Cisco CCNA (200-301) flashcards
226 free flashcards. Tap a card to flip it.
AIOps / ML-driven Network Analytics
Flip cardAIOps applies machine learning to network telemetry data to automatically establish behavioral baselines and proactively detect anomalies, often before they impact users, unlike static rule-based alerting.
- Learns normal baseline from historical data
- Detects anomalies/deviations automatically
- Used in platforms like Cisco DNA Center Assurance
- Proactive vs reactive traditional monitoring
Memory trick: AIOps learns the normal, then shouts when things go abnormal.
Northbound vs Southbound APIs
Flip cardNorthbound APIs let applications interact with an SDN controller (typically REST), while southbound APIs let the controller manage network devices (e.g., NETCONF, OpenFlow).
- Northbound = controller-to-application (up)
- Southbound = controller-to-device (down)
- REST/RESTCONF often used northbound; NETCONF/OpenFlow southbound
Memory trick: North goes up to apps, South goes down to switches.
TCP vs UDP
Flip cardTCP is a reliable, connection-oriented transport protocol; UDP is a fast, connectionless protocol with no delivery guarantees.
- TCP uses SYN/SYN-ACK/ACK handshake
- UDP has lower overhead, used for streaming/DNS/DHCP
- TCP provides flow control via windowing; UDP does not
Memory trick: TCP is a Careful Courier; UDP is an Unreliable Dash.
DNS Zone Transfer
Flip cardThe process of copying DNS zone data from a primary to a secondary name server, which requires TCP because of its reliability guarantees.
- Standard DNS queries: UDP/53 (TCP/53 for large responses)
- Zone transfers (AXFR/IXFR): TCP/53 always
- TCP is chosen for zone transfers due to reliable delivery of larger datasets
Memory trick: Zone transfers need a Ticket (TCP) for guaranteed delivery.
Administrative Distance
Flip cardA value from 0-255 that ranks the trustworthiness of a routing information source; lower is more preferred.
- Connected=0, Static=1, EIGRP=90, OSPF=110, RIP=120
- Only used when multiple sources have a route to the SAME prefix length
- Longest prefix match is checked before AD
Memory trick: Lower AD number = higher trust, like golf scoring.
Auto-MDIX
Flip cardAuto-MDIX (Automatic Medium-Dependent Interface Crossover) lets a switch port automatically detect and correct for cable type (straight-through vs crossover).
- Eliminates need to know if a crossover cable is required
- Standard on most modern Gigabit Ethernet switches
- Works alongside auto-negotiation for speed/duplex
Memory trick: Auto-MDIX: the switch flips the wires so you don't have to.
Cisco IOS Interface Summary
Flip cardThe 'show ip interface brief' command in Cisco IOS provides a quick summary of the IP address and status for all interfaces on a router or Layer 3 switch.
- Displays interface name, IP address, OK? (method), status, and protocol.
- Useful for quickly checking interface operational state and IP configuration.
- Does not show detailed interface statistics or errors.
Memory trick: Briefly IP your Interface, and see its Status.
802.1Q Native VLAN
Flip cardIn 802.1Q trunking, the native VLAN is the VLAN whose traffic traverses the trunk link untagged. All other VLANs on the trunk are tagged.
- Only one native VLAN can be configured per trunk port.
- Native VLANs must match on both ends of a trunk to avoid mismatches and potential security issues.
- Untagged frames received on a trunk port are assumed to belong to the native VLAN.
Memory trick: Native VLAN: No Tag, Just Go!
Cisco Console Cable (Rollover)
Flip cardA Cisco console cable, commonly called a rollover cable, is used to connect a computer's serial port (or a USB-to-serial adapter) to the RJ-45 console port of a Cisco network device for out-of-band management and configuration.
- Used for initial configuration and troubleshooting of Cisco devices.
- Has an RJ-45 connector on one end and typically a DB-9 or USB on the other.
- The pinout is 'rolled over' from one end to the other.
- Provides command-line interface (CLI) access.
Memory trick: Data is straight or crossed, Console is Rolled, Fiber is Light.
Virtual Local Area Network (VLAN)
Flip cardA logical grouping of network devices that allows a single physical switch or a network of switches to be segmented into multiple broadcast domains, isolating traffic at Layer 2.
- Each VLAN is its own broadcast domain.
- Devices in different VLANs cannot communicate without a Layer 3 device (router/L3 switch).
