Implementing and Operating Cisco Enterprise Network Core Technologies (ENCOR) v1.2 flashcards
163 free flashcards. Tap a card to flip it.
Thin Edge Computing
Flip cardAn edge computing model characterized by simple, low-power devices with minimal processing capabilities, primarily focused on data collection and secure forwarding.
- Suitable for large-scale sensor deployments.
- Low power consumption and cost.
- Typically sends raw or lightly processed data to a central system.
Memory trick: Thin edge is for 'tiny data', thick edge for 'heavy lifting'.
RESTCONF for IOS XE Native Config
Flip cardRESTCONF uses YANG models to represent device configurations. For Cisco IOS XE, the 'Cisco-IOS-XE-native:native' model specifically exposes the entire traditional CLI-like running configuration.
- RESTCONF is a protocol for configuring network devices using YANG data models.
- Cisco-IOS-XE-native:native is the YANG model for the traditional IOS XE running configuration.
- The /restconf/data/ path prefix is used to access data nodes.
Memory trick: RESTful configuration fetches data from the native model.
Model-Driven Telemetry (MDT)
Flip cardA push-based mechanism that streams operational data from network devices to collectors using YANG data models, offering high-frequency and granular data collection.
- Push-based data delivery.
- Uses YANG data models for structured data.
- Supports high-frequency and granular data collection.
- More efficient than traditional polling for real-time monitoring.
Memory trick: Telemetry is like a real-time data stream, always pushing fresh info.
Network Modularity
Flip cardThe design principle of dividing a network into smaller, independent, and easily manageable functional blocks or modules.
- Simplifies design and implementation.
- Improves fault isolation and troubleshooting.
- Facilitates scalability and service deployment.
Memory trick: HRMS: Hierarchy, Resilience, Modularity, Scalability are key principles.
YANG Data Modeling Language
Flip cardA data modeling language used to define the data structures of configuration and state data for network devices, enabling programmatic interaction via protocols like NETCONF and RESTCONF.
- Defines data hierarchy, types, constraints.
- Used by NETCONF and RESTCONF APIs.
- Ensures data consistency and validation.
Memory trick: YANG is the 'blueprint' for network data, defining its 'shape'.
Cisco SD-Access Segmentation
Flip cardCisco SD-Access implements advanced network segmentation through Virtual Networks (VNIs) for macro-segmentation and Security Group Tags (SGTs) for micro-segmentation. This allows for policy enforcement based on user and device identity, independent of network topology.
- Macro-segmentation with Virtual Networks (VNIs).
- Micro-segmentation with Security Group Tags (SGTs).
- Identity-based policy enforcement.
- Fabric overlay network for simplified operations.
Memory trick: SD-Access: Campus segmentation for users and devices.
Python json module
Flip cardThe `json` module in Python is the standard library for working with JSON (JavaScript Object Notation) data. It allows for serialization (encoding Python objects to JSON strings) and deserialization (decoding JSON strings to Python objects).
- Built-in Python module.
- Handles JSON encoding (dump, dumps) and decoding (load, loads).
- Converts JSON objects to Python dictionaries and arrays to lists.
Memory trick: JSON is for `json`, XML for `xml`, YAML for `yaml`, CSV for `csv`.
Cisco SD-WAN vManage Role
Flip cardvManage is the centralized management plane of Cisco SD-WAN. It provides a single pane of glass for configuration, monitoring, troubleshooting, and API integration for the entire SD-WAN fabric.
- Centralized management and monitoring.
- Collects telemetry data from all devices.
- Exposes APIs for integration with external systems.
- Used for configuration, policy deployment, and software upgrades.
Memory trick: Manage monitors, Smart controls, Bond connects, Edge carries.
NETCONF Transactional Configuration
Flip cardNETCONF enables transactional configuration management using a 'candidate' configuration datastore. Changes are first staged in the candidate, then atomically committed to the 'running' configuration, ensuring all changes succeed or are rolled back.
- Uses candidate datastore for staging changes.
