Cisco CCNA 200-301 Definitive Study Guide

TCP/IP and OSI Networking Models

Networking models provide a structure for communication between devices. While the CCNA 200-301 exam references the RFC 1122 four-layer TCP/IP model, a five-layer variant is commonly used to separate physical and data-link functions.

Layer Comparison and Protocol Data Units (PDUs)
Layer5-Layer ModelPDUExample Protocols / Equipment
5ApplicationDataHTTPHTTP, FTPFTP, DNSDNS
4TransportSegmentTCPTCP, UDPUDP
3Network / InternetPacketIPIP. Operating device: Router
2Data-LinkFrameEthernetEthernet, 802.11802.11. Operating device: Switch
1PhysicalBit / SymbolUTPUTP, Fiber. Operating device: Hub

Ethernet LAN Fundamentals

Ethernet standards define physical cabling and speed. Media include Unshielded Twisted Pair (UTPUTP) and fiber optic cables (Single-mode or Multimode).

Physical Layer Standards
  • 10BASE-T10BASE\text{-}T: 10 Mb/s10\,Mb/s, 100 m100\,m range, UTP Cat 3UTP\,Cat\,3.
  • 100BASE-T100BASE\text{-}T: 100 Mb/s100\,Mb/s, 100 m100\,m range, UTP Cat 5UTP\,Cat\,5.
  • 1000BASE-T1000BASE\text{-}T: 1 Gb/s1\,Gb/s, 100 m100\,m range, UTP Cat 5eUTP\,Cat\,5e.
  • 10GBASE-T10GBASE\text{-}T: 10 Gb/s10\,Gb/s, 100 m100\,m range, UTP Cat 6aUTP\,Cat\,6a.
  • Fiber Standards: 10GBASE-SR10GBASE\text{-}SR (300 m300\,m, Multimode), 10GBASE-LR10GBASE\text{-}LR (10 km10\,km, Singlemode), 10GBASE-ER10GBASE\text{-}ER (30 km30\,km, Singlemode).
Media Access and MAC Addressing

A Media Access Control (MACMAC) address is a 48-bit48\text{-}bit identifier written in hexadecimal. It consists of a 24-bit24\text{-}bit Organizationally Unique Identifier (OUIOUI) and a 24-bit24\text{-}bit vendor-assigned ID.

CSMA/CDCSMA/CD (Carrier Sense Multiple Access with Collision Detection): Legacy mechanism where nodes listen for silence before transmitting. If a collision is detected, stations send a jamming signal and wait a random backoff time before retrying. Full-duplex Ethernet eliminates the need for CSMA/CDCSMA/CD.

Ethernet II Frame Structure
  1. Preamble (7 bytes7\,bytes): Synchronization.
  2. SFDSFD (1 byte1\,byte): Start Frame Delimiter.
  3. Destination MAC (6 bytes6\,bytes).
  4. Source MAC (6 bytes6\,bytes).
  5. Type (2 bytes2\,bytes): Defines the encapsulated protocol or an 802.1Q802.1Q tag.
  6. Data (46-1500 bytes46\text{-}1500\,bytes): Padded to 46 bytes46\,bytes minimum.
  7. FCSFCS (4 bytes4\,bytes): Frame Check Sequence (Cyclical Redundancy Check).

Switching and Command-Line Interface (CLI)

Basic Configuration Commands
  • Console Password: line console 0 password <pass> login &nbsp;&nbsp;&nbsp;&nbsp;
  • Enable Secret: enable secret <pass> (Hashed, takes precedence over enable password).
  • Save Configuration: copy running-config startup-config or legacy write.
  • Erase Configuration: erase startup-config or write erase.
Switch IP Management

Layer 2 switches use a Switch Virtual Interface (SVISVI) for management.

  • Set IP Address: interface vlan 1 followed by ip address <address> <mask>.
  • Default Gateway: ip default-gateway <address>.
  • SSHSSH Configuration: Requires a hostname, ip domain-name, and generated keys via crypto key generate rsa with a modulus length (e.g., 10241024 or 20482048).
Interface Status and Errors
  • RuntsRunts: Frames smaller than 64 bytes64\,bytes (often collision-related).
  • GiantsGiants: Frames larger than 1518 bytes1518\,bytes.
  • CRCCRC Errors: Failed checksums, often due to faulty cabling or interference.
  • Late Collisions: Collisions occurring after the 64th byte64th\,byte, typically indicating a duplex mismatch.

VLANs and Trunking

Virtual LANs (VLANsVLANs) segment broadcast domains. VLAN IDs range from 1-10011\text{-}1001 (Normal) and 1006-40941006\text{-}4094 (Extended).

Trunking and DTP

Trunk links carry traffic for multiple VLANs using the 802.1Q802.1Q encapsulation. Dynamic Trunking Protocol (DTPDTP) modes include:

  • AccessAccess: Never trunks.
  • TrunkTrunk: Forces trunking.
  • Dynamic AutoDynamic\,Auto: Trunks if the other side is set to TrunkTrunk or DesirableDesirable.
  • Dynamic DesirableDynamic\,Desirable: Actively attempts to trunk.
Voice VLAN

Designed for IP phones with a built-in switch. Configured on an access port via switchport voice vlan <id>. The data traffic remains in the configured switchport access vlan.