- VLANs improve security, network performance, and administrative flexibility.
- Trunk links are used to carry traffic for multiple VLANs between switches or to routers.
Memory trick: VLANs Slice Switches, Subnets Slice IPs, Trunks Carry All, LAGs Bundle Links.
Cisco IOS Configuration Modes
Flip cardCisco IOS devices use a hierarchical command-line interface (CLI) with different operational modes, each allowing specific sets of commands.
- User EXEC mode (Router>): Limited monitoring commands.
- Privileged EXEC mode (Router#): Full monitoring, debugging, and file management commands.
- Global Configuration mode (Router(config)#): For configuring global parameters like static routes, hostnames, etc.
Memory trick: User finds the Key to unlock Global settings, then specific Interface controls.
Integrated Services Router (ISR)
Flip cardAn Integrated Services Router (ISR) is a multi-function network device that combines routing, switching, wireless access, and security services into a single platform for small to medium-sized networks.
- Consolidates multiple network functions into one device.
- Reduces complexity and cost for smaller deployments.
- Offers routing, switching, Wi-Fi, and security features.
Memory trick: An ISR is like a Swiss Army knife: all the services in one router.
STP Designated Port Election
Flip cardIn Spanning Tree Protocol (STP), the designated port for a segment is the port on the designated bridge that sends BPDUs for that segment. The designated bridge is chosen based on a series of tie-breakers.
- Lowest Root Bridge ID wins.
- Lowest Root Path Cost to Root Bridge wins.
- Lowest Designated Bridge ID wins (for a segment).
- Lowest Port ID (port priority then port number) wins if all above are equal.
Memory trick: R.P.D.P. - Root, Path, Designated, Port (ID)
WLC GUI WLAN Configuration
Flip cardThe 'WLANs' section in the Cisco WLC GUI is where administrators define and configure Wireless LANs (SSIDs), including their security parameters, quality of service, and VLAN assignments.
- Each WLAN corresponds to an SSID.
- Security settings (e.g., WPA2-Enterprise) are configured here.
- VLANs are mapped to WLANs via dynamic interfaces.
Memory trick: C.W.S.A. - Controller, WLANs, Security, Administration
Restore Config from TFTP
Flip cardTo restore a configuration file from a TFTP server to the running configuration on a Cisco device, use the 'copy tftp://<server-ip>/<filename> running-config' command.
- TFTP is a simple file transfer protocol.
- The 'copy' command has a consistent source-destination syntax.
- Running-config is the active configuration in RAM.
- Startup-config is the saved configuration in NVRAM.
Memory trick: Copy TFTP to Running, make it active!
CDP Error Messages
Flip cardCisco Discovery Protocol (CDP) can generate syslog messages to alert administrators of certain inconsistencies or mismatches with directly connected Cisco devices.
- CDP operates at Layer 2 and discovers directly connected Cisco devices.
- It reports information like device ID, platform, capabilities, and interface information.
- Specific messages like `NATIVE_VLAN_MISMATCH` help in troubleshooting trunking issues.
Memory trick: CDP: See Discrepancies, Pinpoint Problems.
Cisco IOS DNS Server Verification
Flip cardTo verify which DNS servers a Cisco router is configured to use for name resolution, you can inspect the running configuration for specific commands.
- DNS servers are configured using `ip name-server` command.
- Configuration is stored in running-config.
- Pipe commands (`| section`) are useful for filtering output.
Memory trick: To see the 'name-server' config, look in the 'running-config' section for 'dns'.
Network Topologies
Flip cardNetwork topologies describe the physical or logical arrangement of connections between nodes in a network.
- Physical topology: How devices are physically connected.
- Logical topology: How data flows between devices.
- Common types: Star, Bus, Ring, Mesh.
Memory trick: Stars point to a center, Buses share a line, Rings form a loop, but Mesh connects Everyone.
Cisco AP WLC Discovery Methods
Flip cardCisco lightweight Access Points use several methods to discover and join a Wireless LAN Controller (WLC) to establish a CAPWAP tunnel.
- Methods include DHCP Option 43, DNS, local subnet broadcasts, and manual configuration.
- DNS entry typically 'cisco-capwap-controller.local'.
- Order of preference can vary slightly but manual is often highest.
Memory trick: D.D.D. M. - DHCP, DNS, Discover, Manual
DHCP Excluded Addresses
Flip cardA configuration setting on a DHCP server that specifies a range of IP addresses within a DHCP pool that should not be assigned to dynamic clients, typically reserved for static device assignments.
- Prevents conflicts with static IPs.
- Configured per DHCP pool.
- Ensures critical devices maintain their assigned addresses.
Memory trick: Exclude addresses you want to keep for special guests.
QoS Classification and Marking
Flip cardThe process of identifying specific types of network traffic and assigning them a priority or class label for differentiated treatment.
- First step in a comprehensive QoS strategy.
- Classification criteria: IP address, port number, protocol, ACLs.
- Marking methods: CoS (802.1p), DSCP (IP Precedence), MPLS EXP.
Memory trick: First, you Classify and Mark, then you Manage and Shape.
Cisco IOS Interface Speed/Duplex
Flip cardCisco IOS allows manual configuration of interface speed and duplex settings, overriding auto-negotiation, using the 'speed' and 'duplex' commands.
- Manual settings are useful to resolve auto-negotiation issues or enforce specific link parameters.
- If one side is manually configured and the other is auto-negotiating, a duplex mismatch can occur.
- Common speed options include 10, 100, 1000, and auto. Duplex options are half, full, and auto.
Memory trick: Speed and Duplex are set explicitly, Auto-Negotiate is for flexibility.
Power over Ethernet (PoE)
Flip cardA technology that allows network cables to carry electrical power along with data, eliminating the need for separate power outlets for networked devices.
- Defined by IEEE 802.3af (PoE), 802.3at (PoE+), and 802.3bt (PoE++).
- Simplifies installation of devices like IP phones, access points, and security cameras.
- Requires a Power Sourcing Equipment (PSE) like a PoE switch or injector.
Memory trick: PoE is Power over Ethernet, PLC is Powerline, USB is Small, Fiber is Light.
Cisco IOS Global Configuration Mode
Flip cardGlobal configuration mode is a primary configuration mode in Cisco IOS where system-wide parameters like hostname, routing protocols, and user accounts are set.
- Accessed from privileged EXEC mode.
- Indicated by the prompt `(config)#`.
- Allows for broad, system-level changes.
Memory trick: Every user needs an interface, but global changes need a terminal.
Dual-Band Access Point
Flip cardA dual-band access point is a wireless device that can transmit and receive signals on both the 2.4 GHz and 5 GHz frequency bands simultaneously.
- Supports both 2.4 GHz (longer range, more interference) and 5 GHz (higher speed, less interference).
- Allows clients to connect to the optimal band.
- Common in modern wireless deployments.
Memory trick: Two bands, two frequencies, one access point: dual-band delight!
Cisco IOS RSA Key Generation
Flip cardThe process of creating an RSA public-private key pair on a Cisco device, essential for securing protocols like SSH.
- Uses 'crypto key generate rsa' command.
- Requires a hostname and domain name to be configured.
- Modulus size (e.g., 1024 or 2048) determines key strength.
Memory trick: To make SSH 'secure', you need to 'generate' a 'crypto key' that's 'RSA' and 'general' enough.
Cisco IOS PAT Configuration
Flip cardSteps to configure Port Address Translation (NAT Overload) on a Cisco router for internet access.
- Define `ip nat inside` on the internal interface.
- Define `ip nat outside` on the external (ISP-facing) interface.
- Use `ip nat inside source list <ACL> interface <outside_interface> overload` for PAT.
- An Access Control List (ACL) defines which internal traffic to translate.
Memory trick: Inside is private, Outside is public, ACL lists what to overload on the outside interface.
Dynamic Trunking Protocol (DTP)
Flip cardA Cisco proprietary protocol used to negotiate trunking between two directly connected switches. It can dynamically change a port's operational mode to trunk or access.
- DTP operates in modes: desirable, auto, on, off, nonegotiate.
- It can lead to security risks if not properly managed.
- `switchport mode access` implicitly disables DTP negotiation.
Memory trick: No DTP chat: Access or Trunk 'nonegotiate'.
Verifying DHCP Configuration
Flip cardCommands used on Cisco devices to inspect the current DHCP server or relay agent settings.
- show running-config | section dhcp: comprehensive view of DHCP settings.
- show ip dhcp pool: displays details of configured DHCP address pools.
- show ip dhcp binding: shows active DHCP leases.
Memory trick: To know the DHCP role, look at the whole config script.
Usable Host Calculation
Flip cardThe number of usable host IP addresses in a subnet is calculated as 2^n - 2, where 'n' is the number of host bits.
- The '-2' accounts for the network address and the broadcast address, which cannot be assigned to hosts.
- To find 'n', determine the smallest power of 2 that is greater than or equal to (required hosts + 2).
- The CIDR notation (e.g., /26) indicates the number of network bits; host bits = 32 - network bits.
Memory trick: Hosts need power of 2 minus 2, CIDR gives network, 32 minus that is host.
Enable Cisco DHCP Server
Flip cardTo enable the DHCP server functionality on a Cisco IOS router, the global configuration command 'service dhcp' must be used.
- Required before DHCP pools can be active.
- Enables the DHCP daemon on the router.
- Part of the initial setup for DHCP server roles.
- Without it, DHCP requests will not be processed by the router.
Memory trick: Service DHCP, then you can serve IPs!
Cisco Router DNS Resolution Test
Flip cardUsing Cisco IOS commands to test if a router can successfully resolve domain names configured with `ip name-server` and `ip domain-lookup`.
- `ping <hostname>` is the primary method to test DNS resolution on a router.
- Router must have `ip domain-lookup` enabled (default on many platforms).
- `ip name-server` specifies DNS server IP addresses.
Memory trick: To see if the router knows the name, just PING its domain game.
QoS Policy Verification
Flip cardTo verify the real-time effect of a QoS policy on an interface and see if specific traffic is matching a class, use the 'show policy-map interface <interface-id> {input | output}' command.
- Provides live statistics on class matches and actions.
- Shows bytes and packets matched by each class.
- Essential for troubleshooting QoS implementation.
- Helps identify if traffic is being correctly classified and treated.
Memory trick: Show Policy-Map interface, see the traffic flow!
WLC AP-Manager Interface
Flip cardThe AP-Manager interface on a Cisco Wireless LAN Controller (WLC) is a logical interface specifically configured to handle CAPWAP control and data plane traffic between the WLC and its managed Access Points (APs).
- Dedicated for AP communication.
- Can have multiple AP-Manager interfaces for load balancing.
- Supports CAPWAP data and control tunnels.
Memory trick: M.A.D. S. - Management, AP-Manager, Dynamic, Service
Usable Host IP Addresses Calculation
Flip cardThe number of usable host IP addresses in a subnet is calculated by subtracting two (for the network and broadcast addresses) from the total number of addresses in the subnet.
- Total addresses = 2^(32 - CIDR prefix).
- Network address is the first address in the subnet.
- Broadcast address is the last address in the subnet.
Memory trick: Hosts are like seats: count them all, then remove the first and last.
IPv6 All-Nodes Multicast Address
Flip cardThe IPv6 `ff02::1` address is a link-local multicast address that targets all IPv6-enabled devices on the same local network segment, used for local discovery and communication.
- Prefix `ff02::/16` indicates link-local multicast.
- `ff02::1` is the 'all-nodes' address.
- Used by Neighbor Discovery Protocol (NDP) for various functions.
Memory trick: FF02::1: 'All-Nodes' on 'One' link, shouting out to everyone!
VLAN Creation
Flip cardCreating a VLAN on a Cisco switch involves using a specific command in global configuration mode to define the VLAN ID.
- VLANs segment broadcast domains.
- Each VLAN needs a unique ID (1-4094).
- Created in global configuration mode.
Memory trick: Very Logical Access Naming (VLAN) for network segments.
Cisco Syslog Severity Levels
Flip cardA standardized scale (0-7) used in Cisco IOS syslog messages to indicate the criticality or severity of an event.
- 0 is Emergency (most severe), 7 is Debugging (least severe).
- Number appears after the facility code in the message.
- Helps filter and prioritize log messages.
Memory trick: The 'number' in syslog is like a 'pain scale' – lower means more urgent!
IPv6 Link-Local Address (LLA)
Flip cardAn IPv6 Link-Local Address is an automatically configured address (fe80::/10 prefix) used for communication only on the local network segment, essential for Neighbor Discovery Protocol.
- Automatically configured on every IPv6-enabled interface.
- Cannot be routed beyond the local link.
- Used by Neighbor Discovery Protocol (NDP) for local communication and discovery.
Memory trick: Link-local is like talking to your neighbor: only on your street.
