VLAN/ Specialized Network Devices Flashcards
VLANs
▪ Switch ports are in a single broadcast domain
▪ Allow you to break out certain ports to be in different broadcast domains
▪ Before VLANs, you had to use routers to separate departments,
functions, or subnets
▪ Allow different logical networks to share the same physical hardware
▪ Provides added security and efficiency
Before VLANs
▪ Different switches were required for each LAN for separation
Using VLANs
▪ Same switches but switch ports can be in different VLANs
VLAN Trunking (802.1q)
▪ Multiple VLANs transmitted over the same physical cable
▪ VLANs are each tagged with 4-byte identifier
● Tag Protocol Identifier (TPI)
● Tag Control Identifier (TCI)
▪ One VLAN is left untagged
● Called the Native VLAN
Virtual Private Network (VPN)
▪ Creates a secure VPN or virtual tunnel over an untrusted network like the
Internet
VPN Concentrator
Virtual private network (VPN) creates a secure, virtual tunnel network
over an untrusted network, like the Internet
▪ One of the devices that can terminate VPN tunnels is a VPN concentrator,
although firewalls can also perform this function
VPN Headend
▪ A specific type of VPN concentrator used to terminate IPSec VPN tunnels
within a router or other device
Firewalls
▪ Network security appliance at your boundary
▪ Firewalls can be software or hardware
▪ Stateful firewalls
● Allows traffic that originates from inside the network and go out
to the Internet
● Blocks traffic originated from the Internet from getting into the
network
Next-Generation Firewall (NGFW)
▪ Conducts deep packet inspection at Layer 7
▪ Detects and prevents attacks
▪ Much more powerful than basic stateless or stateful firewalls
▪ Continually connects to cloud resources for latest information on threats
Intrusion Detection or Prevention System (IDS/IPS)
▪ IDS recognizes attacks through signatures and anomalies
▪ IPS recognizes and responds
▪ Host or network-based devices
Proxy Server
▪ A specialized device that makes requests to an external network on behalf of a client
Content Engine/Caching Engine
Dedicated appliance that performs the caching functions of a proxy server
Content Switch/Load Balancer
Distributes incoming requests across various servers in a server farm
VoIP Phone
▪ A hardware device that connects to your IP network to make a
connection to a call manager within your network
Unified Communications (or Call) Manager
Used to perform the call processing for hardware and software-based IP
phones