Ethernet Fundamentals Flashcards
csma/cd
carrier sense multiple access / collision detect
carrier sense: listen to the wire, check if its busy
multiple access: all devices have access to wire at any time
collision detection: if collision occurs, back off, wait random time and try again
collision domain
comprised of all devices on a shared ethernet segment
same cable or hub
switches create new collision domains, each port is their own domain
1000base-sx
mmf
1Gbps
220m
1000base-lx
mmf / smf
1Gbps / 1Gbps
550m / 5km
1000base-zx
smf
1Gbps
70km
hub
layer 1
multiport repeater
passive hub - repeats with no amplification
active hub - repeats with amplification
smart hub - active hub with enhanced features like snmp
1 collision and broadcast domain
bridge
makes intelligent forwarding decisions based on dest mac (1 port switch)
1 collision domain/port
1 broadcast domain/bridge
switch
layer 2 multiport bridge 1 collision domain/port 1 broadcast domain/switch all ports make up 1 broadcast domain *breaks up collision domains
router
layer 3 make forwarding decisions based in ip 1 collision domain/port 1 broadcast domain/port *breaks up collision and broadcast domains
layer 3 switch
layer 3 switch and router combo 1 collision domain/port 1 broadcast domain/port *breaks up collision and broadcast domains
802.3ad
link aggregation
combine multiple physical connections into a single logical connection
increase bandwidth and minimize congestion
802.3af
power over ethernet
requires cat5+
provides up to 15.4 watts
802.3at
power over ethernet +
provides up to 25.5 watts
port monitoring or mirroring
analyze packet flow over a network
network sniffer for hub
port monitoring for switch
mirroring: makes a copy of all traffic and sends it to an analyst machine
802.1x
user authentication
switches can require users to authenticate before entering network
key is generated and used to encrypt all traffic
management access and authentication
to configure and manage switches
- ssh
- console port - plug in with laptop and rollover cable
oob
out of band
keep all network devices on a separate network
first hop redundancy protocols
virtual ip and mac addr to provide an active and standby router for default gateway
vrrp (virtual router redundancy protocol) - open source
mac filering
permits or denies traffic based on mac addr
not that great but exam says you should do it
traffic filtering
multilayer switches can permit or deny traffic based on ip or ports
qos
quality of service
forward traffic based on priority markings
802.1d
stp - spanning tree protocol: permits redundant links between switches and prevents traffic loops and mac table corruption
spb - shortest path bridging is used for larger network environments
broadcast storms
if the broadcast frame is received by both switches, they forward to each other and copy and forward again …
until available bandwidth is consumed
port state cycle
link in topology goes down
non designated port detects and determines if it needs to go to forwarding state
forwarding state
1. blocking
2. listening - populate mac addr table
3. learning - process bpdu and determine role in stp
4. forwarding
link cost
speed of link
lower speed = higher cost
vlan
different logical networks with same physical hardware
more security and efficiency
assign switch ports to different broadcast domains
802.1q
vlan trunking
multiple vlans transmitting over the same physical cable
vlans are tagged with 4-byte identifier: tag protocol identifier and tag control identifier
one vlan is left untagged - native vlan
vpn
virtual private network
creates a secure virtual tunnel over an untrusted network
vpn headend
type of vnp concentrator used to terminate ipsec vpn tunnels
stateful firewall
allows traffic that originates from inside to go out to internet
blocks traffic from internet from getting into the network
ngfw
next gen firewall
conduct deep packet inspection at layer 7
detect and prevent attack
updates on latest info on threats
ids/ips
intrusion detection or prevention system
ids recognizes attacks through signatures and anomalies
ips recognizes and responds
proxy server
specialized device that makes request to an external network on behalf of client
content engine/ caching engine
performs caching functions of proxy server
content switch/ load balancer
distributes incoming requests across various servers in a farm
voip phone
a hardware device that connects to your ip network to make a connection to a call manager
ics
industrial control system
describes the different types of control systems and associated instrumentation
scada
supervisory control and data acquisition
acquires and transmits data from different systems to a central panel for monitoring and control
virtual network devices
major shift in the way data centers are designed, fielded and operated
vSwitches, vNICs