Posts

Showing posts with the label Monitoring

Syslog Severity Levels Explained: 0 to 7 for the Network+ Exam

Syslog assigns every message a severity level from 0 to 7. The numbering is the part people get wrong, and it is the part exams test. Lower numbers are more severe. 0 is an emergency; 7 is debug chatter. It runs backwards from how most people expect a severity scale to work. The Eight Levels Level Keyword Meaning 0 Emergency The system is unusable. Total failure. 1 Alert Action must be taken immediately. A critical subsystem has failed. 2 Critical Critical conditions — a hardware fault, a failing disk. 3 Error Error conditions. Something failed but the system continues. 4 Warning Something may become a problem — a threshold approaching, a deprecated call. 5 Notice Normal but significant. A configuration change, a service restart. 6 Informational Routine operational messages. 7 Debug Verbose diagnostic detail, for troubleshooting only. Remembering the Order The classic mnemonic reads down the list from 0 to 7: E very A wesome C isco E ngineer W ill N eed I ce C ream...

SNMP Community Strings Explained: public, private and SNMPv3 for Network+

An SNMP community string is the password that SNMP versions 1 and 2c use to control access to a device's management data. Calling it a password is generous: it is sent in cleartext, it is shared rather than per-user, and the default values are known to everyone. A community string is a shared secret that is neither secret nor protected. SNMPv1 and v2c have no real authentication, and that is the whole exam point. The Two Kinds Read-only (RO). Permits GET operations — reading interface counters, CPU load, uptime, system description. The default value is almost universally public . Read-write (RW). Permits SET operations as well, which means changing device configuration . The default is almost universally private . Those two default values are worth memorizing exactly, because exam questions use them and because they are the first thing any attacker tries. A device left on defaults with RW enabled can be reconfigured by anyone who can reach it. Why This Is So Dangerou...

NetFlow vs sFlow Explained: Flow Data for the Network+ Exam

NetFlow and sFlow both tell you what traffic is crossing your network, and both are examinable on Network+. They answer the same question by entirely different methods, and that difference is the whole point. NetFlow records every conversation and summarizes it. sFlow captures a random sample of individual packets. One is complete, the other is fast. NetFlow Developed by Cisco and now widely implemented. The device maintains a flow cache , grouping packets into conversations, and exports a summary record when each conversation ends or a timer expires. A flow is traditionally identified by five fields — the 5-tuple : source IP, destination IP, source port, destination port, and protocol. Some implementations add the ingress interface and type of service, making it a 7-tuple. Each exported record carries the tuple plus byte and packet counts, start and end timestamps, TCP flags, and often the next hop and AS numbers. Crucially, NetFlow accounts for every packet . The counts...