Cisco CCNA (200-301) flashcards
226 free flashcards. Tap a card to flip it.
View Active NAT Translations
Flip cardOn a Cisco router, the 'show ip nat translations' command displays active NAT translation entries. Adding 'verbose' provides more detailed information for troubleshooting.
- Essential for verifying NAT operation.
- Shows private-to-public IP/port mappings.
- 'verbose' option adds timers, protocol, and other details.
- Helps identify resource usage and potential issues.
Memory trick: Show NAT translations, verbose for details!
NTP Client Configuration
Flip cardThe process of configuring a device to synchronize its system clock with an external NTP server.
- Uses the `ntp server` command in global configuration mode.
- Ensures accurate timekeeping across network devices.
- Critical for logging, security, and troubleshooting.
Memory trick: To get time from a server, just point and serve it.
WLC Interfaces
Flip cardCisco Wireless LAN Controllers utilize several logical interfaces for different functions, including management, AP communication, and client services.
- Management Interface: Primary for WLC management and AP control plane.
- AP-Manager Interface: Handles AP data plane (CAPWAP data).
- Virtual Interface: Used for client roaming, DHCP proxy, and web authentication.
- Service Port: Out-of-band management port.
Memory trick: Manage APs, Virtual Clients, Service Out.
Secure Remote CLI Access
Flip cardUsing encrypted protocols to manage network devices remotely via the command-line interface.
- SSH is the industry standard for secure CLI access.
- Encrypts all data, including credentials.
- Typically uses TCP port 22.
Memory trick: For secure remote control, SSH is the only choice for the shell.
Switchport Mode Access
Flip cardThe 'switchport mode access' command configures an interface as a permanent non-trunking Layer 2 access port. It will not attempt to negotiate a trunk link.
- Prevents DTP negotiation.
- Ensures the port operates in a single VLAN.
- A security best practice for end-device ports.
Memory trick: A.C.C.E.S.S. - Always Control Connections, Especially Security-Sensitive.
Allowed VLANs on Trunk
Flip cardOn a Cisco switch, the 'switchport trunk allowed vlan' command controls which VLANs are permitted to traverse a trunk link.
- By default, all VLANs are allowed on a trunk.
- This command can filter traffic for security or performance.
- Use 'add', 'remove', or 'except' keywords for granular control.
Memory trick: Trunks are bridges, but sometimes you need a bouncer for the VLANs.
VLAN Trunk Filtering (Except)
Flip cardThe 'switchport trunk allowed vlan except <VLAN-ID>' command is used to allow all VLANs on a trunk link except for the specified VLAN(s).
- It's a convenient way to exclude specific VLANs from a trunk.
- This command implicitly includes all other VLANs.
- It simplifies configuration compared to listing all allowed VLANs.
Memory trick: Exclude the VIP (Very Important Problematic) VLAN.
Cisco IOS DNS Server Functionality
Flip cardCisco routers can be configured to act as DNS relay agents or caching DNS servers for local clients, forwarding requests to external DNS servers.
- Enabled with 'ip dns server' command.
- Upstream servers defined by 'ip name-server'.
- Router caches resolved entries to improve performance.
Memory trick: To be a DNS 'server' for clients, the router must have its 'server' function turned ON.
STP Port Type (P2p)
Flip cardIn Spanning Tree Protocol (STP) output, 'Type: P2p' indicates that a switch port is configured for point-to-point operation, typically implying a full-duplex connection to another switch or host.
- P2p = Point-to-point.
- Implies full-duplex link.
- Enables faster STP convergence (e.g., PortFast, UplinkFast).
Memory trick: Listen, Learn, Forward, Block, Disable: STP's Five States.
Trunk Allowed VLAN Add
Flip cardThe 'switchport trunk allowed vlan add <VLAN-ID>' command is used on a Cisco switch to append a specific VLAN to the existing list of VLANs permitted to traverse a trunk link.
- Does not overwrite existing allowed VLANs.
- Useful for incrementally adding VLANs to an active trunk.
- Ensures new VLANs can pass through.
Memory trick: A.D.D. V. - Add Dynamic Data VLAN
Router Interfaces and IP Addresses
Flip cardEach active interface on a router that connects to a unique IP subnet must be configured with an IP address from that subnet to enable routing between networks.
