6 - Misc LAN Topics Flashcards
What is the RFC for RADIUS?
2865
What is the IEEE protocol for LAN switch authentication to a RADIUS server?
802.1x
What protocol and port does TACACS use?
TCP 49
What protocol and port does RADIUS use?
UDP 1645 and 1812
Which protocol, TACACS or RADIUS, encrypts the entire packet?
TACACS
Which protocol, TACACS or RADIUS, performs Authorization and Accounting in addition to Authentication?
TACACS
What are the 3 things that need to be configured to use AAA?
- AAA servers
- AAA group for the servers
- AAA authentication method(s)
In 802.1x what is the supplicant?
The end-user PC.
In 802.1x what role does the switch play?
Authenticator
What does EAP stand for?
Extensible Authentication Protocol
What does EAP do?
- allows the supplicant to communicate with RADIUS AAA server.
- EAP message from PC to switch in Ethernet frame using encapsulation EAP Over LAN (EAPoL),
- then switch places EAP msg in UDP packet and forwards to the AAA server.
What is EAPoL and what does it do?
- EAP over LAN Encapsulation
- It encapsulates EAP msgs in Ethernet frames between supplicant and switch until the switchport is authorized.
How does DHCP Snooping work?
- Trusted Ports receive and allow legitimate DHCP traffic.
- DHCP Offer and ACK messages on Untrusted ports are dropped
- Switch also creates DHCP binding table for legitimate DHCP bindings. This prevents a different PC with a different MAC from spoofing a legitimate user.
What is MEC
Multichassis Etherchannel - when an access switch has two connections to two distribution switches which are aggregated. These two connections act as a single Etherchannel even though it goes to two different switches. Loc: 5430
What is the base AAA authentication config command?
aaa authentication login default (method1) (method2)
What does DORA stand for?
- Discover (client to server)
- Offer (server to client)
- Request (client to server)
- Acknowledge (server to client)
What is Switch Aggregation?
VSS
Which protocol, TACACS or RADIUS, encrypts the password?
They both do.
Which protocol, TACACS or RADIUS, encrypts the entire packet?
TACACS
What transport protocol does TACACS use?
TCP
What transport protocol does RADIUS use?
UDP
What kind of transmission is the first to be sent by a PC using DHCP?
PC sends a Broadcast
What are the steps to follow when enabling DHCP Snooping?
- enable DHCP Snooping on switch globally or by VLAN
- Configure ports likely to receive legitimate DHCP Server traffic as Trusted
- Leave remaining ports as Untrusted
What 6 things are true of a switch stack?
- single mgmt IP
- Engineer telnets/SSH to a single switch
- Single config file
- STP, CDP, VTP runs on a single switch
- Switchports all appear to belong to single switch
- Single MAC table
In a Switch Stack which switch does all the work?
The Master switch.
What are 4 features of Chassis Aggregation?
- Multichassis Etherchannel
- Active/Standby Control Plane
- Active/Active Data Plane
- Single switch management