VLAN Trunking Protocol (VTP)

Syncs VLAN databases across switches. Modes include Server, Client, and Transparent. VTP version 3VTP\,version\,3 supports primary servers and extended VLAN ranges.

Spanning Tree Protocol (STP)

STPSTP (802.1D802.1D) prevents Layer 2 loops by blocking redundant paths. Components include Bridge Protocol Data Units (BPDUsBPDUs) and the Bridge ID (BIDBID).

The Spanning Tree Process
  1. Elect Root Bridge: Lowest Bridge Priority wins (default 32768default\,32768). In a tie, the lowest MAC address wins.
  2. Elect Root Ports (RPRP): The port on a non-root switch with the lowest root path cost.
  3. Elect Designated Ports (DPDP): The port on a segment with the lowest cost to the root. All ports on the Root Bridge are DPsDPs.
  4. Blocking Ports: All other ports are placed in a blocking state to break loops.
Rapid STP (RSTP)

RSTPRSTP (802.1w802.1w) provides faster convergence (secondsseconds vs 50 seconds50\,seconds). Port states are simplified to Discarding, Learning, and Forwarding.

  • PortFastPortFast: Transitions access ports immediately to forwarding.
  • BPDU GuardBPDU\,Guard: Disables a port if it receives a BPDUBPDU, preventing unauthorized switches from joining.

EtherChannel

Bundles up to 8 links8\,links into a single logical channel for increased bandwidth and redundancy.

Protocols and Modes
  • LACPLACP (802.3ad802.3ad): Active and Passive modes.
  • PAgPPAgP (Cisco): Desirable and Auto modes.
  • Static: Mode set to on (must be on at both ends).

IPv4 Addressing and Subnetting

IPv4 addresses are 32-bit32\text{-}bit values often shown in Dotted Decimal Notation (DDNDDN).

Classful Addressing
  • Class A: 1.x.x.x-126.x.x.x1.x.x.x\text{-}126.x.x.x (/8/8 mask).
  • Class B: 127.x.x.x-191.x.x.x127.x.x.x\text{-}191.x.x.x (/16/16 mask).
  • Class C: 192.x.x.x-223.x.x.x192.x.x.x\text{-}223.x.x.x (/24/24 mask).
  • Class D: 224.x.x.x-239.x.x.x224.x.x.x\text{-}239.x.x.x (MulticastMulticast).
  • Class E: 240.x.x.x-255.x.x.x240.x.x.x\text{-}255.x.x.x (ReservedReserved).
Subnetting Formulas
  • Number of Subnets: 2N2^N, where N=borrowed bitsN = \text{borrowed bits}.
  • Usable Hosts per Subnet: 2H-22^H \text{-} 2, where H=remaining host bitsH = \text{remaining host bits}.

IPv4 Routing

Routers forward packets based on the destination IP using the Routing Table.

Route Selection Logic
  1. Longest Prefix Match: The most specific route (highest prefix length) is chosen first.
  2. Administrative Distance (ADAD): Reliability of the route source. Lower is better.
    • Connected: 00
    • Static: 11
    • EIGRPEIGRP Summary: 55
    • OSPFOSPF: 110110
    • RIPRIP: 120120
  3. Metric: Protocol-specific value (e.g., OSPFOSPF cost, RIPRIP hop count).
Static Routes

Defined manually. A "floating static route" has a higher ADAD than the dynamic protocol and acts as a backup.

  • Standard: ip route <network> <mask> <next-hop>
  • Default: ip route 0.0.0.0 0.0.0.0 <next-hop>

OSPF (Open Shortest Path First)

OSPFOSPF is a Link-State routing protocol that uses the Shortest Path First (SPFSPF) algorithm. It builds a Link-State Database (LSDBLSDB) through Link-State Advertisements (LSAsLSAs).

Concepts
  • Areas: Multi-area design requires Area 0 (Backbone). All other areas must connect to Area 0.
  • Router ID (RIDRID): A unique 32-bit32\text{-}bit value identifying the router.
  • DR/BDRDR/BDR: Designated and Backup Designated Routers are elected on multi-access (Ethernet) segments to reduce flooding.
  • Neighbor States: Down, Init, 2-Way, Exstart, Exchange, Loading, Full.
  • Cost Calculation:     Cost=Reference Bandwidth (default 100 Mbps)Interface Bandwidth\text{Cost} = \frac{\text{Reference Bandwidth (default 100 Mbps)}}{\text{Interface Bandwidth}}

IPv6 Fundamentals

IPv6 addresses are 128 bits128\,bits long, represented by eight quartets of four hex digits.

Address Types
  • Global Unicast: Publicly routable (starts with 22 or 33).
  • Unique Local: Private range (FD00::/8FD00::/8).
  • Link-Local: Non-routable, used for local communications (FE80::/10FE80::/10).
  • Multicast: (FF00::/8FF00::/8).
  • Loopback: (::1::1).
Neighbor Discovery Protocol (NDP)

Replaces ARPARP in IPv6. Functions include Neighbor Solicitation (NSNS), Neighbor Advertisement (NANA), Router Solicitation (RSRS), and Router Advertisement (RARA).

