4.5 + 4.6 mitigation, hardening Flashcards
What is a DMVPN?
Dynamic Multipoint Virtual Private Network, it is a secure network that allows permanent VPN connections to remain open without traffic needing to pass through a VPN concentrator.
flood guard
Configures a maximum number of MAC addresses and disables a port if unrecongized MACs appear.
root guard
Prevents rogue bridges from becoming the root bridge and distrupting STP.
changes interface status to root-inconsistent (listening state) if detected
BPDU guard
Bypasses listening and learning states of STP for faster convergeance, disables interfaces if it detects a BPDU frame.
DHCP snooping
IP tracking on layer 2 device, prevents rogue DHCP servers. Trusted/untrusted devices.
native VLAN
Interfaces not assigned to a specific VLAN, doesn’t add an 802.1Q header (non-trunked freames)
Data going into interfaces not assigned to a VLAN goes where?
native VLAN
default VLAN
the VLAN associated wtih an interface by default
What is the default VLAN for the native VLAN? Why is this significant?
VLAN 1
Keeps user data and mangement protocols separate.
SYN guard
prevents syn flooding in SDN
what is FIM?
File integrity monitoring.
Scans critical files in real time or on-demand such as SFC/Tripwire, makes sure it wasn’t changed
SFC/Tripwire are examples of what?
FIM
SFC/Tripwire are examples of what?
FIM
What is BPDU
Bridge Protocol Data Units are frames that contain information about the spanning tree protocol.
What can prevent a network from becoming overwhelmed with MAC address entries?
flood guard