1/30
Comprehensive vocabulary flashcards focused on FortiSwitchOS functions, including DHCP security, VLAN management, routing mechanisms, and FortiLink protocols.
Name | Mastery | Learn | Test | Matching | Spaced | Call with Kai | Chat |
|---|
No analytics yet
Send a link to your students to track their progress
switch-controller-dhcp-snooping-verify-mac
A feature that verifies the destination MAC address match the learned MAC addresses in DHCP packets to protect against DHCP exhaustion attacks.
DHCP Option 82
Information used for agent information (Circuit ID and Remote ID) to assist in policy and billing; configuration is only available via the Command Line Interface (CLI).
Quarantine VLAN
A specific VLAN used to isolate devices that do not meet network security criteria, such as those failing 802.1X authentication.
DHCP Snooping Trust Model
Enforces a model where ports facing legitimate DHCP servers must be marked 'trusted' and edge ports marked 'untrusted' to prevent rogue DHCP server messages.
SNMP v2c Requirements
Requires activating the SNMP agent on the FortiSwitch and configuring community strings which function as passwords for authentication.
FortiLink Interface
A dedicated interface required on a FortiGate to manage communication, control, and policy enforcement for a connected FortiSwitch stack.
Native VLAN
The default internal ID assigned to any untagged frames arriving at a switch port; only one can be assigned per port.
Allowed-VLANs List
A configuration on a port that filters ingress and egress tagged frames; if a VLAN ID is not on this list, the switch drops the tagged frame.
Untagged VLAN List
A list that specifies VLANs for which the port will transmit egress frames without the 802.1Q tag.
LLDP-MED Inventory Management TLV
Used to retrieve hardware characteristics from endpoints, including manufacturer, software version, hardware version, and serial numbers.
Traffic Processing ACL Actions
Actions such as count, drop, redirect (to another port), and mirror that dictate the physical handling of a matched frame.
IGMP Snooping Querier
Manages multicast traffic by sending queries to find group memberships; active receiver entries age out based on these periodic queries.
Non-supplicant Failure Handling
Occurs when a device lacks 802.1X support; after the Guest authentication delay (default 30 seconds), the device is placed in the Guest VLAN.
Tail-drop mode
A congestion management behavior where the switch drops all incoming packets once a queue reaches its maximum capacity until space becomes available.
Prelookup ACL Stage
The earliest stage in the switching pipeline where ACLs are processed before any Layer 2 or Layer 3 lookups are performed.
Two-tier Routing Lookup
A mechanism where FortiSwitch first checks the hardware routing table (ASIC) and then falls back to the Forwarding Information Base (FIB) in the kernel.
MCLAG (Multichassis Link Aggregation Group)
Allows two FortiSwitch units to operate as a single logicalAggregation peer, creating a loop-free topology without relying exclusively on STP.
Switch Virtual Interface (SVI)
A virtual interface assigned to a VLAN with an associated IP address that can participate in Layer 3 inter-VLAN dynamic routing.
Broadcast Ethernet Frame
A frame with a destination MAC address set to FF:FF:FF:FF:FF:FF, resulting in Layer 2 flooding to all ports in a VLAN domain.
Virtual Domains (VDOMs)
Independent virtual firewalls within a FortiGate used to segment network operations and the multi-tenant administration of managed FortiSwitch devices.
FortiLink over VXLAN
A method used to deploy managed FortiSwitch units at remote sites by tunneling Layer 2 traffic over a Layer 3 WAN underlay.
FortiLink Heartbeat
A continuous keepalive mechanism where a managed FortiSwitch sends Type 5 packets to the FortiGate to verify management tunnel health.
VLAN 4094
The reserved VLAN ID used exclusively for FortiLink management and control-plane traffic between FortiGate and FortiSwitch.
VLAN 4095
The reserved VLAN ID automatically assigned when a physical port is converted into a Routed VLAN Interface (RVI).
802.1X MAC-based Authentication
Authentication mode that treats each MAC address as a distinct session, allowing different access levels for multiple devices on one port.
Loop Guard MAC-Move Detection
An enhancement that monitors for MAC flapping events across ports or VLANs to detect loops beyond the native VLAN.
IGMP Snooping Proxy
A feature that handles IGMP reports locally, only forwarding a join when the first member arrives and a leave when the last member departs a group.
Hardware-based Routing
Routing decisions performed at wire speed directly in the switch ASIC using a hardware-programmed Forwarding Information Base (FIB).
Sniffer Profile
A persistent packet capture method that allows administrators to capture traffic across all switch ports, trunks, and management interfaces simultaneously.
Virtual Port Pool (VPP)
A pool of physical switch ports that can be virtualized and distributed across different VDOMs for multi-tenant isolation.
DAI (Dynamic ARP Inspection)
A Layer 2 security feature that intercepts ARP packets on untrusted ports and validates them against the trusted DHCP snooping database.