Center, 1011

controller-based networking, 396398

wireless LAN controllers (WLCs), 1112

core layer, 1929

Counter Mode with Cipher Block Chaining Message Authentication Code Protocol (CCMP), 385

CRC (cyclic redundancy check), 43

CRUD operations, 409

crypto key generate rsa command, 304, 334335

cryptography, 319, 347

CSMA/CA (carrier-sense multiple access with collision avoidance), 5, 42

curly braces ({ }), 415

cut-through switching, 129

cyclic redundancy check (CRC), 43

D

DAI (dynamic ARP inspection)

configuration of, 375

online resources for, 381

Data and Pad field (Ethernet frames), 131132

data communications equipment (DCE), 37

data exfiltration, 316

Data Link layer (OSI model), 54

data terminal equipment (DTE), 37

data traffic, 302

Database Migration Service, 2622

DataSync, 2622

DCE (data communications equipment), 37

DDoS (distributed denial-of-service) attacks, 315

decimal numbers, converting binary numbers to, 67

default routes, 216

default-router command, 281

deferred frames, 43

DEI (drop eligible indicator), 149

delimiters, 335336

designated ports, 175

designated router (DR), 231

desirable setting (EtherChannel), 155

desktop virtualization, 121

Destination MAC field (Ethernet frames), 132

device access control, 325342

AAA (authentication, authorization, and accounting), 328330

local authentication, 328329

login banners, 335336

MOTD (message-of-the-day) banners, 336

online resources for, 341342

password security policy, 330332

physical security, 332

RADIUS (Remote Authentication Dial-In User Service), 330

source addressing, 333

SSH (Secure Shell), 334335

TACACS+, 330

Telnet, 333334

device hardening, 332

DHCP (dynamic host configuration protocol)

client configuration for, 282

configuration of, 280282

DHCP snooping, 374375, 381

online resources for, 293

relay agents, 283

server/client topology, 280

servers

configuration of, 280281

verification of, 282

troubleshooting, 285288

verification of, 282283

dhcp excluded-address command, 281

DiffServ (Differentiated Services), 301302

Digital Network Architecture (DNA) Center, 1011, 400401

directed broadcasts, 75

discovery protocols, 163171

CDP (Cisco Discovery Protocol), 164166

LLDP (Link Layer Discovery Protocol), 167168

online resources for, 171

distributed denial-of-service (DDoS) attack, 315

distribution layer, 1929

DMVPN (Dynamic Multipoint VPN), 22, 347

DNA (Digital Network Architecture) Center, 1011, 400401

DNS (Domain Name System), 271279

lookup operation, 272273

online resources for, 293

troubleshooting, 275278

ip domain-lookup command, 278

ip domain-name command, 278

ip name-server command, 278

ipconfig /all command, 275276

nslookup command, 278

ping command, 276277

dns-server command, 281

Docker, 120

domain name aliases (CNAME), 273

Domain Name System. See DNS (Domain Name System)

DR (designated router), 231

dribble conditions, 43

drop eligible indicator (DEI), 149

DTE (data terminal equipment), 37

dual band access points, 5

dual-homed topology, 22

duplex, 42

dynamic ARP inspection (DAI)

configuration of, 375

online resources for, 381

dynamic host configuration protocol. See DHCP (dynamic host configuration protocol)

Dynamic Multipoint VPN (DMVPN), 22, 347

dynamic NAT (Network Address Translation), 252254

configuration of, 252253

verification of, 254

dynamic port security, 371

E

Elasticsearch, 412413

enable command, 330

enable password command, 331332

encryption, 347, 384

endpoints, 56

errdisable recovery command, 372

EtherChannel, 152158

static

configuration of, 153154

verification of, 154155

topology of, 152153

Ethernet, 3436

cabling

Auto MDI-X, 35

fiber-optic media, 3536

standards for, 35

UTP (unshielded twisted pair), 35

frames, 42, 43

Layer 2

configuration with LACP, 156157

configuration with PAgP, 155156

Layer 3, 157158

online resources for, 49

PoE (Power over Ethernet), 3637

point-to-point links, 36

runts, 42

shared media, 36

switching, 125136

cut-through, 129

fragment-free, 129

frame flooding, 127128

frame format, 131132

frame switching, 127128

L2 switches, 45

L3 switches, 45

MAC (media access control) addresses in, 127

online resources for, 136

port LEDs for, 129

store-and-forward, 128129

switch layout, 127

exit command, 329

exit interfaces, 217

exploits, 316

extended ACLs (access control lists)

