1/14
Looks like no tags are added yet.
Name | Mastery | Learn | Test | Matching | Spaced |
---|
No study sessions yet.
Infrastructure layer/data plane
Processes network frames and packets
Forwarding/trunking/encrypting/NAT
Does the heavy-lifting
Control layer/control plane
Manages the actions of the data plane
Routing/session/NAT tables
Application layer/management plane
Configuring and managing a device
SSH, a browser, API, etc.
SD-WAN
Everything used to be in one data center⦠now itās distributed across multiple locations/the cloud
Application aware
SD-WANs know which app is in use, and makes routing decisions based on that
Zero-touch provisioning
Remote equipment is automatically configured to know where to reach any service no matter its location/no matter what changes are made
Transport agnostic
No matter what medium is used for connection, the SD-WAN can connect you to any service
Ex. fiber, 5G, DSL, modem, etc.
Central policy management
All SD-WAN network configs are made to all devices via one centralized management console
No need to go to each individual router
Data center interconnect (DCI)
Multiple data centers are connected together
Apps can be distributed anywhere at any time without worrying about IP addresses/routing/connectivity/etc.
Virtual Extensible LAN (VXLAN)
Supports thousands of customers across the world
Can support 16 million virtual networks
These virtual networks are connected to each other via a layer 3 (routing) network
VXLAN Process
An original ethernet frame from one data center is encapsulated by a VXLAN, UDP, and IP header
It would think itās just going over an ethernet connection⦠nope! Itās being sent across the internet to a completely different data center!
Itās decapsulated at the other data center
Zero-touch architecture
Every user/device/etc. is inherently untrusted
Least privilege access
Only the minimum amount of access is given to people to complete their jobs, nothing more
Policy-based authentication
Uses adaptive identity
Location/organizational relationship/role/connection type/IP address/etc. are all being considered
Authenticating from inside the org building vs. from another country over VPN
Secure Access Service Edge (SASE)
A next-gen, cloud-based āVPNā
Moves security tech into the cloud where app data is
Clients are installed on all devices and security process is automated; no action needed