Stp Flashcards
Stp primary/secondary default values
If root > 24576 = 24.576
If root < 24476 = highest possible x of 4096
Stp def int cost
10 Gbps 2 2000
1 Gbps 4
100 Mbps 19
10 Mbps 100
Stp timers
Hello = 2
MAXage = 10 * hello
Forward delay = 15
Default BID priority
32768
802.1D port roles
Root
Designated
802.1w port roles
Root Alternate
Designated backup
Disabled
RSTP port states
Forwarding
LEARNING
DISCARDING
Stp port states
Forwarding
Listening
Learning
Blocking
Stp Root secondary default
> root
< Everything else
Default costs of routes
0 connected 1 static 20 bgp 90 eigrp 110 ospf 120 rip 200 iBGP 255 unusuable
Ospf def costs
Serial 64
Ethernet 10
Fast ethernet 1
Ospf def reference bandwidth
100.000 - 100 Mbps
Default max load balancing ospf/eigrp
4
Max etherchannel links
8
Cisco etherchannel protocol / setting
Pagp - desirable auto
Def switchport dtp setting
Auto
How to change ospf cost
- Change the bandwidth on the interface (in kbps)
- Set cost interface directly 1 - 65.535
- Change the reference bandwidth (in Mbps)
Vlan ranges
1-1005
(1002-1005 réservés)
1006-4094
VTP default settings
Server mode
Pruning disabled
Version 1
VTP requirements
Must be trunk
VTP domain and pass must match
802.1x supplicant?
Workstation
802.1x authenticator
LAN SWITCH
Ospf all routers address
224.0.0.5
Ospf Dr and bdr address
224.0.0.6
how to advertise networks for ospfv6
Activated per interface, no network commands
Ospfv3 neighbor requirements
Do not have to be in same subnet Hello dead timers must match Unique RID Same area Auth
Ospf neighbor requirements
Do not have to be in same subnet Hello dead timers must match Unique RID Same area Auth
DEFAULT OSPF TIMERS
Hello 10
Dead 40 (4x hello)
Lsa reflood 30 min
Ospf becoming neighbors routine
- A sends hello to B
- B learns of A and goes into INIT
- B sends hello to A
- A goes into 2-way state
- A sends hello to B
- A goes into 2-way state
Private IP ranges
A 10.0.0.0 /8
B 172.16.0.0 /12
C 192.168.0.0 /16
IP classes
A 1-126 /8
B 128-191 /16
C 192-223 /24
D 224-239
ACL ranges
Standard
1-99
1300-1999
Extended
100-199
200-2699
Tacacs+ kenmerken
TCP port 49 Used for network devices Encrypts pass + whole packet Can limit IOS shell per usergroup Cisco prop
RADIUS kenmerken
UDP port 1645, 1812
Used mainly for users
Encrypts only password
RFC2865
Where are VLAN commands stored?
VLAN.dat
Where are Switchport assignments stored?
Run Con
Where are VTP commands stored
VLAN.dat
EIGRP variance
Variance is a number (1 to 128), multiplied by the local best metric then includes the routes with the lesser or equal metric. The default Variance value is 1, which means equal-cost load balancing.
EIGRP/OSPF max load balancing
16
soft ospf area router limit
50
How does ospf mulit area reduce routing table and lsa db size?
Route summary
Vtp summary advertisement time
5 min
VTP: Vlan advertisement request
switch asks for a subset advertisement when the
summary advertisement has a higher revision number than itself
vtp subset advertisement
sent when VLAN configuration database has changed
K-value binary trick
10 0 / 10100
Vector
(aka direction) Next hop router and outgoing interface
Metric
measurement of distance
Metric value of infinity (rip/ospf/eigrp)
16 for RIP / 2^32 – 1 for EIGRP / 2^24-1 for OSPF
When do EIGRP partial update messages get sent
-When link fails
-When new route becomes available
(only contains new info)
EIGRP addr
224.0.0.10
Does OSPF use split horizon?
NO
EIGRP Three step model
- Neighbor discovery –> Neighbor table
- Topology exchange –> topology table
- Choosing routes , analysis of topology –> Route table
EIGRP Neighbor requirements
Authentication
Same AS number
Same Subnet
K-values must match
How are EIGRP update messages sent?
- To multicast if multiple routers need it
- To unicast for single addressee
What protocol does EIGRP use?
RTP, reliable transport protocol, can resend info in something fails
EIGRP Metric calc
((10^7 / least-bandwidth)+cum delay)*256
EIGRP Cumulative Delay
Sum of all delay values for all outgoing interfaces. In ‘Tens of microseconds’
EIGRP Least-bandwidth
lowest bandwidth link in the route expressed in Kbps
EIGRP best practices bandwidth settings
Serial links: set to actual L1 speed
LAN interfaces: use defaults
Feasible distance (FD) / Reported distance (RD)
FD= Local routers composite metric of the best route to reach a subnet
RD: Next hop router’s best composite metric
EIGRP Successor
Best route to subnet - route in routing table
Feasibility condition
If a non-successors RD is less than the FD of the current route in the routing table, the route is a feasible successor.
DUAL
Diffusing update algorithm. Used when there is no Feasible successor in EIGRP. - DUAL queries for a loop free route to a subnet and then adds it to the routing table.
