Cisco SONA Layers
Network Infrastructure Vlrtuallzation Network Infrastructure Vlrtuallzation Intelligent Information Network - Intelligent Information Network - The SONA framework brings forth the notion that the network is the common element that connects and enables all components of the IT infrastructure. The SONA outlines these three layers of the IIN The networked infrastructure layer This is where all the IT resources are interconnected across a converged network foundation. The IT resources include...
Users on a segment share upstream and downstream bandwidth
A headend CMTS communicates with cable modems located in subscriber homes. In addition, a headend incorporates a computer system with databases for providing Internet services to cable subscribers. In a modern HFC network, typically 500 to 2000 active data subscribers are connected to a certain cable network segment, all sharing the upstream and downstream bandwidth. The actual bandwidth for Internet service over a CATV line can be up to 27 Mbps on the download path to the subscriber, and about...
Student Guide
Editorial, Production, and Graphic Services 07.21.06 Cisco Systems, Inc. 170 West Tasman Drive San Jose, CA 95134-1706 USA www.cisco.com Tel 408 526-4000 800 553-NETS (6387) Fax 408 526-4100 Cisco Systems International BV Haarlerb ergp ark Haarlerbergweg 13-19 1101 CH Amsterdam The Netherlands www-europe.cisco.com Tel 31 0 20 357 1000 Fax 31 0 20 357 1100 Cisco Systems, Inc. 170 West Tasman Drive San Jose, CA 95134-1706 USA www.cisco.com Tel 408 526-7660 Fax 408 527-0883 www.cisco.com Tel +65...
- A CPE router can connect multiple users via a single ADSL connection using Natpat and DHCP
- Administratively Down State for an ATM Interface
- ADSL operation and performance is influenced by different impairments
- Advanced Monitoring - 2 3
- Advanced Options
- After the Introduction of the PHP
- AH Authentication and Integrity
- Allocating Labels
- AM radio interference
- Asymmetric Encryption RSA
- Authenticate Peer Identity
- Backing Up a WAN Connection with an IPsec VPN
- Backing Up a WAN Connection with an IPsec VPN Example Using GRE over IPsec
- Backup GRE Tunnel Information
- Bandwidth versus distance
- Basic MPLS Concepts Example
- Basic MPLS Features
- Before the Introduction of the PHP
- BGP that supports address families other than IPv4 addresses is called multiprotocol Bgp Mpbgp
- Building the IP Routing Table
- Cable System Benefits
- Cable System Components
- Cable System Standards
- CAP Modulation
- CEF Switching Review
- Cisco Easy VPN Server Configuration Tasks for the Easy VPN Server Wizard
- Cisco Enterprise Architecture
- Cisco Hierarchical Network Model
- Cisco Icons and Symbols
- Cisco IOS Platform Switching Mechanisms
- Cisco Router and SDM
- Cisco SDM Features
- Cisco SONA Framework
- Ciscoproprietary PPPoA
- Clients are preconfigured with a set of IKE policies and IPsec transform sets
- Commonly Used Hash Functions
- Component Architecture of LSR
- Configuration Example
- Configuration of a Cisco Router as the PPPoE Client
- Configuration of a PPPoE Client
- Configuration of a Static Default Route
- Configuration of the Dsl Atm Interface
- Configure a connection to the Internet through dialup networking
- Configure a DHCP Server
- Configuring GRE over IPsec Siteto Site Tunnel Using SDM
- Configuring GRE over IPsec Siteto Site Tunnel Using SDM Cont
- Configuring MPLS on a Frame Mode Interface
- Configuring MPLS on a Frame Mode Interface Example - 2
- Configuring the CPE as the PPPoE Client over the ATM Interface
- Configuring the MTU Size in Label Switching
- Connection between subscriber and CO
- Connection Settings
- Control Plane Components Example