EUI-64EUI\text{-}64 Interface ID Generation
  1. Take the 48-bit48\text{-}bit MAC address.
  2. Insert FFFE in the middle.
  3. Flip the 7th bit7th\,bit (inverted bit).

Wireless LANs (WLANs)

Wireless communication uses half-duplex radio waves over 2.4 GHz2.4\,GHz and 5 GHz5\,GHz frequency bands.

Terminology
  • BSSIDBSSID: MAC address of the Access Point (APAP) radio.
  • SSIDSSID: Service Set Identifier (human-readable name).
  • WLCWLC: Wireless LAN Controller used for centralized management.
  • CAPWAPCAPWAP: Tunneling protocol for communication between Lightweight APs (LAPsLAPs) and WLCsWLCs (UDP 5246 Control,5247 DataUDP\,5246\,Control, 5247\,Data).
Security Standards
  • WPA2WPA2: Uses AES/CCMPAES/CCMP encryption.
  • WPA3WPA3: Uses AES/GCMPAES/GCMP and Simultaneous Authentication of Equals (SAESAE).
  • EAPEAP: Extensible Authentication Protocol used for Enterprise authentication (requires a RADIUSRADIUS server).

Security Services and ACLs

Access Control Lists (ACLs)
  • Standard: Filters based on source IP only (1-991\text{-}99, 1300-19991300\text{-}1999).
  • Extended: Filters based on source/destination IP, protocol, and port (100-199100\text{-}199, 2000-26992000\text{-}2699).
  • Implicit Deny: Every ACLACL ends with an invisible deny any statement.
Device Hardening and Port Security
  • Port Security Modes:
    • shutdown: Disables port (default).
    • restrict: Drops traffic, logs violation.
    • protect: Drops traffic silently.
  • DHCP SnoopingDHCP\,Snooping: Prevents rogue DHCP servers by labeling ports as trusted or untrusted.
  • DAIDAI (Dynamic ARP Inspection): Mitigates ARP poisoning using the DHCP Snooping binding table.

IP Services

NAT (Network Address Translation)
  • Static: 1:11\text{:}1 mapping.
  • Dynamic: Uses a pool of addresses.
  • PATPAT (Port Address Translation / Overload): Maps many internal addresses to a single public IP using ports.
Quality of Service (QoS)
  • Classification & Marking: Uses Differentiated Services Code Point (DSCPDSCP) (Layer 3Layer\,3, 6 bits6\,bits) or Class of Service (CoSCoS) (Layer 2Layer\,2, 3 bits3\,bits).
  • Queueing: LLQLLQ (Low Latency Queueing) provides a priority queue for real-time voice (EF DSCP 46EF\,DSCP\,46).
  • Shaping vs. Policing: Shaping buffers excess traffic; Policing drops it.
FHRP (First Hop Redundancy Protocols)

Redundancy for default gateways.

  • HSRPHSRP (Cisco Proprietary): Active and Standby routers share a Virtual IP/MAC.
  • VRRPVRRP: Open standard similar to HSRPHSRP.
  • GLBPGLBP: Provides per-host load balancing.

Network Architecture and Cloud

Design Models
  • Three-Tier: Core, Distribution, Access.
  • Two-Tier (Collapsed Core): Core and Distribution functions are combined.
  • PoEPoE (802.3af/at/bt802.3af/at/bt): Delivers power over Ethernet cabling up to 100 W100\,W.
Cloud and Virtualization

Services models include Software as a Service (SaaSSaaS), Platform as a Service (PaaSPaaS), and Infrastructure as a Service (IaaSIaaS). Hypervisors manage Virtual Machines (VMsVMs) that share physical server hardware.

Network Automation

Automation moves from manual CLI configuration to programmatic control.

Planes of Operation
  1. Management Plane: Configuration and monitoring (SSHSSH, HTTPSHTTPS, APIsAPIs).
  2. Control Plane: Routing logic and intelligence (OSPFOSPF, STPSTP).
  3. Data Plane: High-speed forwarding (ASICsASICs).
Controllers and Tools
  • SDASDA (Software-Defined Access): Cisco's campus fabric solution using DNA Center,LISP,DNA\,Center, LISP, and VXLANVXLAN.
  • JSONJSON: Data serialization format used in APIsAPIs.
  • Configuration Management:
    • AnsibleAnsible: Push-based, agentless, uses YAML Playbooks.
    • PuppetPuppet: Pull-based, uses agents and Manifests.
    • ChefChef: Pull-based, uses agents and Recipes.

Questions & Discussion

Question: What is the difference between a static route with a next-hop IP and one with an outbound interface? Response: The first option is preferred as it avoids unnecessary encapsulation issues on multi-access links, but the second option is useful when the next-hop IP address is dynamic (e.g., provided via DHCP).

Question: Why use a loopback interface for NTP or OSPF? Response: Loopback interfaces are virtual and never go down unless manually shut. They provide a stable IP address for management and routing even if a specific physical link fails.