predefined policies and roles Flashcards

1
Q

What policies are used in ip access-list session allowall

A

any any any permit

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
2
Q

What policies are used in access-list session control

A
user any udp 68 deny
any any svc-icmp permit
any any svc-dns permit
any any svc-papi permit
any any svc-cfgm-tcp permit
any any svc-tftp permit
any any svc-dhcp permit
any any svc-natt permit
How well did you know this?
1
Not at all
2
3
4
5
Perfectly
3
Q

What policies are used in access-list session captiveportal

A
user alias mswitch svc-https dst-nat 8081
user any svc-http dst-nat 8080
user any svc-https dst-nat 8081
user any svc-http-proxy1 dst-nat 3182
user any svc-http-proxy2 dst-nat 8080
user any svc-http-proxy3 dst-nat 8088
How well did you know this?
1
Not at all
2
3
4
5
Perfectly
4
Q

What policies are used in access-list session cplogout

A

user alias mswitch svc-https dst-nat 8081

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
5
Q

What policies are used in access-list session vpnlogon

A
any any svc-ike permit
any any svc-esp permit
any any svc-l2tp permit
any any svc-pptp permit
any any svc-gre permit
How well did you know this?
1
Not at all
2
3
4
5
Perfectly
6
Q

What policies are used in access-list session ap-acl

A
any any udp 5000
any any udp 5555
any any svc-gre permit
any any svc-syslog permit
any user svc-snmp permit
user any svc-snmp-trap permit
user any svc-ntp permit
How well did you know this?
1
Not at all
2
3
4
5
Perfectly
7
Q

What policies are used in access-list session validuser

A

any any any permit

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
8
Q

What policies are used in access-list session vocera-acl

A

any any svc-vocera permit queue high

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
9
Q

What policies are used in access-list session icmp-acl

A

any any svc-icmp permit

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
10
Q

What policies are used in access-list session sWhat policies are used in -acl

A

any any svc-sip-udp permit queue high

any any svc-sip-tcp permit queue high

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
11
Q

What policies are used in access-list session https-acl

A

any any svc-https permit

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
12
Q

What policies are used in access-list session dns-acl

A

any any svc-dns permit

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
13
Q

What policies are used in access-list session logon-control

A
user any udp 68 deny
any any svc-icmp permit
any any svc-dns permit
any any svc-dhcp permit
any any svc-natt permit
How well did you know this?
1
Not at all
2
3
4
5
Perfectly
14
Q

What policies are used in access-list session srcnat

A

user any any src-nat

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
15
Q

What policies are used in access-list session skinny-acl

A

any any svc-sccp permit queue high

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
16
Q

What policies are used in access-list session tftp-acl

A

any any svc-tftp permit

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
17
Q

What policies are used in access-list session dhcp-acl

A

any any svc-dhcp permit

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
18
Q

What policies are used in access-list session http-acl

A

any any svc-http permit

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
19
Q

What policies are used in access-list session svp-acl

A

any any svc-svp permit queue high

user host 224.0.1.116 any permit

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
20
Q

What policies are used in access-list session noe-acl

A

any any svc-noe permit queue high

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
21
Q

What policies are used in access-list session h323-acl

A

any any svc-h323-tcp permit queue high

any any svc-h323-udp permit queue high

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
22
Q

What is the ip access-list session allowall

A

permits all traffic

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
23
Q

What is the ip access-list session control

A

Controls traffic

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
24
Q

What is the ip access-list session captiveportal

A

Enables captive Portal authentication

25
Q

What is the ip access-list session cplogout

A

Enables Captive portal log-out window

26
Q

What is the ip access-list session vpnlogon

A

permits vpn sessions

27
Q

What is the ip access-list session ap-acl used for

A

permits aps to communicate with the controller - internal use - no modify

28
Q

What is the ip access-list session validuser used for

A

use to restrict foreign ip address from being added to user table. Not applied to any user role - internal system policy

29
Q

What is the ip access-list session vocera-acl used for

A

automatically permit and prioritize Vocera traffic.

30
Q

What is the ip access-list session icmp-acl used for

A

permits all icmp traffic

31
Q

What is the ip access-list session sWhat is the ip-acl used for

A

automatically permit and prioritize all SIP control and data traffic.

32
Q

What is the ip access-list session https-acl used for

A

permits https traffic

33
Q

What is the ip access-list session dns-acl used for

A

permits dns traffic

34
Q

What is the ip access-list session logon-control used for

A

pre-authentication role to be used by all wireless clients. Prohibits clients from acting as dhcp server

35
Q

What is the ip access-list session srcnat used for

A

used to source-nat all traffic

36
Q

What is the ip access-list session skinny-acl used for

A

automatically permit and prioritize Cisco skinny SCCP VoIP traffic

37
Q

What is the ip access-list session tftp-acl used for

A

permits all tftp traffic

38
Q

What is the ip access-list session dhcp-acl used for

A

Permits all DHCP traffic

39
Q

What is the ip access-list session http-acl used for

A

Permits all HTTP traffic.

40
Q

What is the ip access-list session svp-acl used for

A

automatically permit and prioritize Spectralink Voice Protocol

41
Q

What is the ip access-list session noe-acl used for

A

automatically permit and prioritize NOE traffic

42
Q

What is the ip access-list session h323-acl used for

A

automatically permit and prioritize H.323 traffic

43
Q

What policies are used in user-role default-vpn-role

A

session-acl allowall

44
Q

What policies are used in the user-role voice

A
session-acl sip-acl
session-acl noe-acl
session-acl svp-acl
session-acl vocera-acl
session-acl skinny-acl
session-acl h323-acl
session-acl dhcp-acl
session-acl tftp-acl
session-acl dns-acl
45
Q

What policies are used in the user-role guest

A
session-acl http-acl
session-acl https-acl
session-acl dhcp-acl
session-acl icmp-acl
session-acl dns-acl
46
Q

What policies are used in the user-role guest-logon

A

captive-portal default
session-acl logon-control
session-acl captiveportal

47
Q

What policies are used in the user-role -guest-logon

A

captive-portal default
session-acl logon-control
session-acl captiveportal

48
Q

What policies are used in the user-role authenticated

A

session-acl allowall

49
Q

What policies are used in the user-role logon

A

session-acl logon-control
session-acl captiveportal
session-acl vpnlogon

50
Q

What policies are used in the user-role -logon

A

session-acl control
session-acl captiveportal
session-acl vpnlogon

51
Q

What policies are used in the user-role default-vpn-role

A

This is the default role used for VPN-connected clients. It is referenced in the default “aaa authentication vpn” profile.

52
Q

What policies are used in the user-role voice

A

This role can be applied to voice devices in order to automatically permit and prioritize all VoIP protocols.

53
Q

What policies are used in the user-role guest

A

This is a default role for guest users.

It permits only HTTP, HTTPS, DHCP, ICMP, and DNS for the guest user

54
Q

What policies are used in the user-role guest-logon

A

This role is used as the pre-authentication role for guest SSIDs.
It allows control traffic such as DNS, DHCP, and ICMP, and also enables captive portal

55
Q

What policies are used in the user-role ssid-guest-logon

A

Role is only generated when creating a new WLAN using the WLAN Wizard
Auto Created when captive portal is enabled

56
Q

What policies are used in the user-role authenticated

A

This is a default role that can be used for authenticated users

57
Q

What policies are used in the user-role logon

A

This is a system role that is normally applied to a user prior to authentication.
This applies to wired users and non-802.1x wireless users.

58
Q

What policies are used in the user-role ssid-logon

A

The role allows certain control protocols such as DNS, DHCP, and ICMP, and also enables captive portal and VPN termination/pass through. The logon role should be edited to provide only the required services to a pre-authenticated user

59
Q

What policies are used in the user-role ssid-captiveportal-profile

A

WLAN Wizard and you do not have a PEF NG
This implicit user role allows only DNS and DHCP traffic between the client and network and directs all HTTP or HTTPS requests to the captive portal.
You cannot directly modify the implicit user role or its rules