Study guide · Core notes

CCNA Core Notes for 200-301 v1.1

Reference notes for the facts CCNA questions depend on: addresses, VLANs, spanning tree, OSPFv2, NAT, ACLs, and the difference between a northbound API and a southbound one.

Exam: 200-301 v1.1Six domainsReviewed October 2026

How to read these notes: Items tagged Extra sit outside the v1.1 topic list, such as Chef and Puppet. Items tagged v2.0 belong to the blueprint that opens on February 3, 2027. Learn the unmarked items first if you test by February 2, 2027. New to the exam? Start with the overview for the format and the domain weights. Shared port facts also appear in the networking and cloud notes.

Devices, media, and topologies

Domain 1 starts here. Name the decision the device makes before you name the product.

Network components on the v1.1 topic list.
ComponentWhat it does
RouterForwards packets between IP networks. The default gateway is a router address on the host's subnet.
Layer 2 switchForwards a frame by the destination MAC. Unknown unicasts are flooded in the VLAN. The source MAC is learned on the arrival port.
Layer 3 switchSwitches frames and can route between VLANs with switched virtual interfaces.
Next-generation firewall and IPSA firewall allows or blocks by policy. An IPS can drop traffic because it sits in the path.
Access point and WLCAn autonomous AP is configured on its own. A lightweight AP takes its configuration from a wireless LAN controller.
Cisco DNA CenterA campus controller for inventory, assurance, and automation. It is not the WLC that joins lightweight APs.
PoEThe switch supplies power on the Ethernet cable. 802.3af offers up to 15.4 W at the port. 802.3at (PoE+) offers up to 30 W. The switch budget is the limit, not the standard's maximum on every port at once.
Topologies and media. Pick the design by the traffic pattern, not by the vendor logo.
Design or mediumHow to recognize it
Two-tierAccess switches connect to a collapsed core. Distribution and core are the same layer.
Three-tierAccess, distribution, and core are separate. The core moves traffic quickly and does not apply every policy.
Spine-leafEvery leaf connects to every spine. Leaves do not connect to each other. East-west traffic has a predictable hop count.
SOHOA small site, often one device that routes, switches, and offers wireless.
Single-mode fiberOne path for light, a laser, and longer distances. Do not mix it with a multimode optic.
Multimode fiberA wider core and a shorter reach, used inside a building or a campus.
Duplex or speed mismatchA duplex mismatch often stays up and shows late collisions on the half-duplex side. A speed mismatch often leaves the link down.

TCP and UDP. TCP sets up a session, retransmits lost segments, and keeps order. UDP does not. DNS queries, DHCP, NTP, and SNMP usually use UDP. HTTP, SSH, and FTP use TCP.

Virtualization. A virtual machine has a guest operating system on a hypervisor. A container shares the host kernel. A VRF is a separate routing table on one physical router, not a virtual machine. v2.0 pushes harder on diagnosing these, but the three ideas are already on v1.1.

IPv4 addressing

Subtract the network and broadcast addresses before you count hosts. A /30 is the usual point-to-point mask on this exam.

Masks CCNA expects you to calculate without a calculator. Hosts means usable addresses.
PrefixMaskBlock sizeUsable hosts
/24255.255.255.0256254
/25255.255.255.128128126
/26255.255.255.1926462
/27255.255.255.2243230
/28255.255.255.2401614
/29255.255.255.24886
/30255.255.255.25242

Private and special

  • 10.0.0.0/8, 172.16.0.0/12, and 192.168.0.0/16 are private. 172.16.0.0/12 runs through 172.31.255.255. 172.32.0.1 is public.
  • 169.254.0.0/16 is an automatic address a host picks when DHCP fails. It is not a range you planned.
  • 127.0.0.1 is loopback. Traffic to it never leaves the host.

How to find the network

Find the block size in the interesting octet, then step back to the multiple of that size. 192.168.10.70/26 is in 192.168.10.64 through 192.168.10.127. The network is .64, the broadcast is .127, and the usable hosts are .65 through .126. The wildcard of a /26 is 0.0.0.63, which is the inverse of 255.255.255.192.

IPv6 addresses

Know the prefix by the job. You do not need to memorize every hextet.

IPv6 types on the v1.1 list.
TypeHow to recognize it
Global unicast2000::/3. This is the routable address, similar in role to a public IPv4 address.
Unique localfc00::/7. Addresses you assign in practice usually start with fd. They are not meant for the public Internet.
Link-localfe80::/10. Every IPv6 interface has one. It is used on the link, including as an OSPFv3 next hop. v2.0 OSPFv3 itself is not a v1.1 configuration task.
Multicastff00::/8. ff02::1 is all nodes on the link. ff02::2 is all routers on the link.
AnycastThe same unicast address on more than one device. The nearest one answers. There is no separate prefix.
Loopback::1. It stays on the host.
Modified EUI-64Split the MAC, insert fffe in the middle, and invert the U/L bit. 00:11:22:33:44:55 becomes 0211:22ff:fe33:4455.