- A router connects different IP broadcast domains/subnets.
- Each interface acts as the default gateway for its connected subnet.
- Each interface needs a unique IP address from its respective subnet.
Memory trick: One subnet, one address; two subnets, two addresses, to connect them through!
Cisco IOS DNS Resolution Test
Flip cardUsing various Cisco IOS commands to verify if a router can successfully resolve a hostname to an IP address via DNS.
- Ping command implicitly tests DNS resolution.
- Router must have 'ip domain lookup' and 'ip name-server' configured.
- Can also use 'nslookup' if available (though 'ping' is often sufficient).
Memory trick: To see if the router 'knows' a name, just 'ping' it – if it can't find it, it'll tell you!
Wireless Client IP Learn Failure
Flip cardWhen a wireless client associates with an AP but fails to obtain an IP address, it typically indicates a Layer 2 issue preventing DHCP communication, commonly a VLAN or trunking misconfiguration.
- Client associates, but no IP.
- Points to Layer 2/3 boundary issue.
- Commonly VLAN/trunking problem.
Memory trick: VLANs Often Cause Layer 3 Negation during IP acquisition.
Low Latency Queuing (LLQ)
Flip cardA QoS queuing mechanism that combines strict priority queuing for real-time traffic (like voice) with CBWFQ for other traffic classes.
- Uses 'priority' command for strict priority queue.
- Guarantees low latency and jitter for mission-critical applications.
- Includes implicit policing to ensure the priority queue doesn't starve other queues.
Memory trick: For 'Low Latency,' think 'LLQ' – it gives the VIPs (voice) a fast pass!
Cisco IOS SNMP Community String with ACL
Flip cardConfiguring an SNMP community string on a Cisco device and associating it with an access control list (ACL) to restrict which management stations can use that string.
- Enhances security by limiting access to SNMP data.
- Uses 'snmp-server community [string] [ro/rw] [acl_number]'.
- The ACL specifies permitted source IP addresses.
Memory trick: For SNMP security, the 'community string' is the 'key', but the 'ACL' is the 'bouncer' at the door.
DHCP Reservation
Flip cardDHCP reservation is a feature that allows a DHCP server to consistently assign the same IP address to a specific client, identified by its MAC address.
- Maps a static IP to a dynamic MAC address.
- Ensures critical devices like servers or printers always get the same address.
- Configured on the DHCP server itself.
Memory trick: The DHCP server is like a landlord, assigning addresses. Reservations are like a permanent lease.
NAT Translation Table Interpretation
Flip cardUnderstanding the fields in `show ip nat translations` output to determine translation types, source/destination IPs, and ports.
- `Inside local`: Original source IP/port of internal host.
- `Inside global`: Translated source IP/port used externally.
- `Outside local`: Original destination IP/port of external host.
- `Outside global`: Translated destination IP/port (often same as outside local).
Memory trick: Inside to Global, Outside to Outside, Follow the Ports to know the Route.
Cisco Discovery Protocol (CDP)
Flip cardCDP is a Cisco proprietary Layer 2 protocol used to discover information about directly connected Cisco devices, such as device type, IOS version, capabilities, and interface information.
- Runs on all Cisco devices by default.
- Operates at Layer 2 (data link layer).
- Useful for network mapping and troubleshooting.
- Provides device ID, platform, capabilities, and IOS version.
Memory trick: CDP is a detective, finding clues about its direct neighbors.
LACP vs PAgP Modes
Flip cardLACP (Link Aggregation Control Protocol) and PAgP (Port Aggregation Protocol) are two distinct protocols for EtherChannel negotiation, each with its own active and passive/desirable modes.
- LACP uses 'active' and 'passive'.
- PAgP uses 'desirable' and 'auto'.
- LACP and PAgP are NOT interoperable.
Memory trick: Always Connect Links Properly or Perish Gracefully.
show spanning-tree vlan
Flip cardThe 'show spanning-tree vlan <VLAN_ID>' command is used on Cisco switches to display detailed Spanning Tree Protocol information for a particular VLAN.
- Shows STP mode (PVST+, Rapid PVST+, MST).
