CH 6 & 7 Flashcards
feature where If BPDUs show up where they should not, the switch protects itself.
BPDU Guard
Controls which ports are not allowed to become root ports to remote
root switches
root guard
Limits the number of MAC addresses to be learned on an access
switch port
port security
Prevents rogue DHCP servers from impacting the network.
DHCP snooping
Prevents spoofing of Layer 2 information by hosts.
dynamic arp inspection
Prevents spoofing of Layer 3 information by hosts
IP Source Guard
you can authenticate
users before allowing their data frames into the network
802.1x
Limits the amount of broadcast or multicast traffic flowing through
the switch
storm control
Used for traffic control and to enforce policy
ACL’s
a security feature that acts like a firewall between untrusted hosts and
trusted DHCP servers
DHCP snooping
intercepts, logs, and discards ARP packets with invalid IP-to-MAC address bindings
DAI (dynamic arp inspection)
breaking the infrastructure down into smaller components and then
systematically focusing on how to secure each of those components
Network Foundation Protection
(NFP)
what 2 features can be used to protect the control plane
CoPP and CPPr
uses UDP port 123, and it allows network devices to
synchronize their time
NTP
This feature maintains a secure working copy of the router IOS image and the startup configuration files at all times. Once the
feature is enabled, the administrator cannot disable it remotely (but can if connected directly
on the console)
Secure Bootset
IPv6 link local addresses begin with what?
FE80
How many bits in an IPv6 Addrss
128
What characters are added to the 48 bit MAC address to arrive at a 64 bit host ID in a link local IPv6 address
FFFE
::1 what type of IPv6 address is this?
Link local (same as 127.0.0.1in IPv4)
The IPv6 multicast group that all IPv6 devices join is
FF02::1
In addition to the multicast group address of FF02::1
that is joined by all devices configured for IPv6, routers that have had routing enabled
for IPv6 also join which multicast group?
FF02:2
Global
IPv6 unicast addresses have the first four characters in the range of ?
2000 - 3FFF