2026年01月22日/ 浏览 6
一、网络基础与概念
- Network:网络
- Protocol:协议
- Packet:数据包
- Frame:帧
- Byte:字节
- Bit:比特
- Bandwidth:带宽
- Latency / Delay:延迟
- Jitter:抖动
- Throughput:吞吐量
- QoS (Quality of Service):服务质量
- LAN (Local Area Network):局域网
- WAN (Wide Area Network):广域网
- MAN (Metropolitan Area Network):城域网
- VPN (Virtual Private Network):虚拟专用网
- Intranet:企业内网
- Internet:互联网
- Extranet:外联网
- Peer-to-Peer (P2P):对等网络
- Client / Server:客户端 / 服务器
- Switching:交换
- Routing:路由
- Broadcast:广播
- Multicast:组播
- Unicast:单播
- Subnet:子网
- Subnet mask:子网掩码
- Gateway:网关
- DNS (Domain Name System):域名系统
- DHCP (Dynamic Host Configuration Protocol):动态主机配置协议
- NAT (Network Address Translation):网络地址转换
- Firewall:防火墙
- Load balancing:负载均衡
- Redundancy:冗余
- Failover:故障切换
- Backup:备份
- Restore:恢复
- Bandwidth management:带宽管理
- Traffic shaping:流量整形
- Traffic policing:流量监管
- Encapsulation:封装
- Decapsulation:解封装
二、网络设备
- Router:路由器
- Switch:交换机
- Layer 2 switch:二层交换机
- Layer 3 switch:三层交换机
- Hub:集线器
- Bridge:网桥
- Gateway:网关
- Firewall:防火墙
- IDS (Intrusion Detection System):入侵检测系统
- IPS (Intrusion Prevention System):入侵防御系统
- Access point (AP):无线接入点
- Wireless router:无线路由器
- Modem:调制解调器
- CPE (Customer Premises Equipment):客户终端设备
- Server:服务器
- Client:客户端
- Workstation:工作站
- Storage device:存储设备
- NAS (Network Attached Storage):网络附加存储
- SAN (Storage Area Network):存储区域网络
- Load balancer:负载均衡器
- Proxy server:代理服务器
- DNS server:DNS服务器
- DHCP server:DHCP服务器
- VPN gateway:VPN网关
- Controller:控制器(如SDN控制器)
- Sensor:传感器(如IDS/IPS传感器)
三、网络层次与协议模型
- OSI model:OSI模型
- TCP/IP model:TCP/IP模型
- Application layer:应用层
- Transport layer:传输层
- Network layer:网络层
- Data link layer:数据链路层
- Physical layer:物理层
- Header:报文头
- Payload:载荷
- Segment:段(TCP)
- Datagram:数据报(UDP/IP)
- MAC address:MAC地址
- IP address:IP地址
- IPv4:互联网协议第4版
- IPv6:互联网协议第6版
- TCP (Transmission Control Protocol):传输控制协议
- UDP (User Datagram Protocol):用户数据报协议
- ICMP (Internet Control Message Protocol):互联网控制报文协议
- ARP (Address Resolution Protocol):地址解析协议
- RARP (Reverse ARP):反向地址解析协议
- HTTP (Hypertext Transfer Protocol):超文本传输协议
- HTTPS (HTTP Secure):安全HTTP
- FTP (File Transfer Protocol):文件传输协议
- SFTP (SSH File Transfer Protocol):安全文件传输协议
- TFTP (Trivial File Transfer Protocol):简单文件传输协议
- SMTP (Simple Mail Transfer Protocol):简单邮件传输协议
- POP3 (Post Office Protocol v3):邮局协议版本3
- IMAP4 (Internet Message Access Protocol v4):互联网邮件访问协议版本4
- DNS (Domain Name System):域名系统
- DHCP (Dynamic Host Configuration Protocol):动态主机配置协议
- NAT (Network Address Translation):网络地址转换
- PPP (Point-to-Point Protocol):点对点协议
- PPPoE (PPP over Ethernet):以太网上的PPP
- VLAN (Virtual LAN):虚拟局域网
- STP (Spanning Tree Protocol):生成树协议
- RSTP (Rapid STP):快速生成树协议
- MSTP (Multiple Spanning Tree Protocol):多生成树协议
- OSPF (Open Shortest Path First):开放式最短路径优先
- BGP (Border Gateway Protocol):边界网关协议
- EIGRP (Enhanced Interior Gateway Routing Protocol):增强型内部网关路由协议
- RIP (Routing Information Protocol):路由信息协议
- IS-IS (Intermediate System to Intermediate System):中间系统到中间系统
- VRRP (Virtual Router Redundancy Protocol):虚拟路由器冗余协议
- HSRP (Hot Standby Router Protocol):热备份路由器协议
- GLBP (Gateway Load Balancing Protocol):网关负载均衡协议
- SNMP (Simple Network Management Protocol):简单网络管理协议
- NTP (Network Time Protocol):网络时间协议
- LDAP (Lightweight Directory Access Protocol):轻量级目录访问协议
- SSL (Secure Sockets Layer):安全套接字层
- TLS (Transport Layer Security):传输层安全
- SSH (Secure Shell):安全外壳协议
- Telnet:远程终端协议(明文,不安全)
四、IP 地址与子网划分
- IP address:IP地址
- Network address:网络地址
- Host address:主机地址