configuration of, 362

definition of, 358

F

fabric, 398

Fast Ethernet, 35

FCS (Frame Check Sequence) field, 42, 132

FHRPs (first hop redundancy protocols), 237243

fiber-optic media, 3536

FIFO (first-in, first-out) approach, 301

File Transfer Protocol (FTP), 305

files, zone, 273

firewalls, 78

first hop redundancy protocols. See FHRPs (first hop redundancy protocols)

first-in, first-out (FIFO) approach, 301

floating static routes, 218

flooding, frame, 127128

forwarding per-hop behavior (PHB), 301303

fragment-free switching, 129

Frame Check Sequence (FCS) field, 42, 132

frame flooding, 127128

frame rewrite procedure, 201

frame switching, 127128

frames

Ethernet, 42, 43

formats of, 131132

troubleshooting, 43

FTP (File Transfer Protocol), 305

full mesh topology, 22

full-duplex, 42

function virtualization, 121

G

Gateway Load Balancing Protocol (GLBP), 239240, 243

gateway of last resort, 206

Giant frames, 42

Gigabit Ethernet, 35

GLBP (Gateway Load Balancing Protocol), 239240, 243

global unicast addresses, 9192

H

half-duplex, 42

headers

Ethernet, 131

IPv6, 91

hexadecimal notation, 90

high availability, 237243

home offices. See SOHOs (small offices/home offices)

hop counts, 206

horizontal APIs (application programming interfaces), 398

host routes, 216

hostname command, 142, 304

HSRP (Hot Standby Router Protocol), 238239, 243

HTTP (Hypertext Transfer Protocol), 408

hub-and-spoke topology, 22

hybrid cloud services, 27

Hypertext Transfer Protocol (HTTP), 408

hypervisors, 119

I

IaaS (Infrastructure as a Service), 26

IANA (Internet Assigned Numbers Authority), 92

Identity Services Engine (ISE), 346

IEEE (Institute of Electrical and Electronics Engineers)

802.11 wireless standards, 110

802.3 Ethernet standards, 35

PoE (Power over Ethernet) standards, 3637

ifconfig command, 101

ignored frames, 43

Infrastructure as a Service (IaaS), 26

injection, SQL, 316

input drops, 43

input errors, 43

inside source NAT (Network Address Translation), 247259

configuration of, 250251

motivations for, 250

one-way, 250

static, 250252

topology of, 250

verification of, 251252

Institute of Electrical and Electronics Engineers. See IEEE (Institute of Electrical and Electronics Engineers)

