2.6 - DNS Configuration, DHCP Configuration, VLANs and VPNs Flashcards

1
Q

DNS

A

Domain name system

Human readable names to computer readable IPs

Hierarchical
-follow path

Distributed database
-many DNS servers
-13 root server clusters (over 1,000 actual servers)
-hundreds of gTLDs (generic top level domains) (ex: .com, .org, .net, etc)
-275+ ccTLDs (country code top level domains) (ex: .us, .ca, .uk, etc)

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
2
Q

DNS records

A

RR (resource records)
-database records of DNS

30+ record types
-IPs, certs, host alias names, etc

Important + critical configs
-check settings, backup, and test

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
3
Q

Address records

A

A or AAAA

Defines IP of host
-most popular query

A records = for IPv4 addresses
-modify A record to change host name to IP resolution

AAAA records = for IPv6 addresses
-same DNS server, different records

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
4
Q

Mail exchanger record (MX)

A

Determines host name for mail server
-NOT an IP address -> just a name

IN MX mail.mydomain.name.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
5
Q

Text records (TXT)

A

Human readable text info
-useful public info

Can be used for verification
-if u have access to DNS then u must be the admin of the domain name

Usually used for email security
-external email servers validate info from ur DNS

nslookup

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
6
Q

Sender policy framework (SPF)

A

SPF protocol
-list of all servers authorized to send emails for the domain
-prevents mail spoofing
-mail servers perform check to see if incoming mail actually came from an authorized host

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
7
Q

Domain keys identified mail (DKIM)

A

Digitally sign a domain’s outgoing mail
-mail servers validate (not typically seen by end user)
-public key = in DKIM TXT record

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
8
Q

DMARC

A

Domain based message authentication, reporting, and conformance
-prevents spoofing
-extension of SPF + DKIM

You decide what external email servers should do with emails that don’t validate through SPF or DKIM
-policy written into DMARC TXT record
-accept all, send to spam, or reject email
-compliance reports can be sent to email administrator

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
9
Q

DHCP Configuration - Scope properties

A

IP range
- and excluded addresses

Subnet mask

Lease durations

Other scope options
-DNS server
-default gateway
-VOIP servers

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
10
Q

DHCP Pools (DHCP config)

A

Grouping of IP addresses
-each subject has own scope
-192.168.1.0/24
-192.168.2.0/24
-192.168.3.0/2
-etc

Scope = generally contiguous pool of IPs
-DHCP exceptions can be made inside scope

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
11
Q

DHCP address assignment (DHCP config)

A

Dynamic assignment
-DHCP server has big pool of addresses to give out
-addresses reclaimed after lease period

Automatic reassignment
-similar to dynamic allocation
-DHCP server has list of past assignments
-you’ll always get same IP address

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
12
Q

DHCP address allocation (DHCP config)

A

Address reservation
-administratively configured

Table of MAC addresses
-each MAC address has matching IP address

Other names
-static DHCP assignment
-static DHCP
-static assignment
-IP reservation

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
13
Q

DHCP leases (DHCP config)

A

Leasing your address
-temporary
-can seem permanent

Allocation
-assigned lease time by DHCP server
-administratively configured

Reallocation
-reboot computer
-confirms lease

Workstation can manually release IP address
-moving to another subnet

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
14
Q

DHCP renewal (DHCP config)

A

T1 timer
-Check in with lending DHCP to renew IP address
-50% of the lease time (by default)

T2 timer
-if original DHCP is down, try rebinding with any DHCP server
-87.5% of lease time (7/8ths)

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
15
Q

LANs

A

Local area networks

Group of devices in same broadcast domain

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
16
Q

Virtual LANs

A

Virtual local area networks

Group of devices in same broadcast domain

Separated logically, not physically

17
Q

Configuring VLANs

A

Virtual local area networks

Group of devices in same broadcast domain

VLAN 1: Gate room
VLAN 2: Dialing room
VLAN 3: Infirmary

18
Q

VPNs

A

Virtual private networks
-encrypted data traversing a public network

Concentrator
-encryption/decryption access device
-often integrated into firewall

Many deployment options
-specialized cryptographic hardware
-software based options available

Used with client software
-sometimes built into OS

19
Q

Client to site VPNs

A

On demand access from remote device
-software connect to VPN concentrator

Some software can be configured as always on