- Broadcast address:广播地址
- Subnet:子网
- Subnet mask:子网掩码
- Wildcard mask:通配符掩码
- CIDR (Classless Inter-Domain Routing):无类别域间路由
- Classful addressing:有类地址
- Classless addressing:无类地址
- Private IP:私有IP
- Public IP:公有IP
- Loopback address:环回地址
- Reserved address:保留地址
- DHCP lease:DHCP租约
- IP pool:IP地址池
- Gateway:网关
- DNS server:DNS服务器
- Default gateway:默认网关
- Static IP:静态IP
- Dynamic IP:动态IP
五、VLAN、Trunk、STP 等二层技术
- VLAN (Virtual LAN):虚拟局域网
- Access port:接入端口
- Trunk port:干道端口
- Native VLAN:本征VLAN
- VLAN ID:VLAN编号
- VLAN tagging:VLAN打标签
- 802.1Q:VLAN标准协议
- ISL (Inter-Switch Link):交换机间链路(Cisco私有)
- STP (Spanning Tree Protocol):生成树协议
- Root bridge:根桥
- Non-root bridge:非根桥
- Root port:根端口
- Designated port:指定端口
- Non-designated port:非指定端口
- Blocking state:阻塞状态
- Listening state:侦听状态
- Learning state:学习状态
- Forwarding state:转发状态
- Disabled state:禁用状态
- BPDU (Bridge Protocol Data Unit):网桥协议数据单元
- RSTP (Rapid Spanning Tree Protocol):快速生成树协议
- MSTP (Multiple Spanning Tree Protocol):多生成树协议
- EtherChannel:以太通道(端口聚合)
- LACP (Link Aggregation Control Protocol):链路聚合控制协议
- PAgP (Port Aggregation Protocol):端口聚合协议(Cisco私有)
六、路由协议与三层技术
- Routing:路由
- Router:路由器
- Routing table:路由表
- Routing protocol:路由协议
- Static route:静态路由
- Default route:默认路由
- Dynamic routing:动态路由
- IGP (Interior Gateway Protocol):内部网关协议
- EGP (Exterior Gateway Protocol):外部网关协议
- OSPF (Open Shortest Path First):开放式最短路径优先
- Area:区域(OSPF)
- Router ID:路由器ID
- DR (Designated Router):指定路由器
- BDR (Backup Designated Router):备份指定路由器
- LSDB (Link State Database):链路状态数据库
- LSA (Link State Advertisement):链路状态通告
- BGP (Border Gateway Protocol):边界网关协议
- AS (Autonomous System):自治系统
- AS number:自治系统号
- BGP peer / neighbor:BGP对等体/邻居
- IBGP (Internal BGP):内部BGP
- EBGP (External BGP):外部BGP
- Route reflector:路由反射器
- Confederation:联盟(BGP)
- EIGRP (Enhanced Interior Gateway Routing Protocol):增强型内部网关路由协议
- Feasible distance:可行距离
- Reported distance:通告距离
- Feasible successor:可行后继
- RIP (Routing Information Protocol):路由信息协议
- Hop count:跳数
- Metric:度量值
- Administrative distance:管理距离
- Redistribution:路由重分发
- Summarization / Aggregation:路由汇总/聚合
七、网络安全
- Security:安全
- Threat:威胁
- Vulnerability:漏洞
- Exploit:漏洞利用
- Attack:攻击
- Malware:恶意软件
- Virus:病毒
- Worm:蠕虫
- Trojan:木马
- Spyware:间谍软件
- Adware:广告软件
- Ransomware:勒索软件
- Firewall:防火墙
- ACL (Access Control List):访问控制列表
- Filter:过滤
- Policy:策略
- IDS (Intrusion Detection System):入侵检测系统
- IPS (Intrusion Prevention System):入侵防御系统
- Signature:特征(如IDS特征库)
- Anomaly:异常
- VPN (Virtual Private Network):虚拟专用网
- IPsec (IP Security):IP安全协议
- IKE (Internet Key Exchange):互联网密钥交换
- Tunnel:隧道
- Encryption:加密
- Decryption:解密
- Public key:公钥
- Private key:私钥
- Symmetric encryption:对称加密
- Asymmetric encryption:非对称加密
- Hash:哈希
- MD5:一种哈希算法(安全性较弱)
- SHA-1 / SHA-256 / SHA-512:安全哈希算法
- Certificate:证书
- CA (Certificate Authority):证书颁发机构
- PKI (Public Key Infrastructure):公钥基础设施
- SSL / TLS:安全套接字层 / 传输层安全
- SSH (Secure Shell):安全外壳
- Authentication:认证
- Authorization:授权
- Accounting:计费/审计(AAA中的A)
- AAA (Authentication, Authorization, Accounting):认证、授权、计费
- RADIUS:远程认证拨入用户服务
- TACACS+:终端访问控制器访问控制系统加强版
- DMZ (Demilitarized Zone):非军事化区
- NAT (Network Address Translation):网络地址转换
- PAT (Port Address Translation):端口地址转换
- Port forwarding:端口转发
- Port triggering:端口触发
- MAC filtering:MAC地址过滤
- Network segmentation:网络分段
- Zero Trust:零信任
- Least privilege:最小权限原则
- Defense in depth:纵深防御
八、无线网络
- WLAN (Wireless LAN):无线局域网
- Wi-Fi:无线保真技术
- AP (Access Point):无线接入点