- Course Flow
- CPE receives an IP address via IPCP like in the dial model
- Creating a Custom IKE Policy
- Creating Users
- Data Cable Technology Issues
- Data circuits are offloaded from the voice switch
- Data over ADSL
- Dead Peer Detection
- Debug PPP Authentication
- Default GRE Characteristics - 2
- Determine if the PPPoE connect phase is successful
- Determining the Layer to Troubleshoot Cont
- Diffie Hellman Key Exchange - 2
- Diffie Hellman Key Exchange Cont
- Digital certificates
- Docsis
- DSL Distance Limitations
- DSL Variants Examples
- Each customer requires a dedicated router at each POP
- Enabling AAA - 2
- Endto End Routing Information Flow
- Enterprise Architecture Framework
- ESP Protocol
- Example Configuring the PPPoE Dialer Interface
- Example DHCP Server Configuration
- Example Integrated Services for Secure Remote Access
- Example PAT Configuration
- Failure Detection
- Failures
- Fiber Benefits
- Five Steps of IPsec
- Frame Mode MPLS
- Functions of LSRs
- Further Label Allocation
- General Parameters
- Generic Routing Encapsulation
- GRE over IPsec
- GRE over IPsec Characteristics
- HFC Architecture
- How DPD and Cisco IOS Keepalive Features Work
- HSRP for Head End IPsec Routers
- HSRP Operation
- IKE authentication method
- IKE Policy
- IKE Proposals - 2
- Info
- Intelligent Information Network
- Interim Packet Propagation
- Introducing Secure GRE Tunnels
- Introducing the Sdm Vpn Wizard Interface
- IP lookup is performed only oncein the ingress PE router
- Psec and NAT The Problem
- Psec Characteristics
- Psec Headers
- Psec NAT Traversal
- Psec quick mode completes the connection
- Psec Security Features
- Psec Stateful Failover Cont
- Psec Stateful Failover Example
- Psec Transform Sets
- Is Data Being Received from the ISP
- Is included in PIX Firewall version 50 and later
- Is PPP Negotiating Successfully
- Key Lengths of Symmetric vs Asymmetric Encryption Algorithms
- Label Allocation in a Frame Mode MPLS Environment
- Label Distribution and Advertisement
- Label Format
- Label Stack
- Launching the Siteto Site VPN Wizard Cont
- Layer 1 Issues
- Layer 2 Issues
- Layer Troubleshooting
- Learner Skills and Knowledge
- Learner Skills and Knowledge Cont
- LIB and LFIB Setup
- List backup VPN servers to be used in case the primary VPN server is not reachable
- Lists active IPsec security associations
- Local User Database Adding Users
- Local User Management
- Major Components of MPLS Architecture
- Manageable manual configuration
- Maximum distance
- Maximum distance is achieved at lowest data rate
- Message Authentication and Integrity Check Using Hash
- Microfilters at customer premises
- Mode config Push Config and Xauth User Authentication
- Mode Configuration
- Modem terminating DSL and enduser PC with PPPoE client
- Module Objectives - 2 3
- Module Self Check
- Module Self Check Answer - 2 - 2
- Module Summary - 2 3
- Module Summary Cont - 2
- Monitor Tunnel Operation - 2
- Monitoring Easy VPN Server
- Mpls label protocol [tdp ldp both
- Mpls Vpn Architecture
- Mpls Vpn Architecture Terminology
- Mpls Vpn Routing Requirements
- Multiplecarrier modulation technique
- Objectives - 2 3 4 5 6 7 8 9 10 11 12 13 14 15
- Only sites are provisioned not links between them
- Operating costs are reduced
- Option 1 Local Router Configuration
- Option 1 Local User Database
- Option 1 Single Source and Destination Subnet - 2
- Option 1 Static Routing
- Option 2 Dynamic Routing Using EIGRP
- Option 2 External Location via RADIUS
- Option 2 External Location via Radius Cont
- Option 2 External User Database via RADIUS
- Option 2 Using an ACL
- Option 3 Dynamic Routing Using OSPF
- Optional compression