- Changes are committed atomically using the `<commit>` operation.
- Supports validation and rollback mechanisms.
- Ensures configuration consistency and integrity.
Memory trick: NETCONF is the network's ACID transactions.
Paramiko Library
Flip cardA Python library that provides a pure Python (2.7/3.4+) implementation of the SSHv2 protocol, enabling client and server functionality for SSH connections.
- Implements SSHv2 protocol.
- Allows executing commands and transferring files over SSH.
- Suitable for basic command-line automation with network devices.
Memory trick: Python's many tools, but for direct SSH, Paramiko's the key.
requests Library Basic Auth
Flip cardThe 'requests' Python library simplifies HTTP Basic Authentication by allowing a (username, password) tuple to be passed to the 'auth' parameter of request methods.
- Automatically base64 encodes credentials.
- Sets the 'Authorization: Basic' header.
- Securely handles credentials within the library.
Memory trick: Requests 'auth' parameter is the key to 'basic' authentication.
Synthetic Transaction Monitoring
Flip cardA network assurance technique that uses automated scripts to simulate user interactions with applications, proactively measuring end-to-end performance, availability, and validating the entire service delivery chain.
- Proactively tests application performance and availability.
- Identifies issues before actual users are affected.
- Validates all underlying infrastructure, including redundancy.
Memory trick: SNMP checks 'health', NetFlow checks 'flow', Synthetic 'acts' like a user.
Cisco DNA Center Northbound APIs
Flip cardA set of RESTful APIs exposed by Cisco DNA Center that allow external systems to programmatically interact with and manage the SD-Access fabric and other network services.
- Enables integration with ITSM, orchestration, and custom applications.
- Provides programmatic access to network inventory, topology, policy, and assurance.
- Centralized control point for SD-Access automation.
Memory trick: DNA Center is the 'center' for SD-Access integration, connecting the 'world'.
Netmiko Library
Flip cardA Python library that simplifies SSH connections to network devices, handling various prompts and providing a consistent API for sending commands and retrieving output across different vendors.
- Built on top of Paramiko.
- Supports multiple network vendors (Cisco, Juniper, Arista, etc.).
- Simplifies sending commands, config, and parsing output.
Memory trick: Python needs a 'net' to 'miko' (make) SSH connections.
Ansible for Network Automation
Flip cardAn agentless automation engine that uses SSH by default, supports various network protocols via modules, and is highly extensible for multi-vendor network device management and desired state configuration.
- Agentless (uses SSH by default).
- Supports multiple network protocols (NETCONF, RESTCONF, CLI).
- Idempotent: defines desired state.
- Highly extensible with custom modules and roles.
Memory trick: Ansible is the versatile conductor, managing all instruments without needing them to install software.
Declarative Automation
Flip cardAn automation paradigm where the desired end-state of a system is specified, and the automation tool determines and executes the necessary steps to achieve and maintain that state.
- Focuses on 'what' to achieve, not 'how'.
- Tools handle idempotency and state convergence.
- Examples: Ansible, Puppet, Chef, SaltStack.
Memory trick: Declarative is like aiming for a 'target', procedural is like writing 'steps'.
JSON (JavaScript Object Notation)
Flip cardA lightweight, text-based, language-independent data interchange format that is easy for humans to read and write and easy for machines to parse and generate.
- Uses key-value pairs and ordered lists.
- Widely adopted for REST APIs.
- Native support in JavaScript, easily parsed by other languages.
Memory trick: For API data, 'JSON' is the 'just-on' choice for simplicity.
NETCONF <get> Operation
Flip cardIn NETCONF, the `<get>` operation is used to retrieve both configuration data and operational state data from a network device, typically using filters to specify the desired information.
- Retrieves configuration and state data.
- Can use filters to target specific data.
- Distinct from `<get-config>` which only retrieves configuration.
Memory trick: GET everything, GET-CONFIG only config.
Ansible Key Features
Flip cardAnsible is an open-source automation engine that automates software provisioning, configuration management, and application deployment. It's popular for its simplicity, agentless nature, and use of human-readable YAML playbooks.