Integrated Services (IntServ), 301302

interface fa0/0 overload command, 253254

interface range command, 154

interfaces

exit, 217

outgoing, 217

resets, 43

for VLANs (virtual local-area networks), 143

internal networks, 344

Internet Assigned Numbers Authority (IANA), 92

Internet of Things (IoT), 56

Internet Protocol. See IP (Internet Protocol) connectivity; specific services

interswitch connectivity, 148150

Inter-Switch Link (ISL), 148

intrusion prevention systems (IPSs), 8, 319

IntServ (Integrated Services), 301302

IoT (Internet of Things), 56

IP (Internet Protocol) connectivity

FHRPs (first hop redundancy protocols), 237243

IPv4 addresses, 6587

broadcasts, 7475

classes of, 6768

IP parameter verification, 8081

multicasts, 7475

private, 7778

subnet masks, 6869

subnetting, 6672

unicast, 7475

IPv4/IPv6 static routing, 215223

configuration of, 215216

floating static routes, 218

troubleshooting, 218

verification of, 217218

IPv6 configuration, 89107

address types, 9093

anycast, 93

examples of, 9596

global unicast, 9192

link-local unicast, 92

modified EUI-64, 92, 9697

multicast, 92

online resources for, 106107

SLAAC (stateless address autoconfiguration) of, 93, 9798

subnetting, 9192

unique local, 92

verification of, 9697, 100101

online resources for, 87

OSPFv2 (open shortest path first version 2), 225235

BDR (backup designated router), 231

configuration of, 227, 229230

definition of, 226

DR (designated router), 231

online resources for, 235

states, 230231

topology of, 226

troubleshooting, 231

verification of, 227228

routing, 199213

AD (administrative distance), 206209

frame rewrite procedure in, 201

online resources for, 213

packet-handling process in, 200201

routing tables, 203209

Video over IP, 302

Voice over IP, 302

IP (Internet Protocol) services. See specific services

ip access-group command, 360

ip access-list standard command, 360

ip address dhcp command, 282

ip arp inspection command, 375

ip arp inspection trust command, 375

ip dhcp excluded-address command, 281

ip dhcp pool command, 281

ip dhcp snooping command, 375

ip domain-lookup command, 278

ip domain-name command, 278, 304

ip domain-name lab.ajsnetworking.com command, 334335

ip helper-address command, 283

ip name-server command, 278

ip nat inside command, 251

ip nat inside source command, 253254

ip nat inside source list 1 pool MYNATPOOL commands, 253

ip nat inside source static command, 251, 254

ip nat outside command, 251

ip nat pool MYNATPOOL command, 253

ip ospf dead-interval command, 229

ip ospf hello-interval command, 229

ip route command, 216218

ip ssh version 2 command, 304, 334335

ipconfig /all command, 100101, 275276

ipconfig command, 8081

IPsec, 347

IPSs (intrusion prevention systems), 8, 319

IPv4 (Internet Protocol version 4)

addresses

broadcasts, 7475

classes of, 6768

definition of, 6587

IP parameter verification, 8081

multicasts, 7475

online resources for, 87

private, 7778

subnet masks, 6869

subnetting, 6672

unicast, 7475

static routing, 215223

configuration of, 215216

floating static routes, 218

troubleshooting, 218

verification of, 217218

IPv6 (Internet Protocol version 6)

configuration, 89107

address types, 89107

anycast, 93

examples of, 9596

global unicast, 9192

link-local unicast, 92

modified EUI-64, 92, 9697

multicast, 92

online resources for, 106107

SLAAC (stateless address autoconfiguration) of, 93, 9798

subnetting, 9192

unique local, 92

verification of, 9697, 100101

static routing, 215223

configuration of, 215216

floating static routes, 218

troubleshooting, 218

verification of, 217218

ipv6 address autoconfig command, 98

ipv6 address command, 95

ipv6 enable command, 97

ipv6 route command, 216

ipv6 unicast-routing command, 96, 98

ISE (Identity Services Engine), 346

ISL (Inter-Switch Link), 148

J

JSON (JavaScript Object Notation)

benefits of, 414

definition of, 414

JSON-encoded data, 414415

online resources for, 419

Jumbo frames, 42

K

Key Reinstallation Attack (KRACK), 385

keys, 347

keywords, 254

msec, 296

privilege, 330

source-interface, 333

KRACK (Key Reinstallation Attack), 385

L

L2 switches, 45

L3 switches, 45

LACP (Link Aggregation Control Protocol), Layer 2 EtherChannel configuration with, 156157

LAG (link aggregation), 189

late collisions, 43

Layer 2 discovery protocols, 163171

CDP (Cisco Discovery Protocol), 164166

LLDP (Link Layer Discovery Protocol), 167168

online resources for, 171

Layer 2 EtherChannel configuration

with LACP, 156157

with PAgP, 155156

Layer 2 security, 369381

DAI (dynamic ARP inspection)

configuration of, 375

online resources for, 381

DHCP snooping, 374375

online resources for, 380381

port security

configuration of, 371373

dynamic, 371

online resources for, 381

static, 372373

violation actions, 372

sticky MAC address learning, 373374

Layer 3 EtherChannel, 157158

layers

OSI (Open Systems Interconnection) model, 5355

TCP/IP (Transmission Control Protocol/Internet Protocol) model, 53

LDAP (Lightweight Directory Access Protocol), 346

learning MAC (media access control) addresses, 127

Length/Type field (Ethernet frames), 132

LFI (link fragmentation and interleaving), 303

Lightweight Access Point Protocol (LWAPP), 191

Lightweight Directory Access Protocol (LDAP), 346

lightweight mode, 191

Link Aggregation Control Protocol (LACP), Layer 2 EtherChannel configuration with, 156157