- Displays root bridge ID and local bridge ID.
- Provides port roles, states, costs, and priorities for the VLAN.
Memory trick: S.T.P. V. - Spanning Tree Protocol, Verify!
Cisco Router DHCP Client
Flip cardConfiguring a router interface to automatically obtain IP configuration from a DHCP server.
- Uses the `ip address dhcp` command under the interface.
- Receives IP address, subnet mask, default gateway, and DNS servers.
- Simplifies IP address management on client-facing interfaces.
Memory trick: To get your IP 'address' from 'DHCP', just tell it to do so.
Router Function (Layer 3)
Flip cardA router is a network device that operates at Layer 3 (Network Layer) of the OSI model, primarily responsible for forwarding IP packets between different IP networks (subnets).
- Connects different broadcast domains and IP subnets.
- Uses IP addresses to make forwarding decisions.
- Maintains a routing table to determine the best path for packets.
- Prevents broadcast storms from propagating across networks.
Memory trick: Routers Route between Networks, Switches Switch within.
Cisco VTY Transport Input
Flip cardThe 'transport input' command on Cisco VTY lines dictates which protocols (Telnet, SSH, or both) are permitted for remote access.
- Located under 'line vty' configuration mode.
- 'transport input telnet' allows only Telnet.
- 'transport input ssh' allows only SSH.
- 'transport input all' allows both Telnet and SSH.
Memory trick: Transport input: All means all, SSH for just SSH.
Cisco IOS Show Commands
Flip cardIOS `show` commands are used to display the current state, configuration, and operational parameters of a Cisco device for verification and troubleshooting.
- `show running-config` displays the current active configuration.
- `show ip interface brief` provides a quick overview of interface status and IP addresses.
- `show vlan brief` lists all configured VLANs and their assigned ports.
Memory trick: Show me the switchport's secrets!
DHCP DNS Update Verification
Flip cardTo verify if a Cisco IOS DHCP server is configured to perform DNS updates for clients, use the 'show ip dhcp pool' command.
- DHCP servers can dynamically update DNS records for clients.
- This feature helps ensure DNS consistency for dynamically assigned IPs.
- The 'show ip dhcp pool' command reveals the 'dns-update' configuration.
Memory trick: DHCP Pool shows if DNS is a Go!
Subnet Masking (CIDR /25)
Flip cardSubnet masking divides a larger IP network into smaller, more manageable subnets, defining which portion of an IP address identifies the network and which identifies the host.
- A /25 mask corresponds to 255.255.255.128.
- A /25 mask creates two subnets from a Class C /24 network.
- Devices in different subnets require a router to communicate.
Memory trick: Same house, same conversation. Different houses need a door (router).
HSRP Preemption
Flip cardHSRP preemption allows a router with a higher priority to take over the Active role from a lower-priority Active router, even if the lower-priority router is already active.
- Enabled with 'standby <group-number> preempt' command.
- Ensures the highest priority router is always Active.
- Critical for returning to a preferred primary gateway after recovery.
Memory trick: Preemption means the KING always takes the crown back if he's able.
OSPF MTU Mismatch
Flip cardAn MTU mismatch on a link between OSPF neighbors can prevent the successful exchange of Database Description (DBD) packets, causing neighbors to get stuck in the EXSTART or EXCHANGE states.
- MTU: Maximum Transmission Unit (largest packet size).
- OSPF uses MTU in DBD packets.
- Mismatch prevents master/slave negotiation and database synchronization.
- Can be resolved by setting matching MTU values or ignoring MTU checks (not recommended).
Memory trick: DBD exchange needs matching MTU, or EXSTART/EXCHANGE will be stuck like glue.
IPv6 Routing Table Codes
Flip cardCisco IOS uses single-letter codes in routing table entries to indicate how a route was learned or its type, similar to IPv4 routing tables.
- `S` for Static route.
- `C` for Connected route.
- `L` for Local route (interface's own address).
- `O` for OSPF route.
Memory trick: Codes tell the story, of route's origin and glory.
Static Route Next-Hop Resolution (Multi-Access)
Flip cardWhen a static route on a multi-access network (e.g., Ethernet) specifies only an exit interface, the router must resolve the next-hop IP address via ARP on that interface to forward traffic.
