Cisco CCNA Security 640-553 IINS Tutorials Part-8

Extended access control list (ACL) Made up of a series of statements created in global mode.With extended ACLs, IP packets may be filtered based on a number of attributes. Extended ACLs can filter packets according to protocol type, source and IP address,
destination IP address, source TCP or UDP ports, destination TCP or UDP ports, and optional protocol type information if finer granularity of control is required.

Extensible Authentication Protocol-Flexible Authentication via Secure Tunneling (EAP-FAST)
Protects authentication messages within a secure Transport Layer Security (TLS) tunnel using shared secret keys. Security is provided by an SSL (Secure Socket Layer)/TLS certificate on the “server side”/ACS and by a username and password on the client side.

Extensible Authentication Protocol-Message Digest 5 (EAP-MD5)
A standards-based EAP type that uses an MD5-Challenge message. This is much like thechallenge message used in PPP CHAP (Point-to-Point Protocol Challenge HandshakeAuthentication Protocol), which also uses MD5 as its hashing algorithm.

Extensible Authentication Protocol-Transport Layer Security (EAP-TLS) Developed by Microsoft Corporation to address weaknesses found in other EAP types (such as the one-way authentication used by EAP-MD5). EAP-TLS uses certificate-based (X.509
certificate-based) authentication. It requires both a supplicant and an authentication server to possess a digital certification to perform mutual authentication.

Extensible Authentication Protocol-Tunneled Transport Layer Security (EAP-TTLS) Uses a secured Transport Layer Security (TLS) tunnel to send other EAP authentication messages.

Fibre Channel In terms of SAN networking, this is the primary SAN transport used for
hostto- SAN connectivity.

Fibre Channel Authentication Protocol (FCAP)
Born from Switch Link Authentication Protocol (SLAP), the first authentication protocol proposed for Fibre Channel. This optional authentication mechanism may be employed between any two devices or entities on a Fibre Channel network. It uses certificates or optional keys
to provide security.

Fibre Channel over IP (FCIP) Represents the implementation of Fibre Channel in an IP
implementation that relies on TCP/IP as the network protocol.

Fibre Channel Password Authentication Protocol (FCPAP)

An optional password-based authentication key-exchange protocol. It may be used in
Fibre Channel networks to provide mutual authentication between Fibre Channel ports. As compared to FCAP, FCPAP does not require a PKI to operate.

No comments: