Implementing and Operating Cisco Enterprise Network Core Technologies (ENCOR) v1.2 flashcards
163 free flashcards. Tap a card to flip it.
MAC Address Security (Port Security)
Flip cardA switch feature that restricts input to an interface by limiting and identifying the MAC addresses of devices allowed to access the port, preventing unauthorized MAC address spoofing.
- Binds MAC addresses to specific switch ports.
- Can be configured to statically or dynamically learn MAC addresses.
- Offers various violation modes (shutdown, restrict, protect) when an unauthorized MAC is detected.
Memory trick: MACs stick to their own ports, no sharing allowed!
OAuth 2.0 with JWTs for API Security
Flip cardAn open standard for delegated authorization (OAuth 2.0) often used with JSON Web Tokens (JWTs) to securely grant clients access to protected resources on behalf of a user, providing authentication and authorization for REST APIs.
- OAuth 2.0 defines roles (resource owner, client, authorization server, resource server) and grant types.
- JWTs are self-contained, digitally signed tokens containing claims about the user and permissions.
- JWTs ensure authenticity and integrity through cryptographic signing.
- Provides a scalable and flexible solution for securing REST APIs.
Memory trick: API Security: Basic, Key, or OAuth Token
IP SLA One-Way Measurements
Flip cardThe ability of certain IP SLA operations (like UDP Jitter) to measure performance metrics (latency, jitter, packet loss) in each direction independently, requiring an initiator and a responder.
- Crucial for identifying asymmetric network issues.
- Requires an IP SLA responder on the target device.
- UDP Jitter is a primary operation for one-way metrics.
Memory trick: One-way UDP Jitter needs two ends, to measure each path, where the data extends.
EEM Syslog Event Detector
Flip cardAn Embedded Event Manager (EEM) event detector that triggers an EEM applet when a specific syslog message pattern is matched.
- Monitors syslog messages for predefined patterns.
- Enables automated responses to critical system events.
- Uses regular expressions for pattern matching.
Memory trick: EEM listens for Timers, Syslog, SNMP, and more, to automate tasks and help you soar.
IP SLA UDP Jitter
Flip cardAn IP SLA operation that measures one-way latency, two-way latency (round-trip time), jitter, and packet loss for UDP traffic between a source and a responder.
- Requires an IP SLA responder on the target device.
- Provides granular metrics for real-time application performance.
- Useful for voice and video quality assessment.
Memory trick: Ping (ICMP) checks reach, Jitter (UDP) checks flow, HTTP checks web, DNS checks name, all for network show.
Cisco DNA Center Client 360 View
Flip cardClient 360 View in Cisco DNA Center Assurance provides a comprehensive, single-pane-of-glass perspective of an individual client's connectivity, performance, and health across the wired and wireless network.
- Shows real-time and historical client data.
- Includes details like RSSI, SNR, retransmissions, associated AP, authentication status.
- Essential for deep-dive troubleshooting of specific client connectivity issues.
Memory trick: Client 360: Get the 'Whole Picture' of a Client's Troubles.
Troubleshooting Firewall Blocks
Flip cardThe process of identifying if and why a firewall is preventing specific network traffic from reaching its destination.
- Firewalls block based on IP, port, protocol, state.
- Logs are critical for 'denied' messages.
- Packet captures show traffic flow and drops.
Memory trick: Logs are truths, captures show path, traceroute finds hop, but ping's a narrow wrath.
Switched Port Analyzer (SPAN)
Flip cardA Cisco feature that allows mirroring traffic from source ports or VLANs to a destination port on the same switch for analysis.
- Local traffic mirroring
- One-to-one or many-to-one port mapping
- Does not forward mirrored traffic itself, only copies it
Memory trick: SPAN is your local traffic spy, RSPAN crosses switches, ERSPAN goes far, NetFlow just counts cars.
DNA Center Client Experience Score
Flip cardA metric in Cisco DNA Center Assurance that provides an aggregated view of end-user Wi-Fi performance, considering various factors directly impacting client connectivity and application usage.
- Aggregates multiple client-centric metrics.
- Factors include onboarding, connectivity, and application performance.
- Aims to quantify the quality of the wireless user's interaction.
Memory trick: Client Experience: Onboarding's key, apps must fly, signal strong, not just the wired tie.
SNMP Trap
Flip cardAn unsolicited message sent by an SNMP agent to an SNMP manager when a significant event occurs on the agent's device.
- Proactive notification mechanism.
- Used for critical events or threshold breaches.
- Does not require the manager to poll the agent.
Memory trick: Get to fetch, Set to change, Walk to explore, Trap for events - that's the SNMP core.
SNMP Polling and Traps
Flip cardSNMP (Simple Network Management Protocol) is used to manage network devices. Polling involves a manager periodically requesting data from agents, while traps are unsolicited messages sent by agents to managers upon significant events.