link aggregation (LAG), 189

link fragmentation and interleaving (LFI), 303

Link Layer Discovery Protocol (LLDP), 167168

link-local unicast addresses, 92

links, point-to-point, 36

Linux

Ansible on, 411412

Chef on, 412413

IP (Internet Protocol) parameters on, 8081

LLDP (Link Layer Discovery Protocol), 167168

lldp receive command, 167

lldp run command, 167

lldp transmit command, 167

LLQ (low-latency queueing), 303

local authentication, 328329

local mode, 191

logging, 296299

buffer, 298

configuration of

default configuration, 296

example of, 299

SNMP security levels, 299

timestamps, 296

console, 296

message fields, 298

monitor, 297

online resources for, 310

severity levels, 298

login banners, 335336

login local command, 329

lookup operation, DNS (Domain Name System), 272273

lost carrier errors, 44

low-latency queueing (LLQ), 303

LWAPP (Lightweight Access Point Protocol), 191

M

MAC (media access control) addresses

aging, 127

learning, 127

MAC address tables, 128

maximum, 372

sticky MAC address learning, 373374

Mac OS systems, IP (Internet Protocol) parameters on, 8081

machine learning (ML), 8, 401

malware, 314

man-in-the-middle attacks, 316

Martian packets, 77

masters (NTP), 262263

maximum MAC (media access control) addresses, 372

message-of-the-day (MOTD) banners, 336

Metro Ethernet, 22

mGRE (Multipoint Generic Routing Encapsulation), 347

mitigation techniques, 318319

ML (machine learning), 8, 401

Mobility AnyConnect, 345

models

OSI (Open Systems Interconnection), 5256

TCP/IP (Transmission Control Protocol/Internet Protocol), 5256

modes, access point, 191192

modified EUI-64 addresses, 92, 9697

monitor logging, 297

MOTD (message-of-the-day) banners, 336

MPLS (Multiprotocol Label Switching), 22

msec keyword, 296

multicast, 7475, 92

multimode fiber, 3536

Multipoint Generic Routing Encapsulation (mGRE), 347

Multiprotocol Label Switching (MPLS), 22

MX (mail exchangers), 273

N

NACLs (network ACLs), 353

name servers (NS), 273

named ACLs (access control lists), 362

NAT (Network Address Translation), 77, 247259

bidirectional, 250

configuration of, 250251

dynamic, 252254

configuration of, 252253

verification of, 254

motivations for, 250

one-way, 250

online resources for, 259

overloading, 253

PAT (Port Address Translation), 253

pools, 253

static, 250252

topology of, 250

troubleshooting, 254

verification of, 251252

ND (Neighbor Discovery), 98

neighbor formation. See OSPFv2 (open shortest path first version 2)

network access

Layer 2 discovery protocols, 163171

CDP (Cisco Discovery Protocol), 164166

LLDP (Link Layer Discovery Protocol), 167168

online resources for, 171

wireless. See wireless networks

network ACLs (NACLs), 353

Network Address Translation. See NAT (Network Address Translation)

network cloaking, 111

network command, 226227, 281

network components, 316

access points, 5

controllers

Cisco DNA Center, 1011

wireless LAN controllers (WLCs), 1112

endpoints, 56

firewalls, 78

L2 switches, 45

L3 switches, 45

servers, 6

Network layer (OSI model), 54

network management, automation in, 393405

benefits of, 394395

Cisco DNA (Digital Network Architecture) Center, 400401

controller-based networking, 396398

online resources for, 405

network masks, 204

network models

OSI (Open Systems Interconnection), 5256

TCP/IP (Transmission Control Protocol/Internet Protocol), 5256

network routes, 216

network topology, 1730

cloud services, 2627

DHCP (dynamic host configuration protocol), 280

EtherChannel, 152153

NAT (Network Address Translation), 250

online resources for, 2930

OSPFv2 (open shortest path first version 2), 226

point-to-point, 22

on-premises resources, 26

SOHOs (small offices/home offices), 22

Spanning Tree Protocol, 176

three-tier architecture, 1819

two-tier architecture, 1819

two-tier spine-leaf, 1819

WANs (wide-area networks), 2122

network virtualization, 120

next hop IP addresses, 204205

Next Hop Resolution Protocol (NHRP), 347

next-generation firewalls (NGFW), 78

next-generation SDN (software-defined networking), 397

NGFW (next-generation firewalls), 78

NHRP (Next Hop Resolution Protocol), 347

No buffer condition, 43

no carrier errors, 43

no shutdown command, 154

noAuthNoPriv level, 299

non-broadcast networks, 231

northbound APIs (application programming interfaces), 397

NS (name servers), 273

nslookup command, 278

NTP (Network Time Protocol), 261269

benefits of, 262

configuration of, 262263

online resources for, 269

ports for, 262

stratum value in, 262

verification of, 264

ntp master command, 262263

ntp server command, 263

numbered ACLs (access control lists)

configuration of, 358359

verification of, 358359

O

objects, JSON (JavaScript Object Notation), 415

one-way NAT (Network Address Translation), 250

on-premises resources, 26

Open SDN Controller, 397

open shortest path first. See OSPFv2 (open shortest path first version 2)