- Agentless (uses SSH, WinRM).
- Declarative language (YAML playbooks).
- Strong community support and extensive modules.
- Idempotent operations.
Memory trick: Agentless, Community, Declarative: Think A-C-D, think Ansible.
Hybrid SD-WAN Deployment
Flip cardAn SD-WAN deployment model that integrates both on-premises and cloud-hosted components to connect diverse network segments, such as branches, data centers, and public cloud resources.
- Combines physical appliances with cloud gateways/controllers.
- Offers flexibility for heterogeneous environments.
- Optimizes connectivity to both on-premises and cloud applications.
Memory trick: Hybrid SD-WAN is the 'best of both worlds' for mixed environments.
Hybrid Cloud Connectivity
Flip cardConnecting on-premises data centers with public cloud infrastructure to create a unified computing environment.
- Requires secure, reliable, and often low-latency links.
- Options include VPNs, SD-WAN, and dedicated private connections.
- Goals: consistent policies, optimized traffic, seamless resource access.
Memory trick: Dedicated links are the 'express lane' for hybrid cloud traffic.
Routed Access (Layer 3 Access)
Flip cardA campus network design where access switches perform Layer 3 routing, extending the routing domain to the access layer and eliminating the need for Spanning Tree Protocol.
- Eliminates STP complexity and convergence issues.
- Enables faster convergence and more efficient routing.
- Facilitates Equal-Cost Multi-Path (ECMP) for load balancing.
Memory trick: Layer 3 to the access is 'faster, simpler, stronger'.
NETCONF over SSH Authentication
Flip cardNETCONF typically uses SSH as its secure transport. Authentication for NETCONF over SSH relies on the underlying SSH authentication mechanism. If username/password authentication fails, it often indicates an issue with the local user account's configuration for SSH access or privilege level on the device.
- NETCONF uses SSH for secure transport.
- Authentication is handled by SSH (e.g., username/password, SSH keys).
- Local user accounts on Cisco devices need `privilege 15` for full NETCONF capabilities.
- SSH server must be enabled and VTY lines configured for SSH access.
Memory trick: Authentication failed? Check the user's SSH rights and privilege first.
802.1X with NAC
Flip cardA robust network access control mechanism that authenticates users and devices before granting network access, often dynamically assigning them to appropriate VLANs and applying security policies.
- Requires an authentication server (e.g., RADIUS/TACACS+).
- Authenticates based on user credentials or device certificates.
- Enables dynamic VLAN assignment and policy enforcement.
Memory trick: VLANs divide 'rooms', 802.1X/NAC is the 'bouncer' at the door.
Python xml.etree.ElementTree
Flip cardThe `xml.etree.ElementTree` module provides a simple and efficient API for parsing and creating XML data. It represents XML as a tree structure, allowing navigation and manipulation of elements and attributes.
- Standard Python library for XML.
- `fromstring()` parses XML text into an Element object.
- Elements have attributes accessible via the `.get()` method.
- Supports XPath-like expressions for finding elements.
Memory trick: XML is a tree, ElementTree helps you climb it and GET attributes.
SD-WAN Orchestrator
Flip cardA centralized management platform in an SD-WAN architecture that provides a single pane of glass for configuring, monitoring, and managing the entire SD-WAN fabric.
- Centralized configuration and policy deployment.
- Provides overall visibility and control.
- Orchestrates communication between controllers and edge devices.
Memory trick: Orchestrator 'conducts' the whole SD-WAN band.
Packet Capture and Analysis
Flip cardA network assurance technique involving the interception and examination of individual data packets to understand network behavior, diagnose issues, and analyze traffic at the lowest level.
- Provides granular, real-time insight into traffic.
- Essential for deep-dive troubleshooting of intermittent or complex issues.
- Reveals protocol errors, latency, and application-level problems.
Memory trick: Packet capture is the 'microscope' for network problems.