- Optional GRE Extensions
- Optionally tie a VPN connection to a dialup connection defined in the Networking section of Windows
- Overlay VPNs Frame Relay Example
- Overview - 2 3 4 5 6 7
- Packet Propagation Across an MPLS Network
- PE Router Architecture
- Peertopeer VPN
- Peerto Peer VPNs
- Penultimate Hop Popping
- Phase 15 is optional IKE Phase
- PKI Credentials
- PKI Environment
- Populating the LFIB Table
- PPPoA
- PPPoA Sample Configuration
- PPPoE Sample Configuration
- PPPoE vs PPPoA
- Propagation of Routing Information Across the PNetwork
- Proper PPP Negotiation
- Provides framework for authenticating and securing of data
- Quick mode
- Quick Setup
- Receiving Label Advertisement
- Redundancy
- References - 2 3 4
- Remote Access Using Cisco Easy VPN
- Remote Connection Topologies
- Remote Site Requirements
- Requires knowledge of Cisco Ios Cli commands
- Restrictions for Stateful Failover for IPsec
- Routing Information
- Routing Table
- Run backbone IGP with the PE routers and exchange information about global subnetworks core links and loopbacks
- SA Lifetime
- Security Associations
- Security Level of Cryptographic Algorithms
- Select Interface for Terminating IPsec
- Sets IP address to be negotiated with the remote peer using IPCP
- Siteto Site IPsec Configuration Apply VPN Configuration
- Siteto Site IPsec Configuration Phase
- Siteto Site VPN Components
- Siteto Site VPN Components Cont
- Slow upstream for undemanding data requests
- Split Tunneling
- Standard IP Switching Review
- Step 1 Interesting Traffic
- Step 1 The VPN Client Initiates the IKE Phase 1 Process
- Step 2 IKE Phase
- Step 3 IKE Phase
- Step 3 The Cisco Easy VPN Server Accepts the SA Proposal
- Step 5 The Mode Configuration Process Is Initiated
- Step 5 Tunnel Termination
- Step 6 The RRI Process Is Initiated
- Step 7 IPsec Quick Mode Complts the Connection
- Stepby Step Setup
- Subscriber end CPE for DSL connection and PPP session termination
- Summary - 2
- Summary Cont - 2 3 3 4 5 6 7 8 9 10
- Symmetric Encryption 3DES
- Symmetric Encryption DES
- Symmetric vs Asymmetric Encryption Algorithms
- Task 1 Install Cisco VPN Client
- Task 2 Create a New Client Connection Entry - 2
- Task 2 Create a New Client Connection Entry Cont
- Task 3 Configure Client Authentication Properties
- Task 4 Configure Transparent Tunneling
- Test Tunnel Configuration and Operation - 2
- Test Tunnel Configuration and Operation Cont
- The Challenge of Connecting the Teleworker
- The Challenges
- The MPLS Conceptual Model
- The PE router appears as another router in the Cnetwork
- The Procedure to Configure MPLS
- The Teleworker Components
- This design cannot support all topologies required by the customer
- Transform - 2
- Transform Set
- Troubleshooting - 2
- Tunnel and Transport Mode
- Use the Cisco VPN Client to Establish a VPN Connection and Verify the Connection Status
- Using DPD and Cisco IOS Keepalive Features with Multiple Peers in the Crypto
- Using preshared keys Initiate aggressive mode Using digital certificates Initiate main mode
- Using the VPN label assigned by the egress PE router as the second label in the stack
- Usually not needed
- Verify DHCP Clients
- Verify how IP addresses are translated on the router
- Verify PAT
- Verify the existing DHCP bindings on the router DHCP server
- Verifying a PPPoE Configuration
- Verifying a PPPoE Configuration Cont
- Via IPCP
- VoIP Service Example
- VoIP Service Example Connectivity Requirements
- VPN Authentication Information
- VPN Taxonomy
- VPN Wizards
- What Are Cisco IOS Platform Switching Mechanisms
- What Are the VPN Implementation Technologies
- What is Cable
- X509 v3 Certificate
- Xauth Options