IPv4 Type of Service (ToS) Field
Flip cardThe IPv4 Type of Service (ToS) field (now Differentiated Services Field) is an 8-bit field used to request specific QoS treatment for a packet, enabling prioritization and differentiated services.
- 8-bit field in the IPv4 header.
- Includes the Differentiated Services Code Point (DSCP) bits and Explicit Congestion Notification (ECN) bits.
- Used by routers and switches to classify and prioritize traffic.
Memory trick: To prioritize 'Service', look at the 'Type' in the IPv4 header.
DTP Dynamic Desirable
Flip cardThe 'switchport mode dynamic desirable' command configures a switch port to actively attempt to convert the link into an 802.1Q or ISL trunk link using DTP (Dynamic Trunking Protocol).
- Actively seeks to form a trunk.
- Forms a trunk with 'desirable', 'auto', or 'trunk' on the other side.
- Requires DTP to be enabled.
Memory trick: Dynamic Desirable Always Trunks, Auto Waits.
Default Gateway Function
Flip cardThe default gateway is the IP address of the router interface on the local subnet that hosts send traffic to when the destination is outside their local network.
- Crucial for inter-subnet communication and internet access.
- If misconfigured, a host can only communicate with devices on its immediate local network.
- Typically configured manually or assigned by DHCP.
Memory trick: Local is Fine but Global is Blocked? Gateway is Gone!
Rapid PVST+ Global Configuration
Flip cardRapid PVST+ (Rapid Per-VLAN Spanning Tree Plus) is configured globally on a Cisco switch to provide faster convergence of STP states on a per-VLAN basis.
- Uses 'spanning-tree mode rapid-pvst' command.
- Applies to all VLANs by default.
- Offers faster convergence than PVST+.
Memory trick: M.O.D.E. - Mode Of Default Enablement
Static NAT
Flip cardA one-to-one mapping of a private IP address to a public IP address, ensuring the same public IP is always used for a specific private host.
- Always uses the same public IP for a given private IP.
- Useful for publicly accessible servers on a private network.
- Configured using 'ip nat inside source static' command.
Memory trick: Static NAT is like a fixed postal address for your internal server – always the same public face.
QoS Marking
Flip cardQoS Marking is the process of adding or modifying a QoS label (like CoS or DSCP) within a packet header after traffic has been classified, enabling downstream devices to apply appropriate prioritization.
- Follows classification in the QoS process.
- Applies a tag to the packet (e.g., CoS in Layer 2, DSCP in Layer 3).
- Allows other network devices to enforce QoS policies.
- Critical for end-to-end QoS implementation.
Memory trick: Classify, Mark, Queue, Police, Shape!
NTP Client Configuration
Flip cardThe process of configuring a device to synchronize its system clock with an external NTP server.
- Uses the `ntp server` command in global configuration mode.
- Ensures accurate timekeeping across network devices.
- Critical for logging, security, and troubleshooting.
Memory trick: To get time from a server, just point and serve it.
Secure Remote CLI Access
Flip cardUsing encrypted protocols to manage network devices remotely via the command-line interface.
- SSH is the industry standard for secure CLI access.
- Encrypts all data, including credentials.
- Typically uses TCP port 22.
Memory trick: For secure remote control, SSH is the only choice for the shell.
Switchport Mode Access
Flip cardThe 'switchport mode access' command configures an interface as a permanent non-trunking Layer 2 access port. It will not attempt to negotiate a trunk link.
- Prevents DTP negotiation.
- Ensures the port operates in a single VLAN.
- A security best practice for end-device ports.
Memory trick: A.C.C.E.S.S. - Always Control Connections, Especially Security-Sensitive.
Allowed VLANs on Trunk
Flip cardOn a Cisco switch, the 'switchport trunk allowed vlan' command controls which VLANs are permitted to traverse a trunk link.
- By default, all VLANs are allowed on a trunk.
- This command can filter traffic for security or performance.
- Use 'add', 'remove', or 'except' keywords for granular control.
Memory trick: Trunks are bridges, but sometimes you need a bouncer for the VLANs.
VLAN Trunk Filtering (Except)
Flip cardThe 'switchport trunk allowed vlan except <VLAN-ID>' command is used to allow all VLANs on a trunk link except for the specified VLAN(s).
- It's a convenient way to exclude specific VLANs from a trunk.
- This command implicitly includes all other VLANs.
- It simplifies configuration compared to listing all allowed VLANs.
Memory trick: Exclude the VIP (Very Important Problematic) VLAN.