Cisco SD-Access
Flip cardCisco's intent-based networking solution for campus and branch environments, providing automated end-to-end network segmentation, policy enforcement, and centralized management across wired and wireless networks.
- Automated network segmentation (macro and micro).
- Policy enforcement based on user/device identity.
- Consistent wired and wireless experience.
- Managed by Cisco DNA Center.
Memory trick: SD-Access is the campus guard, segmenting and protecting everyone.
gRPC for Network Automation
Flip cardA modern, open-source RPC framework that uses Protocol Buffers for efficient data serialization and HTTP/2 for transport, enabling high-performance, bidirectional streaming, and language-agnostic communication.
- Uses Protocol Buffers (Protobuf) for efficient serialization.
- Based on HTTP/2 for transport, enabling multiplexing and streaming.
- Supports bidirectional streaming RPCs.
- Language-agnostic with code generation for multiple languages.
Memory trick: gRPC is the fast lane, streaming data like a river with efficient packaging.
Cisco DNA Center in SD-Access
Flip cardCisco DNA Center is the controller and management platform for Cisco SD-Access. It provides a single user interface for designing, provisioning, applying policy, and assuring the network, translating business intent into network configurations.
- Centralized management and orchestration.
- Policy definition (e.g., SGTs, VNIs).
- Network design, provisioning, and assurance.
- Translates business intent into network configurations.
Memory trick: DNA Center is the brain that writes the rules.
NETCONF Protocol
Flip cardAn XML-based network management protocol that provides mechanisms to install, manipulate, and delete configuration data on network devices, offering structured, programmatic access and transactional capabilities.
- Uses XML for data encoding.
- Typically runs over SSH for secure transport.
- Relies on YANG models for data definition.
- Separates configuration data from operational state.
Memory trick: NETCONF is the secure, structured librarian for your network's configuration books.
RESTCONF Protocol
Flip cardAn HTTP-based protocol that provides a programmatic interface for accessing YANG-modeled data, including configuration and state, on network devices.
- Uses HTTP/HTTPS for communication.
- Adheres to REST principles (GET, POST, PUT, DELETE).
- Supports XML and JSON data formats.
- Interacts with data defined by YANG models (including native configuration).
Memory trick: RESTCONF is like a web browser for your network config, using familiar HTTP commands.
Zero Trust Security
Flip cardA security model that assumes no user or device, whether inside or outside the network, should be trusted by default. All access requests are authenticated, authorized, and continuously validated.
- Core principle: 'Never trust, always verify'.
- Emphasizes micro-segmentation and granular access control.
- Helps prevent lateral movement of threats within the network.
- Requires strong identity verification and continuous monitoring.
Memory trick: Security Models: Trust Zero, Control Access, Guard Perimeter, Stop DDoS
SSL VPN Split Tunneling List
Flip cardA configuration element, typically an Access Control List (ACL) or network list, used in SSL VPNs (like Cisco AnyConnect) to define which traffic should be sent through the encrypted VPN tunnel (for internal resources) and which traffic should be sent directly to the public internet (unencrypted).
- Controls whether all traffic or only specific traffic goes through the VPN.
- Improves performance for non-corporate traffic.
- Can be a security risk if not carefully configured, allowing untunneled access to the internet while connected to the VPN.
Memory trick: Split Tunneling decides the traffic's path: Tunnel or Not!
Cisco FTD SSL Policy
Flip cardA dedicated policy within Cisco Firepower Threat Defense (FTD) that defines rules for handling SSL/TLS encrypted traffic, including whether to decrypt it for inspection, block it, or allow it to pass through without decryption.
- Enables deep packet inspection of encrypted traffic.
- Requires the FTD to act as a proxy (man-in-the-middle).
- Can apply different decryption actions based on source, destination, and certificates.
Memory trick: SSL Policy: Unlock the 'S' for Inspection!
SD-WAN Benefits
Flip cardSD-WAN optimizes WAN performance, reduces costs, and enhances security by centralizing control and intelligently routing traffic over various transport services.
- Application-aware routing for optimal path selection.
- Centralized management and policy enforcement.