Open Systems Interconnection. See OSI (Open Systems Interconnection) model

OpenFlow, 397

option command, 281

OSI (Open Systems Interconnection) model, 5256

Layer 2 security, 369381

DAI (dynamic ARP inspection), 375

DHCP snooping, 374375

online resources for, 380381

port security, 371373

sticky MAC address learning, 373374

layers of, 5355

online resources for, 64

PDUs (protocol data units) in, 55

protocols in, 5556

OSPFv2 (open shortest path first version 2), 225235

BDR (backup designated router), 231

configuration of, 227, 229230

definition of, 226

DR (designated router), 231

floating static routes for, 218

online resources for, 235

states, 230231

topology of, 226

troubleshooting, 231

verification of, 227228

outgoing interfaces, 217

output buffer failures, 43

output buffers swapped out, 43

output drops, 43

output hang, 43

overlays, 398

overload keyword, 254

overloading NAT (Network Address Translation), 253

overruns, 43

P

PaaS (Platform as a Service), 26

Packet Tracer, 264

packet-handling process, 200201

PAgP (Port Aggregation Protocol), 155156

parameters, IP (Internet Protocol)

IPv6, 100101

verification of, 8081

password security policy, 330332

PAT (Port Address Translation), 253

PCP (priority code point), 149

PDH (plesiochronous digital hierarchy), 22

PDUs (protocol data units), 55

Per VLAN Spanning Tree Plus (PVST+), 174176

PHB (forwarding per-hop behavior), 301303

phishing, 315

physical interfaces, 3349. See also cabling

online resources for, 49

troubleshooting

potential errors and problems, 4044

show interface command, 41, 43

Physical layer (OSI model), 54

ping command, 228, 251, 276277

Platform as a Service (PaaS), 26

plesiochronous digital hierarchy (PDH), 22

PMF (Protected Management Frames), 385

PoE (Power over Ethernet), 3637

pointers for reverse DNS lookups (PTR), 273

point-to-multipoint networks, 231

point-to-multipoint non-broadcast networks, 231

point-to-point links, 36

point-to-point networks, 22, 231

Point-to-Point Protocol over Ethernet (PPPoE), 22

policies

password security, 330332

security, 319

policing tools, 303, 310

pools, NAT (Network Address Translation), 253

Port Address Translation (PAT), 253

Port Aggregation Protocol (PAgP), 155156

PortFast, 181

ports

NTP (Network Time Protocol), 262

port LEDs, 129

port numbers, 59

PortFast, 181

security

configuration of, 371373

dynamic, 371

online resources for, 381

static, 372373

violation actions, 372

Spanning Tree Protocol

classic Spanning Tree Protocol, 175

RPVST+ (Rapid Per VLAN Spanning Tree Plus), 181

Power over Ethernet (PoE), 3637

PPPoE (Point-to-Point Protocol over Ethernet), 22

Preamble field (Ethernet frames), 131

prefix notation, 91, 93, 204

Presentation layer (OSI model), 55

priority code point (PCP), 149

priority values, Spanning Tree Protocol, 178179

private cloud services, 26

private IPv4 addresses, 7778

privilege keyword, 330

programmability, 407419

configuration control and management, 411413

JSON-encoded data, 414415

online resources for, 419

RESTful APIs, 408409

Protected Management Frames (PMF), 385

protocol data units (PDUs), 55

protocols. See specific protocols

PTR (pointers for reverse), 273

public cloud services, 26

public key cryptography, 347

Puppet, 412

PVST+ (Per VLAN Spanning Tree Plus), 174176

Python, 412

Q

QoS (quality of service)

BE (best effort), 301

DiffServ (Differentiated Services), 301302

forwarding per-hop behavior tools, 302

IntServ (Integrated Services), 301302

marking traffic for, 302

online resources for, 310

PHB (forwarding per-hop behavior), 301303

settings for, 190

R

radio frequencies (RF), 110

RADIUS (Remote Authentication Dial-In User Service), 319, 330, 346

ransomware, 316

Rapid Per VLAN Spanning Tree Plus (RPVST+), 179181

Rapid Spanning Tree Protocol (RSTP), 179

REAP (Remote Edge Access Point), 191

redundancy. See FHRPs (first hop redundancy protocols)