Client checks: Windows uses ipconfig. Linux uses ip address. macOS uses ifconfig. Look for the mask, the gateway, and a 169.254 address before you blame the router.

VLANs, trunks, and EtherChannel

Domain 2. A VLAN is a broadcast domain. A trunk is how that domain crosses a switch.

Switching facts v1.1 asks you to configure or verify.
IdeaWhat to remember
Access portOne data VLAN, sent untagged. A voice VLAN can be added and is tagged. The normal VLAN range is 1 to 1005. VLAN 1 is the default.
802.1Q trunkInserts a VLAN tag. The native VLAN is sent untagged. Both ends must agree, or traffic leaks or drops.
Inter-VLAN routingA router-on-a-stick uses subinterfaces with encapsulation dot1Q. A Layer 3 switch uses an SVI per VLAN and ip routing.
CDP and LLDPBoth discover the neighbor at Layer 2. CDP is Cisco. LLDP is the multi-vendor protocol. Neither is a routing protocol.
LACPactive and passive form a channel. Passive with passive does not. Speed, duplex, and the VLAN list must match. PAgP (desirable and auto) is Cisco-only and is not the protocol v1.1 names.

Wireless on this domain. A local-mode AP tunnels client traffic to the WLC. FlexConnect can switch locally at a branch. Monitor mode watches the RF and does not serve clients. The WLC connects to the switched network on an access port, a trunk, or a link aggregation group. The GUI task is to create a WLAN, set security, and pick a QoS profile. WPA2 PSK is the security setting v1.1 asks you to verify.

Rapid PVST+

One spanning tree per VLAN. The goal is one forwarding path, so a loop cannot multiply a broadcast.

Spanning-tree roles and the protections v1.1 added or kept.
TermMeaning
Root bridgeThe switch with the lowest bridge ID. The ID is priority plus MAC, and the default priority is 32768. Set a primary and a secondary on purpose. Do not leave the root to the lowest MAC.
Root portThe port on this switch with the best path to the root. A switch has one root port, unless it is the root.
Designated portThe forwarding port for a segment. Every segment has one.
Alternate portA backup path toward the root. It discards frames until the root port fails.
PortFastSkips listening and learning on an edge port so a PC comes up quickly. Do not enable it on a link to another switch.
BPDU GuardError-disables a PortFast port that receives a BPDU. That is how you stop someone from plugging in a switch.
Root GuardIf a superior BPDU arrives, the port is blocked so this switch keeps the root you chose.
Loop GuardIf BPDUs stop on a root or alternate port, the port stays discarding instead of becoming designated and closing a loop.
BPDU FilterStops BPDUs on a port. v1.1 lists it. It can hide a loop, so it is not a substitute for BPDU Guard.

How a router forwards

Domain 3 is 25 percent. Read the prefix before you read the protocol letter.

  1. Longest matching prefix. 10.1.1.0/24 beats 10.1.0.0/16 for 10.1.1.10.
  2. Lowest administrative distance, only when the prefixes are equal.
  3. Lowest metric, only inside the protocol that won the previous step.
Administrative distances that show up when you read a routing table. A lower number is more trusted.
SourceCodeDistance
ConnectedC0
StaticS1
eBGP ExtraB20
EIGRP internal ExtraD90
OSPFO110
RIP ExtraR120

v1.1 asks you to configure static routes and OSPFv2, and to interpret a table. Configuring EIGRP, RIP, or BGP is outside that list. You still need their distances when a show command prints them. A floating static uses an administrative distance worse than the primary protocol, such as 130, so OSPF (110) is used while it is up and the static route takes over when OSPF withdraws. A host route is a /32. A default route is 0.0.0.0/0, and the gateway of last resort is that default.

First-hop redundancy. HSRP, VRRP, and GLBP give hosts one virtual gateway. If the active router fails, another router owns the virtual IP. Hosts do not change their gateway setting. v1.1 asks you to describe this, not to build a full HSRP lab. v2.0 asks you to interpret HSRP and VRRP output.

Single-area OSPFv2

Neighbors must agree before a route is exchanged. Area 0 is the backbone, and a single-area design is all area 0.

What must match, and what the router ID and DR election use.
CheckRule
Router IDThe manual ID if you set one. Otherwise the highest loopback, otherwise the highest active interface address. It does not have to be a reachable address, but it must be unique.
Hello and deadMust match. On Ethernet broadcast and point-to-point, the defaults are 10 and 40 seconds.
Area and subnetThe interfaces must be in the same area and the same subnet on a broadcast link. A wildcard in the network statement selects interfaces. It is not a subnet mask.
Point-to-pointNo DR or BDR. Use this on a WAN link between two routers.
Broadcast DRHighest priority wins, then the highest router ID. Priority 0 never becomes DR. The default priority is 1.
CostReference bandwidth divided by interface bandwidth. The default reference is 100 Mbps, so Fast Ethernet and Gigabit Ethernet both cost 1 until you raise the reference.