- Polling gathers current state data (e.g., CPU, memory).
- Traps provide immediate notifications for critical events or threshold breaches.
- Requires an SNMP manager and agents configured on network devices.
Memory trick: SNMP: See Network Metrics, Send Notifications Promptly.
IP SLA Path Echo
Flip cardIP SLA Path Echo is an operation that sends a sequence of ICMP echo messages to trace the network path between a source and destination, measuring round-trip time and providing hop-by-hop latency statistics.
- Uses ICMP echo messages similar to traceroute but with more detailed metrics.
- Provides hop-by-hop latency and path information.
- Useful for diagnosing routing loops, asymmetric routing, and path performance issues.
Memory trick: IP SLA Path Echo: Inspect Paths, Pinpoint Problems, Precisely.
Wireless Interference Sources
Flip cardFactors that disrupt wireless signals, categorized as co-channel interference (from other Wi-Fi devices) or non-Wi-Fi interference (from external sources like microwaves or cordless phones).
- Non-Wi-Fi interference can be highly disruptive.
- Spectrum analysis tools help identify interference sources.
- Proper AP placement and power levels mitigate co-channel interference.
Memory trick: Interference? Look around first! Then power, then channels, then DHCP, if it's still hurting, you see.
Local SPAN (LSPAN) VLAN Source
Flip cardLocal SPAN (LSPAN) allows mirroring traffic from source ports or VLANs to a destination port on the same switch. When a VLAN is configured as the source, all traffic flowing within that VLAN (ingress and egress) is mirrored.
- Source and destination must be on the same switch.
- Can mirror traffic from individual ports or entire VLANs.
- Destination port should be dedicated to the monitoring device.
Memory trick: SPAN: Set the Source, Pick the Port, See the Packets.
Cisco DNA Center Client 360
Flip cardA feature within Cisco DNA Center Assurance that provides a holistic, real-time view of an individual wireless client's performance, connectivity, and experience.
- Client-centric troubleshooting.
- Shows detailed metrics like RSSI, data rates, association status.
- Integrates data across wired and wireless domains for a single client.
Memory trick: Client 360 sees all, RRM optimizes, CleanAir finds noise, AP groups roll call.
Virtual Switch Port Mirroring
Flip cardA feature on virtual switches (like VMware vSwitch or Cisco Nexus 1000V) that duplicates network traffic from source ports/VLANs to a destination port for monitoring and analysis.
- Essential for troubleshooting and security analysis of intra-host VM traffic.
- Can mirror traffic from specific VMs, port groups, or uplinks.
- Often configured to send mirrored traffic to a virtual appliance for analysis (e.g., IDS/IPS).
Memory trick: Port Mirroring: See All Traffic Clearly.
MPLS Layer 3 VPNs
Flip cardA highly scalable and secure network virtualization technology that creates isolated Layer 3 VPNs over a shared MPLS backbone, commonly used by service providers.
- Uses VRFs at provider edge (PE) routers for customer isolation.
- Enables overlapping IP address spaces between different customers.
- Provides traffic forwarding based on labels, improving scalability and performance.
Memory trick: MPLS L3 VPNs: Massive Private Links, Securely.
SR-IOV
Flip cardSingle Root I/O Virtualization (SR-IOV) is a PCI Express (PCIe) standard that allows a single PCIe physical function (PF) to be shared among multiple virtual machines (VMs) as virtual functions (VFs), providing direct hardware access for improved I/O performance and reduced CPU overhead.
- Bypasses hypervisor for I/O.
- Provides near-native performance.
- Reduces CPU utilization on the hypervisor.
Memory trick: Speedy SR-IOV Slices, Hypervisor's Headache Solved.
Virtual Routing
Flip cardVirtual routing refers to the capability of virtualized environments to provide Layer 3 forwarding services, typically through a virtual router appliance or a routing function integrated into a distributed virtual switch. This enables communication between virtual machines residing in different IP subnets.
- Enables Layer 3 communication between VMs in different subnets.
- Can be a dedicated virtual appliance or a DVS feature.
- Essential for inter-subnet connectivity in virtualized environments.
Memory trick: Different Subnets, Need a Router's Blueprint.
NFV Elasticity
Flip cardThe ability of Network Function Virtualization (NFV) to dynamically scale network functions (VNFs) up or down based on changing network demands.
- Achieved through resource pooling and automated orchestration.
- Decouples network functions from proprietary hardware.
- Enables efficient resource utilization and cost savings.
Memory trick: NFV: Network Functions Virtualized for Flexibility.
VXLAN
Flip cardVXLAN (Virtual eXtensible LAN) is a network virtualization encapsulation protocol that creates Layer 2 overlay networks on top of a Layer 3 infrastructure. It extends VLAN capabilities, supporting up to 16 million logical network segments (VNIs) and enabling large-scale multi-tenancy and mobility in data centers.