- Applies to multi-access interfaces (e.g., Ethernet, not point-to-point serial).
- Without an explicit next-hop IP, the router assumes the next-hop is directly reachable on the specified interface.
- Requires ARP resolution for the destination network on the exit interface.
Memory trick: Static routes need a path; multi-access needs a neighbor's IP to leap.
IPv6 Static Route with Link-Local Next-Hop
Flip cardWhen configuring an IPv6 static route using a link-local address as the next-hop, both the next-hop link-local address AND the local exit interface must be specified.
- Link-local addresses are unique only on a single link.
- Router needs the exit interface to know which link to send traffic out.
- Syntax: `ipv6 route [prefix/len] [interface] [link-local-address]`.
- Prevents ambiguity in next-hop resolution.
Memory trick: Link-local needs its Link, to know where to think.
OSPF Routing Table Metric
Flip cardOSPF routes in the routing table display `[Administrative Distance/Cost]`, where the cost is the OSPF metric calculated based on interface bandwidths.
- Administrative Distance (AD) is 110 for OSPF internal routes.
- The cost is an accumulated value from the source to the destination.
- Lower cost is preferred for path selection.
Memory trick: AD then Metric, a route's specific numeric trick.
Static Route Administrative Distance
Flip cardBy default, static routes have an administrative distance of 1, indicating a high level of trustworthiness compared to dynamic routing protocols.
- Administrative distance (AD) is used to select the best path when multiple routing protocols provide routes to the same destination.
- Lower AD is preferred.
- AD 1 is the default for static routes.
- AD 0 is for directly connected routes.
Memory trick: AD is the judge, lower number wins the knowledge.
OSPF Timer Matching
Flip cardOSPF Hello and Dead intervals must match between directly connected neighbors for adjacency to form and be maintained.
- Hello interval: frequency of sending Hello packets.
- Dead interval: time to wait for a Hello before declaring a neighbor down.
- Default Dead interval is 4 times the Hello interval.
- Mismatch prevents neighbor state from reaching FULL.
Memory trick: To be OSPF friends, timers must match from ends to ends.
OSPF E2 Route Metric
Flip cardFor OSPF External Type 2 (E2) routes, the metric displayed in the routing table (after the administrative distance) is the external cost advertised by the ASBR, which remains constant.
- E2 routes are external routes.
- The metric is the external cost from the ASBR.
- Internal cost to ASBR is not added for E2 routes.
Memory trick: OSPF's journey: Internal cost accumulates, E1 adds, E2 keeps it fixed.
Longest Prefix Match Rule
Flip cardWhen a router receives a packet, it compares the destination IP address with all routes in its routing table and selects the route with the longest (most specific) matching prefix.
- Takes precedence over Administrative Distance and metric.
- A /26 prefix is more specific than a /24 prefix.
- Ensures traffic is sent to the most precise known destination.
- Fundamental principle of IP routing.
Memory trick: Longest Prefix is the first choice, then AD shouts its voice, then Metric's rejoice.
Show IP Route Command
Flip cardThe `show ip route` command displays the IPv4 routing table, detailing all known routes, their administrative distances, metrics, next-hop IP addresses, and exit interfaces.
- Primary command for routing table verification.
- Shows how routes were learned (e.g., C for connected, S for static, O for OSPF).
- Includes administrative distance and metric for each route.
- Displays next-hop IP and/or exit interface.
Memory trick: To see the routes, `show ip route` shouts.
OSPF Passive Interface
Flip cardA passive OSPF interface suppresses the sending and receiving of OSPF Hello packets, preventing neighbor adjacencies, but still advertises its connected network into the OSPF domain.
- Prevents OSPF Hellos on the interface.
- No OSPF neighbor relationships formed on passive interface.
- Connected network is still advertised into OSPF.
Memory trick: Passive means silent neighbor, but still tells everyone about its home.
Cisco IOS XE RESTCONF Enablement
Flip cardTo use RESTCONF on a Cisco IOS XE device, the feature must be explicitly enabled in the configuration, typically via the 'restconf' command in global configuration mode.
- Enables interaction with device using RESTful API over HTTP/HTTPS.
