Domain 6: Networks Flashcards
Permanent Virtual Circuit (PVC)
Connection between endpoints where carrier configs routes, speeds, etc.
Switched Virtual Circuit (SVC)
Dynamically configed circuit routes when circuit is used. Less expensive.
Layer 2 Forwarding (L2F)
Created by cisco. Tunnels that don’t require encryption. Mostly Dialup. Port 1701
IPSEC IKE use
exchanging symmetric key
IPSEC AH
Sender authentication & integrity
IPsec ESP
“Encrypts the packet.”
IPsec Security Association
SA. Agreed-upon symmetric algorithm
Bastion hosts
Hardened and permit external access. aka DMZ hosts
MAC limiting
Max number of MAC addresses that can be learned on a specific interface or all interface.
SPI
Stateful Packet Inspection
Clipping level
Level above baseline that generates an alarm
IDS/IPS Behavior based detection
Monitoring deviations from baseline
IDS/IPS Signature based detection
Monitors based on previously determined signatures
IDS/IPS Anomaly-based detection
Behavior based with automated baseline adjustment
IDS/IPS Heuristic based detection
Learning system that uses algorithms to make decisions. Can be inaccurate and fast.