Less-Specific Routes of a Network's Own Aggregate
A specific rule of routing states that, for the sake of preventing routing loops, a network must not follow a less-specific route for a destination that matches one of its own aggregated routes. A routing loop occurs when traffic circles back and forth between network elements, never reaching its final destination. Default routes 0.0.0.0/0 are a special case of this rule. A network should not follow the default route to reach destinations that are part of its aggregated adver..
Using Multiple Authentication Methods
AAA authentication allows reference to multiple servers and to multiple authentication methods so that a user can be authenticated even if one authentication method is not working. The aaa authentication command supports up to four methods on a single command. Additionally, there is no practical limit to the number of RADIUS or TACACS+ servers that can be referenced in a RADIUS or TACACS+ server group. The logic used by Cisco IOS when using these methods is as follows: ■ U..
WAN Aggregation Router QoS Design
A fictitious company, ABC, Inc., already correctly is classifying and marking (at Layer 3 via DSCP) all 11 classes of traffic from the QoS Baseline Model within its campus. It wants to provision QoS policies for each of these application classes over its WANs as well. ABC, Inc., selected ATM as its primary Layer 2 medium because of its ease of expansion for future bandwidth needs. Each remote branch is connected to the main campus by dual-T1 links (at a minimum), with some l..
Cisco Security Agent and Host-Based IDS
CSA provides threat protection for servers and PCs. CSA identifies and prevents malicious behavior, thereby eliminating known and unknown security risks. Typically, devices with antivirus software do not detect the latest worms or code violations. CSA fills in this gap by triggering an alert to the system or the management server any time an application or packet tries to use the kernel inside a Windows-based system. CSA also blocks the attack. CSA can be installed as a stand..
There are many different ways to configure two routers to allow Token Ring to Token Ring bridging through DLSw. The most common reason for doing this is to allow Token Ring SNA LLC2 devices to communicate with a mainframe Front End Processor (FEP) attached to another Token Ring. It is relatively common to have many remote rings connecting to a single central ring. In cases like this, it is often best to use one or more dedicated DLSw routers at the central location. The CPU o..



