AAA uRPF Flashcards

You may prefer our related Brainscape-certified flashcards:
1
Q

Q

A

A

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
2
Q

What are the operating ports of Radius?

A

UDP port 1812/1645 (Authentication), 1813/1646 (Accounting)

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
3
Q

Encrypt the entire payload of each packet (leaving only the RADIUS header in cleartext)

A

False, it is TACACS

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
4
Q

In Radius, Authentication and authorization are combined in one function (packet), Command logging is not supported

A

True

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
5
Q

TACACS runs on TCP port ___

A

49

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
6
Q

In TACACS, authentication, authorization, and accounting are separated

A

True

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
7
Q

Describe the sequence of configuring AAA elements

A

Configure the servers, Enable AAA - aaa new-model, Configure the lists for authentication, authorization, and accounting, Configure the lines to use the lists

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
8
Q

URPF, The ______

A

Allows the lookup to match with the default route, With strict mode, the packet only passes if it is received on the interface where the default route points, Allow default

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
9
Q

Global configuration followed by a cold reload is required to enable or disable uRPF on the router

A

True

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
10
Q

The allow self-ping option is default for loose and strict modes and cannot be disabled

A

True

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
11
Q

Command to configure URFP

A

ip verify unicast source reachable via {rx | any}

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
12
Q

The command below configures _____ mode

A

ip verify unicast source reachable via any, loose (strict would be rx)

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
13
Q

RTBH, A router called the ______ router notifies the ______ about the attack so that the traffic is dropped

A

signaling, edges

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
14
Q

How does RTBH source-based work?

A

Uses BGP Signaling + uRPF to drop packets originating from attackers, This way, the attacked IP remains available for legitimate sources, Operation:, The attacker(s) IP(s) must be identified, uRPF must be active on interfaces where the attack might be coming from, Upstream facing or customer facing interfaces, When the traffic is received on the router, it will undergo a lookup, and in the RIB, the next hop interface for the IP or block will be null0, thus uRPF will drop the traffic

How well did you know this?
1
Not at all
2
3
4
5
Perfectly