relay agents (DHCP), 283

remote access VPNs (virtual private networks), 345

Remote Authentication Dial-In User Service (RADIUS), 319, 330, 346

Remote Edge Access Point (REAP), 191

representational state transfer (REST), 398, 408409

resets, interface, 43

Resource Reservation Protocol (RSVP), 301302

REST (representational state transfer), 398, 408409

RF (radio frequencies), 110

RFC 1918, 7778

Rogue Detector mode, 192

root bridges, 175

root cost, 175

rootkits, 315

router ospf 1 command, 227

router-id command, 230

routing, 199213

frame rewrite procedure in, 201

IPv4/IPv6 static routing, 215223

configuration of, 215216

floating static routes, 218

troubleshooting, 218

verification of, 217218

packet-handling process in, 200201

routing tables

administrative distance (AD) values in, 206209

components of, 203206

online resources for, 213

RPVST+ (Rapid Per VLAN Spanning Tree Plus), 179181

RSTP (Rapid Spanning Tree Protocol), 179

RSVP (Resource Reservation Protocol), 301302

Ruby, 412

runts, 42

S

SaaS (Software as a Service), 27

sandboxes, 120

SDH (synchronous digital hierarchy), 22

SDN (software-defined networking), 396398

SE-Connect mode, 191

Secure Shell (SSH), 304305, 319, 334335

Secure Sockets Layer (SSL), 344

secure tunnels, 344

security, 313323

ACLs (access control lists), 353367

ACEs (access control entries), 358

advantages of, 353

extended, 358, 362

NACLs (network ACLs), 353

named, 360361

numbered, 358359

standard, 358360

CCMP (Counter Cipher Mode with Block Chaining Message Authentication Code Protocol), 385

Cisco DNA Center, 401

cryptography, 319, 347

DAI (dynamic ARP inspection)

configuration of, 375

online resources for, 381

device access control, 325342

AAA (authentication, authorization, and accounting), 328330

local authentication, 328329

login banners, 335336

MOTD (message-of-the-day) banners, 336

online resources for, 341342

password security policy, 330332

physical security, 332

RADIUS (Remote Authentication Dial-In User Service), 330

source addressing, 333

SSH (Secure Shell), 334335

TACACS+, 330

Telnet, 333334

DHCP snooping, 374375

encryption, 347, 384

exploits, 316

mitigation techniques for, 318319

online resources for, 323, 380381

policies for, 319

port

configuration of, 371373

dynamic, 371

online resources for, 381

static, 372373

violation actions, 372

program elements, 318319

SNMP (Simple Network Management Protocol), 299

SSH (Secure Shell), 304305

SSL (Secure Sockets Layer), 344

sticky MAC address learning, 373374

threats, 314316

TKIP (Temporal Key Integrity Protocol), 384

TLS (Transport Layer Security), 344

vulnerabilities, 316

WLAN security profiles, 189191

WPA (Wi-Fi Protected Access), 383390

zero-day attacks, 317

security passwords min-length 10 command, 330331

serial connections, 3738

servers

definition of, 6

DHCP (dynamic host configuration protocol)