- Reduced reliance on expensive MPLS links.
- Enhanced security with integrated firewall and VPN capabilities.
Memory trick: SD-WAN: Smartly Delivering Wide Area Networks.
Cisco ISE Profiling
Flip cardA Cisco Identity Services Engine (ISE) feature that collects contextual information about connected endpoints from various network sources to identify and categorize them.
- Uses probes (e.g., DHCP, HTTP, DNS, NetFlow, NMAP) to gather data.
- Creates endpoint profiles based on attributes like OS, device type, manufacturer.
- Feeds into authorization policies to assign appropriate network access.
- Essential for granular network segmentation and security.
Memory trick: ISE Processes Authenticate, Profile, Posture, Guest
Edge Computing
Flip cardA distributed computing paradigm that brings computation and data storage closer to the sources of data, reducing latency and bandwidth usage.
- Processes data near the source (e.g., IoT devices).
- Reduces latency for real-time applications.
- Optimizes bandwidth by sending only aggregated data to the cloud.
- Enhances security by processing sensitive data locally.
Memory trick: Distributed Computing: Cloud, Edge, Data, Serverless - Where's the brain?
802.1X Guest VLAN
Flip cardAn 802.1X feature that provides a temporary, restricted network access VLAN for clients that fail authentication or when the authentication server is unavailable. This allows clients to perform necessary remediation tasks before attempting full authentication.
- Assigns clients to a specific VLAN with limited access.
- Used for unauthenticated clients or when the RADIUS server is down.
- Facilitates patching, anti-virus updates, or registration for new devices.
Memory trick: If the door's locked, go to the Guest room for a fix!
Hybrid Cloud
Flip cardA cloud computing environment that uses a mix of on-premises, private cloud and third-party, public cloud services, with orchestration between the two platforms.
- Combines public and private cloud environments.
- Allows data and applications to move between environments.
- Offers flexibility for compliance, cost optimization, and scalability.
Memory trick: Cloud Models: Public, Private, Hybrid, Community - Choose your blend.
SSL VPN (Clientless)
Flip cardA type of Virtual Private Network that provides secure remote access to internal network resources using a standard web browser, eliminating the need for dedicated client software.
- Uses SSL/TLS for encryption, typically over port 443.
- Access is provided via a web portal, often to web applications, file shares, or terminal services.
- Highly compatible with various operating systems and devices due to browser-based access.
- Simpler to deploy and manage for basic remote access needs compared to client-based VPNs.
Memory trick: Remote Access: Client, Browser, or Site-to-Site?
Cisco IP SLA
Flip cardCisco IP Service Level Agreement (SLA) is a technology that allows network performance to be measured and monitored by generating synthetic traffic and collecting statistics.
- Measures network performance metrics (latency, jitter, packet loss, availability).
- Uses synthetic traffic to test specific paths or applications.
- Can be used for proactive monitoring and path selection in routing.
- Supports various operations like ICMP echo, UDP echo, HTTP, DNS, etc.
Memory trick: Troubleshooting: Ping/Tracert for basic, SNMP for health, IP SLA for path, NetFlow for traffic.
802.1X Authenticator
Flip cardA network device (e.g., switch or wireless access point) that acts as an intermediary between the supplicant and the authentication server in an 802.1X deployment.
- Forwards authentication requests (EAP messages) from the supplicant to the authentication server.
- Relays authentication responses from the server back to the supplicant.
- Enforces access control by blocking or allowing network traffic based on the authentication result.
- Typically a switch port or wireless access point.
Memory trick: SAC: Supplicant Asks, Authenticator Connects, Server Checks
Microsegmentation
Flip cardA network security technique that creates secure zones in data centers and cloud environments, allowing organizations to isolate workloads and secure them individually.
- Granular policy enforcement at the workload or endpoint level.
- Reduces the attack surface by preventing lateral movement.
- Independent of network topology (VLANs, IP addresses).
- Often implemented using SGTs, VXLAN, or host-based firewalls.