- Layer 2 overlay over Layer 3.
- Scales to 16 million logical networks (VNIs).
- Enables large-scale multi-tenancy and VM mobility.
Memory trick: VXLAN: Vast X-tended LAN, Virtualized for X-tra tenants.
Cisco Nexus 1000V VSM
Flip cardThe Virtual Supervisor Module (VSM) is the control plane component of the Cisco Nexus 1000V distributed virtual switch. It runs as a virtual appliance and provides centralized management, configuration, and advanced networking features for all connected Virtual Ethernet Modules (VEMs) on hypervisors.
- Control plane for Nexus 1000V.
- Centralized management.
- Runs as a virtual appliance.
Memory trick: VSM is the Brain, VEMs are the Brawn.
VRF-Lite
Flip cardVRF-Lite (Virtual Routing and Forwarding-Lite) is a technology that allows multiple independent routing tables to coexist on the same physical router, enabling Layer 3 isolation for different tenants or services without requiring MPLS.
- Provides Layer 3 isolation.
- Each VRF instance has its own routing table, forwarding table, and interfaces.
- Does not require MPLS, making it 'Lite'.
Memory trick: Route your Virtual Routes, Forwarding Lite.
Virtual PortChannel (vPC)
Flip cardA Cisco Nexus technology that allows two Nexus switches to form a single logical PortChannel from the perspective of a downstream device.
- Enables active-active forwarding and bandwidth aggregation across two physical switches.
- Eliminates Layer 2 loops without blocking links.
- Provides redundancy for dual-homed servers or network devices.
Memory trick: vPC: Virtual PortChannels Create Redundancy.
VRF-Lite for Multi-tenancy
Flip cardA feature on Cisco routers that enables logical separation of routing and forwarding functions, allowing multiple independent routing instances to coexist on one physical device.
- Each VRF maintains its own routing table, FIB, and connected interfaces.
- Provides Layer 3 isolation for multi-tenant environments.
- Does not require MPLS, making it 'Lite'.
Memory trick: VRF-Lite: Virtual Routes for isolated tenants without MPLS.
DVS Service Chaining
Flip cardDistributed Virtual Switch (DVS) Service Chaining is a capability that allows administrators to define a sequence of network services (e.g., firewall, load balancer, IDS) that traffic must traverse. This enables virtual network appliances to inspect and process inter-VM traffic on the same hypervisor, optimizing traffic flow and enforcing policies.
- Redirects traffic to virtual network appliances.
- Enables inspection of inter-VM traffic on the same host.
- Optimizes traffic flow by keeping it local to the hypervisor.
Memory trick: DVS Chains Services, VMs See No Outside Walls.
VXLAN (Virtual eXtensible LAN)
Flip cardA network virtualization encapsulation protocol that extends Layer 2 network segments over a Layer 3 IP network.
- Encapsulates Ethernet frames in UDP, typically on port 4789.
- Uses a 24-bit VXLAN Network Identifier (VNI) for scalability (up to 16 million segments).
- Enables large-scale multi-tenancy and VM mobility across Layer 3 boundaries.
Memory trick: VXLAN: Virtual eXtensible LANs bridge Layer 2 over Layer 3.
Distributed Virtual Switch (DVS) Dataplane
Flip cardThe component of a DVS that performs the actual forwarding of network traffic for virtual machines, including inter-host and external network connectivity.
- Handles Layer 2 forwarding of Ethernet frames.
- Operates on each physical host, executing forwarding decisions from the control plane.
- Responsible for encapsulating/decapsulating traffic for network virtualization overlays (e.g., VXLAN).
Memory trick: DVS Planes: Control, Management, Data - CMD for your network flight.
Virtual Load Balancer
Flip cardA software-based network function that distributes incoming network traffic across multiple servers to optimize resource utilization, maximize throughput, and ensure high availability.
- Runs as a virtual appliance on a hypervisor.
- Performs health checks on backend servers.
- Can provide advanced features like SSL offloading and content switching.
Memory trick: VNFs: Virtual Network Functions are Very Needed.
Virtual Firewall
Flip cardA software-based firewall instance that runs on a virtualized platform, providing dedicated security services for virtualized environments.
- Offers granular security policies per application or tenant.
- Runs on a hypervisor or as a virtual appliance on a physical firewall.
- Enables multi-tenancy and efficient resource utilization for security.
Memory trick: Virtual Firewalls: Dedicated Security for Virtual Apps.
Virtual Device Context (VDC)
Flip cardA technology on Cisco Nexus switches that allows a single physical switch to be partitioned into multiple logical switches, each operating independently.
- Provides full separation of control, data, and management planes.
- Each VDC can have its own interfaces, VLANs, and routing instances.