EIGRP Default timers
Hello: 5 sec
Hold: 3x hello (15 )
Variance unequal route calculation
IF metric.FS < (Variance * FD )
THEN
FS added to routing table
Differences between ipv4 and 6 EIGRP
- IPv6 advertises prefixes / IPv4 subnets
- show commands use ipv6 keyword
- IPv6 neighbors don’t have to be in the same subnet
- EIGRP for IPv6 does not have an auto-summary concept
EIGRPv6 Shutdown feature
EIGRPv6 Process can be shut or no shut like an interface
Which side provides clockrate?
DCE (other side is DTE)
Serial link protocols?
HDLC (older)
PPP - additional capabilities like authentication, multilink bundles, and constant link monitoring.
Link speed standards (DS0,DS1,DS3)
DS0 - 64kbps DS1 - (T1) 1544 kbps E1 - 2048 Kbps DS3 - 44.736 kbps E3 - 34.000 kbps
Default Serial Link encapsulation?
HDLC
Why PPP?
- Definition of header and trailer
- Supports synchronous and asynchronous links
- Protocol Type field in header
- Authentication
- Support for multilink
- Control protocols for each higher layer protocol
PAP kenmerken
- Clear text pass
- device ‘being authenticated’ acts first and just sends over pass
- Authenticating device sends ack
CHAP kenmerken
- Hashed pass
- Authenticating device sends over challenge
- Other sends hashed pass
- Authenticating device sends ack
Why use MLPPP?
- Improve availability
- Cheaper
- Reduces L3 complexity
- Miltiple SE ints look like single int
- One subnet between routers
- One routing prot neighborship
- One route per destination
How does MLPPP loadbalancing work?
- Frames get fragemented (one per link)
- Smaller pieces get PPP header and trailer to manage fragmentation
- Receiving router reassembles the packet
Which commands go on PPP multilink?
- Encapsulation
- ppp multilink
- ip addr
- ppp multilink group x
Which commands go on SE interface of multilink?
- no ip addr
- encapsulation
- Authentication
- ppp multilink
- ppp multilink group x
EIGRP ipv6 is ip-address on interface necessary?
No, ipv6 enable on an interface sets the link local address automatically which is enough to form a neighbor-ship
Hold-down timer
used by RIP to specify the amount of time to wait before accepting new information when a route goes down
What is ISL
Encapsulation used by CISCO ONLY for VLAN information
What is an EIGRP active state?
It means the route is actively fucked
What is an EIGRP passive state?
A route with a working link is in a passive state
DUAL?
EIGRP
DIJKSTRA?
OPSF
Belman-ford?
RIP
Proxy-ARP
proxy device on a given network answers the ARP queries for an IP address that is not on that network. The proxy is aware of the location of the traffic’s destination, and offers its own MAC address as the (ostensibly final) destination.
Why PPPoE
ISPs use PPP for authentication (through CHAP) and the ability to assign an IP address on the other end. Internet moved to faster DSL lines that connected to ethernet interfaces. A way of transporting PPP over ethernet was needed.
PPPoE Dialer MTU setting
1492
Default MTU size
1500
PPPoE header size
8
When using a GRE Tunnel, which device is used as an outgoing interface in the routing table?
The tunnel interface
What does an internet VPN do? (2)
- Encrypts the packet
- Encapsulates with a new IP header, using IPs in the unsecured space, making the original IP unreadable
2 GRE headers?
- Header to manage the tunnel (GRE)
- Delivery header (20byte IP header) that will be used to route the packet and contains IP in unsecured internet space
What is the source address of a tunnel interface?
Address of the physical outgoing interface. Public IP - config possible with interface ID
What IP goes on the Tunnel INT?
private IP
What is the destination address of a GRE tunnel
address of the physical int on the other side of the link (unsecure IP)
Best practice GRE TUN MTU setting?
1400
Traceroute with GRE tunnel, what’s special?
Will not list any routers in the unsecured part of the route due to encapsulation.
Requirement of Destination IP on GRE tunnel
Router must have a route to destination address
does GRE use TCP or UDP?
GRE is its own transport protocol.
ACL blocking GRE?
-allow ip
-allow gre
TCP/UDP would not work
NLRI
Network Layer reachability information, advertised by BGP
iBGP
Connection between routers from the same ISPs (inside the same ASN)
eBGP
Connection between routers from different ISPs(different ASNs)
How does BGP choose the best path?
Path attributes - different facts about the network
Internet edge
connection between ISP and customer
Single homed
design with one connection between a customer and one ISP router
Dual homed
design with two or more connections between a customer and a single ISP router
Mutlihomed
design with connection between a customer and multiple ISPs
Default route to ISP, how?
- Static config
- Learned with BGP and redistributed in the network by an iGP
BGP transport protocol?
TCP port 179. Starting BGP process opens up port 179 and waits for incoming messages
Remove BGP neighbor connection
neighbor A.B.C.D. shutdown – removes the need to delete all config for that neighbor
What is a discard route?
Static discard route can be used to advertise a route with BGP when it is not in the routing table
Reason for the network command not to advertise a route in BGP?
BGP network command only advertises networks for which there is a route in the routing table.
CADA
Confidentiality (prevent mitm data access)
Authentication (verify sender)
Data Integrity
Anti-Relay (prevent MitM relay)