configuration of, 280281

verification of, 282

virtualization, 118120

service password-encryption command, 331332, 333

service set identifiers (SSIDs), 111

services. See specific services

Session layer (OSI model), 55

severity levels, syslog, 298

SFD (Start Frame Delimiter) field, 131

shaping tools, 302, 310

shared media, 36

show access-list command, 359, 361, 362

show cdp command, 165

show cdp interface command, 165

show cdp neighbors detail command, 165

show controllers command, 38

show etherchannel 1 summary command, 154

show etherchannel 3 summary, 157

show etherchannel summary command, 155

show interface command, 41, 43

show interface gi0/2 switchport commands, 144

show interface gi1/0 switchport command, 149

show interface trunk command, 150

show ip dhcp binding command, 282, 288

show ip dhcp conflict command, 282

show ip interface brief command, 283, 288

show ip interface command, 361

show ip nat translation command, 251, 254

show ip ospf neighbor command, 227228, 230

show ip route command, 204, 209, 217218, 228

show ipv6 interface brief command, 97

show ipv6 interface command, 96

show ipv6 route command, 218

show lldp command, 168

show lldp interface command, 168

show lldp neighbors detail command, 168

show ntp associations command, 264

show ntp status command, 264

show port-security interface command, 374

show run | include nat command, 252

show spanning-tree command, 176179, 180

show vlan brief command, 142, 143, 144

show vtp status command, 141142

shutdown command, 154

Simple Network Management Protocol (SNMP), 299, 310

single-area OSPFv2 (open shortest path first version 2), 225235

configuration of, 227, 229230

definition of, 226

topology of, 226

troubleshooting, 231

verification of, 227228

single-homed topology, 22

single-mode fiber, 3536

site-to-site VPNs (virtual private networks), 345

SLAAC (stateless address autoconfiguration), 93, 9798

small offices/home offices (SOHOs), 22

SMTP mail exchangers (MX), 273

Sniffer mode, 192

SNMP (Simple Network Management Protocol), 299, 310

snmp-server source-interface traps loopback 1 command, 333

SNMPv3, 319

snooping, DHCP, 374375

configuration of, 374375

online resources for, 381

SOA (start of authority), 273

Software as a Service (SaaS), 27

software-defined networking (SDN), 396398

SOHOs (small offices/home offices), 22

SONET, 22

source addressing, 333

Source MAC field (Ethernet frames), 132

Sourcefire, 8

source-interface keyword, 333

southbound APIs (application programming interfaces), 397

Spanning Tree Protocol, 173186

bridges

BID (bridge ID), 175

definition of, 175

root, 175

configuration of, 178179

designated ports, 175

online resources for, 185186

PVST+ (Per VLAN Spanning Tree Plus), 174176

RPVST+ (Rapid Per VLAN Spanning Tree Plus), 179181

topology of, 176

verification of, 176179

speed mismatches, 42

spyware, 315

SQL injection attacks, 316

SSH (Secure Shell), 304305, 319, 334335

SSIDs (service set identifiers), 111

SSL (Secure Sockets Layer), 344

standard ACLs (access control lists), 358

standby routers, 239

Start Frame Delimiter (SFD) field, 131

start of authority (SOA), 273

stateless address autoconfiguration (SLAAC), 93, 9798

states, OSPFv2 (open shortest path first version 2), 230231

static EtherChannel

configuration of, 153154

verification of, 154155

static NAT (Network Address Translation), 250252

static port security, 372373

static routing, 215223

configuration of, 215216

floating static routes, 218

troubleshooting, 218

verification of, 217218

sticky MAC address learning, 373374

storage virtualization, 120

store-and-forward switching, 128129

stratum value, 262

subnet masks, 6869

subnetting

IPv4, 6672

IPv6, 9192

switching, 125136. See also bridges

configuration for RPVST+, 180

cut-through, 129

Ethernet frame format, 131132

fragment-free, 129

frame flooding and switching, 128

interswitch connectivity, 148150

L2 switches, 45

L3 switches, 45

MAC (media access control) addresses in, 127128

online resources for, 136

port LEDs for, 129

store-and-forward, 128129

switch layout, 127

troubleshooting, 4044

VLAN creation on, 142

switchport access vlan 20 command, 143

switchport mode trunk command, 149

switchport port-security command, 371373

switchport voice vlan 50 command, 144

symmetric-key algorithms, 347

synchronous digital hierarchy (SONET/SDH), 22

syslog, 296299

buffer logging, 298

configuration of

default configuration, 296

example of, 299

SNMP security levels, 299

timestamps, 296

console logging, 296

message fields, 298

monitor logging, 297

online resources for, 310

serverity levels, 298

system logging. See syslog

T

tables

MAC address, 128

routing

administrative distance (AD) values in, 206209

components of, 203206

online resources for, 213

TACACS+, 319, 330

tag control information (TCI), 149

tag protocol identifier (TPID), 149

tagged ports. See trunking

targeted broadcasts, 75

TCI (tag control information), 149

TCP (Transmission Control Protocol), 5759, 64

TCP/IP (Transmission Control Protocol/Internet Protocol) model, 5256

Telnet, 304, 333334

Temporal Key Integrity Protocol (TKIP), 384

Temporary IPv6 Address value, 101

Terminal Access Controller Access-Control System (TACACS+), 319

TFTP (Trivial File Transfer Protocol), 305

threats, types of, 314316

three-tier architecture, 1819

