Home > ccie resources > BGP Command

802.1X Authentication Using EAP

Switches can use IEEE 802.1X to perform user authentication, rather than the types of device authentication performed by many of the other features described in this section. User authentication requires the user to supply a username and password, verified by a RADIUS server, before the switch will enable the switch port for normal user traffic. Requiring a username and password prevents the attacker from simply using someone else’s PC to attack the network without first br..

Multicast Listener Discovery Protocol

RFC 2710 defines specifications for the Multicast Listener Discovery (MLD) protocol. MLD is derived from IGMPv2 and is designed for IPv6. The operation of MLD is similar to IGMPv2. The major differences between IGMPv2 and MLD are as follows: ■ All the multicast devices on a subnet use a special IPv6 link-local address as their source address in their communication to other multicast devices. The use of the link-local source address prevents the MLD packet from traveling be..

Point-to-Point Protocol

The two most popular Layer 2 protocols used on point-to-point links are High-Level Data Link Control (HDLC) and Point-to-Point Protocol (PPP). The ISO standard for the much older HDLC does not include a Type field, so the Cisco HDLC implementation adds a Cisco-proprietary 2-byte Type field to support multiple protocols over an HDLC link. PPP includes an architected Protocol field, plus a long list of rich features. Table 17-5 points out some of the key comparison points of t..

Advanced Security Concepts

A wealth of security concepts have been covered in the previous chapters; now, you are ready to look at some of the techniques that are used to secure areas of your network that are vulnerable to attacks, in particular the demilitarized zone (DMZ). The DMZ is defined as an isolated part of the network that is easily accessible to hosts outside of the network, such as the Internet. Figure 6-1 displays a typical network design where a DMZ is defined with a number of bastion h..

Loop Guard

 Suppose that a switch port is receiving BPDUs and the switch port is in the Blocking state. The port makes up a redundant path; it is blocking because it is neither a root port nor a designated port. It will remain in the Blocking state as long as a steady flow of BPDUs is received. If BPDUs are being sent over a link but the flow of BPDUs stops for some reason, the lastknown BPDU is kept until the Max Age timer expires. Then that BPDU is flushed, and the switch thinks..

Contact Us

86-136-2222-6316
CALL ME NOW

© 2011 CathaySchool, an ANDA Technology Group company, All Rights ReservedPrivacy Policy | Refund Policy | Disclaimer | Sitemap | Resources Tags