Network Operations Flashcards
Device/Chassis sensors
Abnormal values can signal a problem
Bandwidth
Amount of network use over time.
Excessive bandwidth could signal lack of available space, etc.
Latency
A delay between request and response.
High latency signals a problem.
Jitter
The time between frames. Excessive jitter can cause choppy calls/video.
SNMP
Simple Network Management Protocol.
On a network, devices run an SNMP Agent that responds to queries (or just sends information to) from an SNMP Manager (a server).
SNMP Traps
SNMP OIDs
Object Identifiers. Statistics about devices, example: How many bytes have gone into a router interface?
SNMP MIBs
Management Information Bases. A database of information that you can query for info (MIB II). Some proprietary MIBs also exist.
Syslog
Message logging protocol that creates a consolidated log. Stored in a central logging receiver (SIEM)
Logging Levels/Severity Levels
- Emergency
- Critical
- Major
- Minor
- Warning
- Notice
- Info
- Trace
- Debug
Speed/Duplex
Must match on both ends of a link.
CRC errors
Typically caused by bad cable or interface.
Giants
Frames that are more than 1518 bytes (when not using jumbo frames). Can indicate a communication problem.
Runts
Frames that are less than 64 bytes - can be the result of a collision.
Encapsulation Errors
Mismatch between switch tagging configurations (ISL / 801.2Q)
Netflow Data
Gathers traffic statistics from all traffic flows. Consists of a probe and a collector. The probe collects data and sends it to the collector.
Change Management
Clear policies to document a change to a device/ configuration, etc.
Incident Response Plan
How to respond to security incidents:
Preparation
Detection/Analysis
Containment, Eradication, and Recovery
Post-Incident Activity