Memory trick: Segmentation: VLANs, VRFs, Micros, Firewalls - Choose your barrier.
IPsec Transform Set
Flip cardA combination of IPsec security protocols and algorithms that defines how traffic is protected in an IPsec Phase 2 Security Association (SA).
- Specifies the Authentication Header (AH) or Encapsulating Security Payload (ESP) protocol.
- Defines encryption algorithms (e.g., AES, 3DES) and hashing algorithms (e.g., SHA, MD5).
- Both VPN peers must have identical transform sets configured for Phase 2 to establish.
- Part of the crypto map configuration.
Memory trick: Phase One is Key, Phase Two is Transform
MACsec Key Agreement (MKA)
Flip cardThe protocol used by MACsec (802.1AE) to discover MACsec-capable devices, negotiate MACsec parameters, and create and manage the security keys (SAKs) for encrypting and authenticating Layer 2 traffic.
- Operates over Ethernet (Layer 2).
- Negotiates the Cipher Suite and Key Server role.
- Requires matching MKA policy parameters on both ends of the link.
- Essential for establishing and maintaining the MACsec secure channel.
Memory trick: MACsec Needs Matching MKA for Secure Links
Intent-Based Networking (IBN)
Flip cardA network management paradigm that uses machine learning and automation to translate business intent into network policies, constantly monitors the network to ensure intent is met, and proactively takes corrective action.
- Translates business intent into network configuration.
- Continuous validation and assurance of network state.
- Automated policy enforcement and dynamic adjustment.
- Requires end-to-end visibility and analytics.
Memory trick: Performance: Intent is Key to Visibility and Efficiency.
JSON Web Token (JWT)
Flip cardA compact, URL-safe means of representing claims to be transferred between two parties. The claims in a JWT are encoded as a JSON object that is digitally signed, providing integrity and authenticity, and making it self-contained.
- Composed of a header, payload, and signature.
- Digitally signed (JWS) for tamper detection and authenticity.
- Self-contained: recipient can verify claims and identity without querying a database.
- Commonly used for API authentication and authorization.
Memory trick: JWTs: Just What's Needed for Signed, Self-Contained API Trust!
Network Assurance
Flip cardThe process of continuously monitoring, analyzing, and validating network performance, security, and compliance to ensure it meets business intent.
- Proactive identification of issues before users are impacted.
- Comprehensive visibility across physical, virtual, and cloud environments.
- Leverages advanced analytics, machine learning, and automation.
- Focuses on intent validation and compliance.
Memory trick: Assurance: See all, Analyze deep, Act fast, Automate well.
Control Plane Policing (CoPP)
Flip cardA security feature that protects the router's CPU from excessive traffic destined for the control plane, such as routing updates, management protocols, and packets that require CPU processing, thereby preventing DoS attacks and maintaining router stability.
- Uses QoS policies to classify and rate-limit traffic to the CPU.
- Protects against reconnaissance, DoS, and malformed packet attacks.
- Targets traffic that is 'for' the router, not 'through' the router.
Memory trick: CoPP protects the CPU from Control Plane Chaos!
Cisco DNA Center
Flip cardCisco Digital Network Architecture (DNA) Center is a centralized network management and automation platform that provides a single pane of glass for designing, provisioning, applying policy, and assuring wired and wireless networks.
- Core component of Cisco's Intent-Based Networking (IBN).
- Automates network provisioning and policy deployment.
- Provides end-to-end visibility and assurance.
- Supports wired, wireless, and WAN domains.
Memory trick: Cisco Management: Meraki for Cloud, Prime for legacy, DNA for Intent.
IPsec Transform Set Components
Flip cardAn IPsec transform set defines how IPsec protects a particular data flow. It combines an authentication algorithm (for integrity/authenticity) and an encryption algorithm (for confidentiality) to be applied to the data.
- Specifies the combination of security protocols (ESP/AH) and algorithms.
- Authentication algorithm ensures data integrity and origin authenticity.
- Encryption algorithm ensures data confidentiality.
Memory trick: Transformations need Algorithms for Authenticity and Encryption!
