📝 Section Review: Security
اہم نکاتKey TakeawaysKey Takeaways
- 802.1X پورٹ-بیسڈ نیٹ ورک ایکسس کنٹرول دیتا ہے: supplicant سوئچ (authenticator) کے ذریعے RADIUS سرور سے authenticate ہوتا ہے۔ MAB supplicant-less ڈیوائسز کو MAC address سے کور کرتا ہے۔802.1X port-based network access control deta hai: supplicant switch (authenticator) ke zariye RADIUS server se authenticate hota hai. MAB supplicant-less devices ko MAC address se cover karta hai.802.1X gives port-based network access control: the supplicant authenticates through the switch (authenticator) to a RADIUS server. MAB covers devices without a supplicant, using MAC addresses.
- MACsec (802.1AE) وائر پر hop-by-hop ٹریفک encrypt کرتا ہے۔ trusted links پر استعمال کریں جہاں full VPN بغیر encryption چاہیے۔MACsec (802.1AE) wire par hop-by-hop traffic encrypt karta hai. Trusted links par use karein jahan full VPN baghair encryption chahiye.MACsec (802.1AE) encrypts traffic hop-by-hop on the wire. Use it on trusted links where you want encryption without a full VPN.
- AAA بنیادیات: نیٹ ورک ایکسس کے لیے RADIUS، ڈیوائس admin کے لیے TACACS+ with command authorization۔ ڈیوائسز harden کریں: صرف SSH، banners، unused services بند، مضبوط passwords۔AAA basics: network access ke liye RADIUS, device admin ke liye TACACS+ with command authorization. Devices harden karein: sirf SSH, banners, unused services band, mazboot passwords.AAA basics: RADIUS for network access, TACACS+ for device admin with command authorization. Harden devices: SSH only, banners, disable unused services, strong passwords.
- CoPP CPU کی طرف جانے والے ٹریفک کو police کر کے کنٹرول پلین کی حفاظت کرتا ہے۔ data-plane ACLs ٹرانزٹ ٹریفک فلٹر کرتی ہیں۔ دونوں کے کام الگ رکھیں۔CoPP CPU ki taraf jane wale traffic ko police kar ke control plane ki hifazat karta hai. Data-plane ACLs transit traffic filter karti hain. Dono ke kaam alag rakhein.CoPP protects the control plane by policing traffic to the CPU. Data-plane ACLs filter transit traffic. Never mix the two jobs.
- VPN آپشنز: fixed tunnels کے لیے سائٹ-ٹو-سائٹ IPsec، dynamic hub-and-spoke یا spoke-to-spoke کے لیے DMVPN، private WAN پر ٹریفک encrypt کرنے کے لیے GETVPN۔VPN options: fixed tunnels ke liye site-to-site IPsec, dynamic hub-and-spoke ya spoke-to-spoke ke liye DMVPN, private WAN par traffic encrypt karne ke liye GETVPN.VPN options: site-to-site IPsec for fixed tunnels, DMVPN for dynamic hub-and-spoke or spoke-to-spoke, GETVPN for encrypting traffic across a private WAN.
خود جانچ (مشق)Self-Check (Practice)Self-Check (Practice)
یہ مشقی سوالات ہیں، امتحانی سوالات نہیں۔These are practice questions, not exam questions.These are practice questions, not exam questions.
❓ 802.1X کے تین roles کے نام بتائیں۔802.1X ke teen roles ke naam batayen.Name the three 802.1X roles.
Supplicant (کلائنٹ)، authenticator (سوئچ)، authentication server (RADIUS)۔Supplicant (client), authenticator (switch), authentication server (RADIUS).Supplicant (the client), authenticator (the switch), authentication server (RADIUS).
❓ MAB کب استعمال کرتے ہیں؟MAB kab use karte hain?When do you use MAB?
ان ڈیوائسز کے لیے جن میں 802.1X supplicant نہیں — printers، cameras، phones — انہیں MAC address سے authenticate کریں۔Un devices ke liye jin mein 802.1X supplicant nahi — printers, cameras, phones — unhein MAC address se authenticate karein.For devices with no 802.1X supplicant — printers, cameras, phones — authenticate them by MAC address.
❓ RADIUS اور TACACS+ میں فرق؟RADIUS aur TACACS+ mein farq?RADIUS vs TACACS+?
RADIUS نیٹ ورک ایکسس کے لیے (802.1X، VPN)؛ TACACS+ ڈیوائس administration کے لیے، per-command authorization کے ساتھ۔RADIUS network access ke liye (802.1X, VPN); TACACS+ device administration ke liye, per-command authorization ke saath.RADIUS is for network access (802.1X, VPN); TACACS+ is for device administration with per-command authorization.
❓ CoPP کس کی حفاظت کرتا ہے؟CoPP kis ki hifazat karta hai?What does CoPP protect?
کنٹرول پلین — ڈیوائس کا CPU۔ CoPP کنٹرول/management ٹریفک کو rate-limit کرتا ہے تاکہ attacks روٹنگ protocols کو روک نہ سکیں۔Control plane — device ka CPU. CoPP control/management traffic ko rate-limit karta hai taake attacks routing protocols ko rok na sakein.The control plane — the device CPU. CoPP rate-limits control/management traffic so attacks cannot starve routing protocols.