- Requires `restconf` command in global config mode.
- Often uses default HTTPS port 443, but can be configured.
- Provides programmatic access to YANG data models.
Memory trick: RESTCONF needs to be 'REST-ing' on the device, not just 'present'.
DTP Negotiation with Desirable and Auto
Flip cardWhen a Dynamic Desirable port connects to a Dynamic Auto port, the Desirable port actively initiates trunking, and the Auto port responds, successfully forming a trunk link.
- Dynamic Desirable: Actively attempts to convert the link into a trunk link.
- Dynamic Auto: Makes the port willing to convert the link to a trunk link if the neighboring port is set to trunk or desirable mode.
- Trunking occurs when at least one side is Desirable, or both sides are Trunk.
Memory trick: Desirable Drives, Auto Agrees: A Trunk Together.
EtherChannel Summary Command
Flip cardThe 'show etherchannel summary' command is used to quickly verify the operational status, protocol, and member interfaces of all configured EtherChannels on a Cisco switch.
- Displays group number, protocol (LACP, PAgP, or On), and port-channel interface.
- Shows individual member ports and their flags (P for bundled, S for suspended, I for standalone).
- Indicates the overall status of the Port-Channel interface (e.g., U for up, D for down).
Memory trick: EtherChannel Summary: See the whole story, quickly.
LACP Active/Passive Interaction
Flip cardAn EtherChannel using LACP will form successfully when one side is configured in 'active' mode and the other in 'passive' mode, as 'active' initiates negotiations and 'passive' responds.
- LACP Active: Actively sends LACP PDUs and tries to negotiate an EtherChannel.
- LACP Passive: Responds to LACP PDUs but does not initiate them.
- A successful LACP EtherChannel requires at least one side to be in 'active' mode.
Memory trick: Active Asks, Passive Partners: Channel Connects.
Ansible `ios_vlan` Module
Flip cardThe `ios_vlan` Ansible module is used to manage VLAN configurations on Cisco IOS and IOS XE devices, ensuring idempotent creation, modification, or deletion of VLANs.
- Part of `cisco.ios` collection.
- Manages VLAN properties like ID, name, state.
- Supports `state: present` for creation/ensuring existence.
- Supports `state: absent` for deletion.
Memory trick: For 'VLANs on IOS', 'ios_vlan present' is the idempotent solution.
RSTP Alternate Port (Alt) and Link Type (P2p)
Flip cardIn Rapid PVST+, an Alternate (Alt) port is a blocking port that provides a redundant path to the root bridge. A Point-to-point (P2p) link type indicates a full-duplex connection to another switch, enabling rapid transition to forwarding.
- Alternate (Alt) port: A non-designated port that is blocking and has a valid path to the root bridge.
- P2p link type: Indicates a full-duplex, point-to-point connection, allowing for rapid state transitions (e.g., from blocking to forwarding in 2-3 seconds).
- Shared link type: Indicates a half-duplex or shared segment (e.g., hub), which uses traditional STP timers.
Memory trick: Alternate Blocks, Point-to-Point Powers Past.
802.1Q Trunk Configuration
Flip cardTo configure a switch port as an 802.1Q trunk, you use the 'switchport mode trunk' command, which enables the port to carry traffic for multiple VLANs.
- 802.1Q is the industry standard for VLAN tagging on trunk links.
- Trunk ports carry traffic for multiple VLANs, access ports carry traffic for a single VLAN.
- On modern Cisco switches, 802.1Q is the default and often only supported trunk encapsulation type.
Memory trick: Trunk Mode: Tagging Traffic for Transport
WLC DHCP Relay for Local Mode APs
Flip cardWhen an AP is in Local mode, the WLC acts as the DHCP relay for its clients. If the DHCP server is on a different VLAN, an IP helper address must be configured on the WLC's SVI for the client's VLAN to forward DHCP requests.
- Local mode APs tunnel client traffic to the WLC via CAPWAP.
- The WLC processes client DHCP requests (decapsulates and forwards).
- IP helper addresses are crucial on the WLC for cross-VLAN DHCP communication.
Memory trick: WLC's Helper Hand: Directing DHCP to the Right Door.