advanced networking Flashcards
network layer
switches routes based on mac address
Datalink layer
MAC address
Network layer
IP address, where we are going to send it to . Where it is begin sent
Transport layer
How it is being sent. is about how it is going to tbe sent. TCP UDP
overhead of tcp
web browzer
TCP,
DDos attacks
Protection at multiple layers
Load balancers protect at
layer 3-4 Ddos attacks
Class A, B , C
8, 16, 24
Unicast only in AWS
no broadcast and multicast
Why create multiple subnet within aws vpc
security isolation
network addres vs host address
10.0 is the network address. . Last address we cannot used
network addres vs host address
10.0 is the network address. . Last address we cannot used for broadcast although there is no broadcast in aws.
range of address in aws
/16 to /28
Can VPC have the same network as subnet
yes
IPVC addresses are automtically assigned by AWS
It is all public. You don’t want to communicate via public?
IPV6 addresses are automtically assigned by AWS
It is all public. You don’t want to communicate via public?
::/0 equivalent to all
link local prefix fe80::/64 not routable( 169.254 on IPV4)
secondary CIDR blocks
You can add additional CIDR block to
You can add 4 additional
Total 5 CIDR.
To extend CIDR what you have
it has to be continuous
DHCP options
EC2 gets gw, ip, Dynamic host configuration protocol.
setup a DNCP option set to get control on the IP and other configuration
security group when created
does not allow anything in and everything is allowed out
security groups is linked to a resource
it is an instance level firewall but is is not the complete descrition. Seucurity groups is attached to the network adapter.. You can have multiple security groups to EIN
When do you use security group
always
NACL when
You use it when you need deny. You have to open up a wide range of ports in outbound
ephemeral ports
1024 and above till 65000.