DMVPN (Dynamic Multipoint VPN)
Flip cardA Cisco solution that provides a scalable and flexible way to create a full-mesh or hub-and-spoke VPN topology without requiring static configuration of every spoke-to-spoke tunnel.
- Uses mGRE (multipoint GRE) to support multiple GRE tunnels with a single interface.
- Uses NHRP (Next Hop Resolution Protocol) to discover spoke public IP addresses.
- Leverages IPsec for encryption and authentication.
- Enables dynamic spoke-to-spoke tunnels on demand, reducing hub load.
Memory trick: VPNs Connect Sites: Static, GRE, DMVPN, FlexVPN
AAA Accounting
Flip cardThe component of AAA (Authentication, Authorization, Accounting) responsible for collecting and recording information about user activities on a network device, such as services accessed, time spent, and specific commands executed, for billing, auditing, or resource utilization purposes.
- Tracks user activities after authentication and authorization.
- Records command execution, session duration, data transfer.
- Sends data to a central accounting server (e.g., RADIUS, TACACS+).
Memory trick: AAA: Authenticate, Authorize, Account for Everything!
Zero Trust Principle: Never Trust, Always Verify
Flip cardThe foundational principle of Zero Trust security, stating that no user, device, or application is implicitly trusted, regardless of its location (inside or outside the network). All access attempts must be explicitly authenticated and authorized.
- Eliminates the concept of a trusted internal network.
- Requires continuous verification for every access request.
- Forms the basis for all other Zero Trust components.
Memory trick: In Zero Trust, Trust is a Four-Letter Word!
SSL VPN for Remote Access
Flip cardA VPN technology that uses the SSL/TLS protocol to create a secure connection between a remote user and an internal network. It is highly flexible, often web-browser friendly, and can provide full network layer access.
- Utilizes standard SSL/TLS ports (e.g., 443), making it firewall-friendly.
- Supports various client types: clientless (web-based), thin client, and full tunnel client (e.g., AnyConnect).
- Ideal for remote access due to ease of deployment and broad OS compatibility.
Memory trick: Remote Users need Secure, Simple, and Standard Access!
FlexVPN IKEv2 Profile
Flip cardA configuration element in Cisco FlexVPN that defines the IKEv2 policy, authentication methods, peer identity, and client configuration parameters for VPN connections.
- Specifies local and remote authentication methods (e.g., pre-shared key, EAP, certificate).
- Identifies the remote peer (e.g., by FQDN, IP address).
- Configures client parameters such as IP address assignment, DNS servers, WINS servers.
- Links to IKEv2 proposals and IPsec profiles.
Memory trick: FlexVPN Pieces: Proposal, Profile, IPsec, Map
Software-Defined WAN (SD-WAN)
Flip cardSD-WAN is a virtual WAN architecture that allows enterprises to leverage any combination of transport services—including MPLS, LTE, and broadband internet services—to securely connect users to applications.
- Centralized control and management.
- Intelligent path selection for applications.
- Enhanced security and cost reduction.
Memory trick: SD-WAN: Smartly Directing WAN Access Now.
IKEv2 Keyring
Flip cardA configuration component in Cisco's IKEv2 setup that defines the authentication credentials used by IKEv2 peers. It specifies either pre-shared keys or references to digital certificates (trustpoints) for peer authentication.
- Stores authentication information for IKEv2 peers.
- Can be configured with pre-shared keys for specific peers or a default.
- Can point to a trustpoint for certificate-based authentication.
Memory trick: Keyrings hold the keys to IKEv2 authentication!
WLAN Deployment Models
Flip cardDifferent architectures for deploying wireless networks, each with varying levels of scalability, management complexity, and feature sets.
- Autonomous APs: Standalone, suitable for small deployments.
- Controller-based APs: Centralized management, scalability, advanced features for large enterprises.
- Cloud-managed APs: Centralized management via cloud platform, flexible, scalable.
Memory trick: WLAN Models: Connecting with APs, Control, or Cloud.