throttles, 43

time, NTP (Network Time Protocol), 261269

benefits of, 262

configuration of, 262263

online resources for, 269

stratum value in, 262

verification of, 264

timestamps

configuration of, 296

syslog, 298

TKIP (Temporal Key Integrity Protocol), 384

TLS (Transport Layer Security), 344

topologies. See network topology

TPID (tag protocol identifier), 149

trailers, Ethernet frame, 131

Transmission Control Protocol (TCP), 5759, 64

Transmission Control Protocol/Internet Protocol (TCP/IP) model, 5256

transport input command, 335

transport input none command, 304

transport input ssh command, 304, 334335

Transport layer (OSI model), 54

Transport Layer Security (TLS), 344

Trivial File Transfer Protocol (TFTP), 305

Trojan horses, 315

troubleshooting

DHCP (dynamic host configuration protocol), 285288

DNS (Domain Name System), 275278

ip domain-lookup command, 278

ip domain-name command, 278

ip name-server command, 278

ipconfig /all command, 275276

nslookup command, 278

ping command, 276277

interface and cabling issues, 43

potential errors and problems, 4044

show interface command, 41, 43

IPv4/IPv6 static routing, 218

NAT (Network Address Translation), 254

OSPFv2 (open shortest path first version 2), 231

trunking

configuration of, 148150

definition of, 141

two-tier spine-leaf architecture, 1819

Type 1 hypervisors, 119

Type 2 hypervisors, 119

U

UDP (User Datagram Protocol), 5759, 64

underlays, 398

underruns, 43

unicast, 7475, 9192

unidirectional NAT (Network Address Translation), 250

unique local addresses, 92

UNIX, Puppet on, 412

unknown unicast flooding, 127128

unshielded twisted pair (UTP), 35

User Datagram Protocol (UDP), 5759, 64

username JOHNS privilege 15 secret 1L0v3C1sc0Systems command, 329

UTP (unshielded twisted pair), 35

V

variable-length subnet masking, 71

verification

of ACLs (access control lists), 358359

of DHCP (dynamic host configuration protocol), 282283

of EtherChannel, 154155

of interfaces for VLANs, 143

of IP parameters, 8081

of IPv4/IPv6 static routing, 217218

of IPv6 configuration, 9697, 100101

of NAT (Network Address Translation)

dynamic, 254

static NAT, 251252

of NTP (Network Time Protocol), 264

of OSPFv2 (open shortest path first version 2), 227228

of port security, 371373

of Spanning Tree Protocol, 176179, 180

of trunking, 149150

of VLANs (virtual local-area networks), 142143

VID (VLAN identifier), 149

Video over IP, 302

violation actions, port security, 372

Violation Mode setting (port security), 372

virtual local-area networks (VLANs), 118

virtual machines (VMs), 119

virtual private networks. See VPNs (virtual private networks)

Virtual Router Redundancy Protocol (VRRP), 238240

virtualization

application, 120

desktop, 121

function, 121

network, 120

online resources for, 124

server, 118120

storage, 120

VLANs (virtual local-area networks), 118

VMs (virtual machines), 119

VPNs (virtual private networks), 343351

online resources for, 351

services offered by, 346347

types of, 344345

viruses, definition of, 314

VLAN identifier (VID), 149

VLANs (virtual local-area networks), 118

configuration of, 140145

CDP (Cisco Discovery Protocol), 144

examples of, 142143

interfaces for, 143

voice VLANs, 143145

VTP (VLAN Trunking Protocol), 141142

EtherChannel, 152158

Layer 2, 155157

Layer 3, 157158

static, 153155

topology of, 152153

interswitch connectivity, 148150

online resources for, 162

verification of, 142143

VTP (VLAN Trunking Protocol), 141142

VMs (virtual machines), 119

Voice over IP, 302

voice VLANs (virtual local-area networks), 143145

VPNs (virtual private networks), 343351

online resources for, 351

services offered by, 346347

types of, 344345

VRRP (Virtual Router Redundancy Protocol), 238240

VTP (VLAN Trunking Protocol), 141142

vulnerabilities, 316

W

WANs (wide-area networks), 2122

weighted random early detection (WRED), 303

wide-area networks (WANs), 2122

Wi-Fi. See wireless networks

Wi-Fi Protected Access. See WPA (Wi-Fi Protected Access)

Windows systems

Chef on, 412413

IP (Internet Protocol) parameters on, 8081

Puppet on, 412

wireless LAN controllers. See WLCs (wireless LAN controllers)

wireless networks, 109115

bands in, 110

channels in, 110

Cisco wireless architectures, 187195

AP (access point) modes, 191192

CAPWAP (Control and Provisioning of Wireless Access Points), 191

LAG (link aggregation), 189

online resources for, 195

quality of service (QoS) settings, 190

WLAN security profiles, 189191

IEEE 802.11 standards for, 111

network cloaking, 111

online resources for, 115

SSIDs (service set identifiers), 111

WPA (Wi-Fi Protected Access), 383390

wireless security protocols, 383390

WLCs (wireless LAN controllers), 1112, 187195

AP (access point) modes, 191192

CAPWAP (Control and Provisioning of Wireless Access Points), 191

LAG (link aggregation), 189

online resources for, 195

quality of service (QoS) settings, 190

WLAN security profiles, 189191

worm attacks, 315

WPA (Wi-Fi Protected Access), 383390

WPA2, 384386

WPA3, 385

WRED (weighted random early detection), 303

X-Y-Z

XaaS (X as a Service), 2627

Xorg, 121

zero-day attacks, 317

zone files, 273

..................Content has been hidden....................

You can't read the all page of ebook, please click here login for view all page.
Reset
3.133.146.237