Cisco IOS DNS Server Functionality
Flip cardCisco routers can be configured to act as DNS relay agents or caching DNS servers for local clients, forwarding requests to external DNS servers.
- Enabled with 'ip dns server' command.
- Upstream servers defined by 'ip name-server'.
- Router caches resolved entries to improve performance.
Memory trick: To be a DNS 'server' for clients, the router must have its 'server' function turned ON.
STP Port Type (P2p)
Flip cardIn Spanning Tree Protocol (STP) output, 'Type: P2p' indicates that a switch port is configured for point-to-point operation, typically implying a full-duplex connection to another switch or host.
- P2p = Point-to-point.
- Implies full-duplex link.
- Enables faster STP convergence (e.g., PortFast, UplinkFast).
Memory trick: Listen, Learn, Forward, Block, Disable: STP's Five States.
Trunk Allowed VLAN Add
Flip cardThe 'switchport trunk allowed vlan add <VLAN-ID>' command is used on a Cisco switch to append a specific VLAN to the existing list of VLANs permitted to traverse a trunk link.
- Does not overwrite existing allowed VLANs.
- Useful for incrementally adding VLANs to an active trunk.
- Ensures new VLANs can pass through.
Memory trick: A.D.D. V. - Add Dynamic Data VLAN
Router Interfaces and IP Addresses
Flip cardEach active interface on a router that connects to a unique IP subnet must be configured with an IP address from that subnet to enable routing between networks.
- A router connects different IP broadcast domains/subnets.
- Each interface acts as the default gateway for its connected subnet.
- Each interface needs a unique IP address from its respective subnet.
Memory trick: One subnet, one address; two subnets, two addresses, to connect them through!
Cisco IOS DNS Resolution Test
Flip cardUsing various Cisco IOS commands to verify if a router can successfully resolve a hostname to an IP address via DNS.
- Ping command implicitly tests DNS resolution.
- Router must have 'ip domain lookup' and 'ip name-server' configured.
- Can also use 'nslookup' if available (though 'ping' is often sufficient).
Memory trick: To see if the router 'knows' a name, just 'ping' it – if it can't find it, it'll tell you!
Wireless Client IP Learn Failure
Flip cardWhen a wireless client associates with an AP but fails to obtain an IP address, it typically indicates a Layer 2 issue preventing DHCP communication, commonly a VLAN or trunking misconfiguration.
- Client associates, but no IP.
- Points to Layer 2/3 boundary issue.
- Commonly VLAN/trunking problem.
Memory trick: VLANs Often Cause Layer 3 Negation during IP acquisition.
Low Latency Queuing (LLQ)
Flip cardA QoS queuing mechanism that combines strict priority queuing for real-time traffic (like voice) with CBWFQ for other traffic classes.
- Uses 'priority' command for strict priority queue.
- Guarantees low latency and jitter for mission-critical applications.
- Includes implicit policing to ensure the priority queue doesn't starve other queues.
Memory trick: For 'Low Latency,' think 'LLQ' – it gives the VIPs (voice) a fast pass!
Cisco IOS SNMP Community String with ACL
Flip cardConfiguring an SNMP community string on a Cisco device and associating it with an access control list (ACL) to restrict which management stations can use that string.
- Enhances security by limiting access to SNMP data.
- Uses 'snmp-server community [string] [ro/rw] [acl_number]'.
- The ACL specifies permitted source IP addresses.
Memory trick: For SNMP security, the 'community string' is the 'key', but the 'ACL' is the 'bouncer' at the door.
DHCP Reservation
Flip cardDHCP reservation is a feature that allows a DHCP server to consistently assign the same IP address to a specific client, identified by its MAC address.
- Maps a static IP to a dynamic MAC address.
- Ensures critical devices like servers or printers always get the same address.
- Configured on the DHCP server itself.
Memory trick: The DHCP server is like a landlord, assigning addresses. Reservations are like a permanent lease.
NAT Translation Table Interpretation
Flip cardUnderstanding the fields in `show ip nat translations` output to determine translation types, source/destination IPs, and ports.
- `Inside local`: Original source IP/port of internal host.
- `Inside global`: Translated source IP/port used externally.
- `Outside local`: Original destination IP/port of external host.
- `Outside global`: Translated destination IP/port (often same as outside local).
Memory trick: Inside to Global, Outside to Outside, Follow the Ports to know the Route.