6 - Misc LAN Topics Flashcards
What is the RFC for RADIUS?
2865
What is the IEEE protocol for LAN switch authentication to a RADIUS server?
802.1x
What protocol and port does TACACS use?
TCP 49
What protocol and port does RADIUS use?
UDP 1645 and 1812
Which protocol, TACACS or RADIUS, encrypts the entire packet?
TACACS
Which protocol, TACACS or RADIUS, performs Authorization and Accounting in addition to Authentication?
TACACS
What are the 3 things that need to be configured to use AAA?
- AAA servers
- AAA group for the servers
- AAA authentication method(s)
In 802.1x what is the supplicant?
The end-user PC.
In 802.1x what role does the switch play?
Authenticator
What does EAP stand for?
Extensible Authentication Protocol
What does EAP do?
- allows the supplicant to communicate with RADIUS AAA server.
- EAP message from PC to switch in Ethernet frame using encapsulation EAP Over LAN (EAPoL),
- then switch places EAP msg in UDP packet and forwards to the AAA server.
What is EAPoL and what does it do?
- EAP over LAN Encapsulation
- It encapsulates EAP msgs in Ethernet frames between supplicant and switch until the switchport is authorized.
How does DHCP Snooping work?
- Trusted Ports receive and allow legitimate DHCP traffic.
- DHCP Offer and ACK messages on Untrusted ports are dropped
- Switch also creates DHCP binding table for legitimate DHCP bindings. This prevents a different PC with a different MAC from spoofing a legitimate user.
What is MEC
Multichassis Etherchannel - when an access switch has two connections to two distribution switches which are aggregated. These two connections act as a single Etherchannel even though it goes to two different switches. Loc: 5430
What is the base AAA authentication config command?
aaa authentication login default (method1) (method2)