- Enhances multi-tenancy and resource isolation on Nexus platforms.
Memory trick: Nexus VDCs: Virtual Devices Create Separation.
Network Function Virtualization (NFV)
Flip cardNetwork Function Virtualization (NFV) is an architectural concept that virtualizes entire classes of network node functions into building blocks that can be chained together to create communication services. It decouples network functions (e.g., firewalls, load balancers) from proprietary hardware appliances.
- Decouples network functions from hardware.
- Enables flexible deployment and scalability.
- Reduces CAPEX and OPEX.
Memory trick: NFV: Network Functions, Virtually Flexible.
Private VLAN (PVLAN) in Virtual Switching
Flip cardA virtual switching feature that provides Layer 2 isolation between ports or VMs within the same VLAN, restricting communication.
- Uses primary, isolated, and community VLAN types for granular control.
- Isolated ports can only communicate with the primary VLAN uplink.
- Community ports can communicate with each other and the primary VLAN uplink.
Memory trick: PVLANs: Private VLANs Lock Down VM Communication.
802.1X Multi-Domain Authentication (MDA)
Flip cardAn 802.1X switch port mode that allows an IP phone and a single data device (like a PC) to authenticate separately on the same port.
- Supports both voice and data authentication on one port.
- IP phone authenticated to the voice VLAN, PC to the data VLAN.
- Requires separate MAC addresses for each device.
Memory trick: How many and who gets in through the 802.1X door?
MACsec (802.1AE)
Flip cardA security standard that provides hop-by-hop, Layer 2 encryption and authentication for Ethernet frames.
- Operates at the Data Link Layer (Layer 2).
- Secures point-to-point Ethernet links.
- Uses AES-GCM for encryption and integrity.
Memory trick: Each network layer has its own bodyguard.
Clientless SSL VPN
Flip cardA type of SSL VPN that provides remote access to network resources, primarily web-based applications, using only a standard web browser without requiring dedicated client software.
- Uses HTTPS for secure communication.
- Ideal for external partners or contractors.
- Provides access to web applications, file shares (through web interface), and sometimes limited network access.
Memory trick: Remote friends need a VPN door.
Reconnaissance Attack
Flip cardThe preparatory phase of an attack where an attacker gathers information about a target network, system, or organization.
- Aims to map network, identify vulnerabilities, discover services.
- Often uses tools like Nmap, SNMP queries, DNS lookups, port scans.
- Precedes exploitation phase.
Memory trick: Attackers first 'look around,' then 'break in,' then 'take control.'
IPsec Authentication Header (AH)
Flip cardAn IPsec protocol that provides connectionless data integrity, data origin authentication, and an anti-replay service.
- Does not provide confidentiality (encryption).
- Authenticates the entire IP packet (except mutable fields).
- Identified by IP Protocol number 51.
Memory trick: IPsec has two main bodyguards: one for a full suit of armor, one for a stealth cloak.
OAuth 2.0 Access Token
Flip cardA credential issued by an authorization server to a client application, allowing it to access protected resources on behalf of a user.
- Used for delegated authorization, not authentication.
- Short-lived and typically opaque to the client.
- Presented to the resource server to gain access.
Memory trick: OAuth is like getting a temporary key (access token) from a doorman (IdP) to enter a specific room (resource server) on behalf of a friend.
IKEv2 Proposal Parameters
Flip cardA set of cryptographic parameters proposed during IKEv2 negotiation, including encryption, integrity, PRF, and Diffie-Hellman group.
- Must match between peers for IKEv2 SA to form.
- Defines security for the IKEv2 control plane.
- Different from IPsec transform-set parameters (data plane).
Memory trick: An IKEv2 proposal is like a 'secret handshake' with specific steps and tools.
Cisco AnyConnect SSL VPN
Flip cardA client-based SSL VPN solution that provides full Layer 3 network access for remote users to an enterprise network.
- Requires a client application on the end-user device.
- Uses SSL/TLS for secure communication.
- Offers granular access control and strong authentication.
Memory trick: Remote workers need a secure 'Any' path to 'Connect' to the office.
DMVPN NHRP Redirect
Flip cardAn NHRP message type sent by the DMVPN hub to a spoke, informing it of the real (public) IP address of another spoke, enabling direct spoke-to-spoke IPsec tunnels.
- Initiated by the hub.
- Facilitates direct spoke-to-spoke communication.
- Optimizes data path by bypassing the hub.
Memory trick: The DMVPN hub is like a matchmaker, redirecting spokes to each other.
AAA Authorization
Flip cardThe AAA component that determines what an authenticated user is permitted to do on a network resource.
- Occurs after successful authentication.
- Defines access rights and permissions.
- Can be rule-based or role-based.
Memory trick: AAA is like a security guard, a bouncer, and a time clock.