© 2015 Mohamed Samir YouTube channel All rights reserved. Samir Part V: Monitoring Campus Networks
© 2015 Mohamed Samir YouTube channel All rights reserved. Samir Logging Switch Activity
© 2015 Mohamed Samir YouTube channel All rights reserved. Samir SNMP
© 2015 Mohamed Samir YouTube channel All rights reserved. Samir IP SLA
© 2015 Mohamed Samir YouTube channel All rights reserved. Samir Monitor Session
© 2015 Mohamed Samir YouTube channel All rights reserved. Samir Using Local SPAN Switched Port Analyzer (SPAN) to analyze a port one or more VLANs on the switch, you can identify the VLANs as the SPAN source called VLAN-based SPAN or VSPAN.
© 2015 Mohamed Samir YouTube channel All rights reserved. Samir Remote SPAN
© 2015 Mohamed Samir YouTube channel All rights reserved. Samir Part VI: Implementing High Availability
© 2015 Mohamed Samir YouTube channel All rights reserved. Samir
© 2015 Mohamed Samir YouTube channel All rights reserved. Samir Layer 3 High Availability
© 2015 Mohamed Samir YouTube channel All rights reserved. Samir Hot Standby Router Protocol HSRP HSRP is a Cisco proprietary protocol RFC 2281 The routers exchange HSRP hello messages at regular intervals multicast destination (“all routers”) using UDP port group number, from 0 to 255 most Catalyst switches support only up to 16 unique HSRP group numbers HSRP groups are locally significant only on an interface. If all router priorities are equal highest IP address on the HSRP interface becomes the active By default, hellos are sent every 3 seconds.
© 2015 Mohamed Samir YouTube channel All rights reserved. Samir Gateway Load Balancing Protocol
© 2015 Mohamed Samir YouTube channel All rights reserved. Samir Securing VLANs
© 2015 Mohamed Samir YouTube channel All rights reserved. Samir Private VLANs VTP does not pass any information about the private “locally significant to a switch” You must configure each physical switch port that uses a private VLAN Promiscuous: The switch port connects to a router, firewall, or other common gateway device. Host: The switch port connects to a regular host that resides on an isolated or community VLAN. The port communicates only with a promiscuous port or ports on the same community VLAN.
© 2015 Mohamed Samir YouTube channel All rights reserved. Samir Securing VLAN Trunks VLAN Hopping Switch(config)# vlan 800 Switch(config-vlan)# name bogus_native Switch(config-vlan)# exit Switch(config)# interface gigabitethernet 1/0/1 Switch(config-if)# switchport trunk encapsulation dot1q Switch(config-if)# switchport trunk native vlan 800 Switch(config-if)# switchport trunk allowed vlan remove 800 Switch(config-if)# switchport mode trunk
© 2015 Mohamed Samir YouTube channel All rights reserved. Samir Preventing Spoofing Attacks
© 2015 Mohamed Samir YouTube channel All rights reserved. Samir Managing Switch Users
© 2015 Mohamed Samir YouTube channel All rights reserved. Samir AAA Authentication: Who is the user? Authorization: What is the user allowed to do? Accounting: What did the user do? AAA functions that are centralized, standardized, resilient, and flexible. Cisco switches can use the following two protocols to communicate with AAA servers: TACACS+: A Cisco proprietary secure and encrypted over TCP port 49 RADIUS: A standards-based uses UDP ports 1812 and 1813 (accounting), but is not completely encrypted
© 2015 Mohamed Samir YouTube channel All rights reserved. Samir Switching certificate Exam