IP services

Domain 4 is 10 percent. These are the services you turn on, not a second routing exam.

Services v1.1 asks you to configure, verify, or explain.
ServiceWhat to remember
NATInside local is the private address. Inside global is the public address the outside sees. Mark interfaces ip nat inside and ip nat outside. overload is PAT.
DHCPDiscover, offer, request, acknowledge. The server uses UDP 67 and the client uses UDP 68. A relay (ip helper-address) forwards the broadcast to a server on another subnet. v1.1 configures the client and the relay. v2.0 also troubleshoots a DHCP server on the router.
DNSTurns a name into an address. An A record is IPv4. An AAAA record is IPv6. The router can point at a DNS server. It is not the public resolver for the Internet unless you built it to be.
NTPA client points at a server. A lower stratum is closer to the reference clock. Time matters because logs and certificates depend on it.
SNMPQueries use UDP 161. Traps use UDP 162. v2c uses a community string. v3 can authenticate and encrypt.
Syslog0 emergency, 1 alert, 2 critical, 3 error, 4 warning, 5 notification, 6 informational, 7 debug. A lower number is more severe. A trap level of 4 sends 0 through 4.
SSHSet a domain name, generate an RSA key, create a local user, and allow SSH on the VTY lines. Telnet is TCP 23 in clear text. SSH is TCP 22.
TFTP and FTPTFTP is UDP 69 and has no login. FTP is TCP 21 and 20. Both move images and configurations. TFTP is the usual IOS copy method on this exam.
QoSClassify, mark, queue, then either police (drop or remark) or shape (buffer). Policing does not store the extra traffic. Shaping does.

Security fundamentals

Domain 5 is 15 percent. Configure the control that matches the threat. Do not enable every feature on every port.

Security tasks on the v1.1 list.
ControlWhat it stops
Threats and exploitsA threat is the possible harm. A vulnerability is the weakness. An exploit is the method that uses the weakness. Mitigation is the control.
Local passwordsenable secret is hashed. enable password is weak. service password-encryption hides type 7 passwords and is not a strong hash. Prefer a local username with a secret.
AAAAuthentication is who you are. Authorization is what you may do. Accounting is the record of what you did. RADIUS and TACACS+ are the servers. RADIUS uses UDP. TACACS+ uses TCP and separates the three functions.
Standard ACLNumbers 1 to 99 and 1300 to 1999. Filters the source only. Place it close to the destination.
Extended ACLNumbers 100 to 199 and 2000 to 2699. Filters protocol, source, destination, and port. Place it close to the source. Every ACL ends with an implicit deny.
Port securityLimits MAC addresses on an access port. Sticky learns them into the running config. Shutdown is the default violation and error-disables the port. Restrict drops and counts. Protect drops quietly.
DHCP snoopingTrusted ports face the real DHCP server. Untrusted ports drop server messages, which stops a rogue DHCP server.
Dynamic ARP inspectionChecks ARP against the DHCP snooping table, so a host cannot claim someone else's IP.
WPA2 and WPA3WPA2-Personal is a pre-shared key with AES-CCMP. WPA3-Personal uses SAE. The configuration task on v1.1 is WPA2 PSK in the WLAN GUI.
IPsec VPNSite-to-site joins two networks. Remote access joins one user. v1.1 asks you to describe them, not to build a full tunnel lab.

Automation and programmability

Domain 6 is 10 percent. Explain the architecture. You are not asked to write a production playbook.

Automation ideas on the v1.1 list. Chef and Puppet were removed from this version.
IdeaMeaning
Traditional versus controllerTraditional management logs into each device. A controller holds intent and pushes it, so one change does not mean fifty CLI sessions.
Underlay and overlayThe underlay is the routed network that provides reachability. The overlay is the tunnel, such as VXLAN, built on top. The fabric is both working together.
Control and data planeThe control plane decides. The data plane forwards. A controller centralizes the decision.
Northbound and southboundNorthbound faces the application, often REST. Southbound faces the devices.
RESTGET reads, POST creates, PUT replaces, PATCH changes part of a resource, and DELETE removes it. The API is stateless. Authenticate with a token rather than pasting a password into the URL.
JSONObjects, arrays, strings, numbers, true, false, and null. Keys are strings. There are no comments and no trailing commas.
AnsibleAgentless. It pushes YAML playbooks over SSH. You describe the tasks.
TerraformDeclarative infrastructure as code. It stores state and converges the devices to that state. v1.1 names it. v2.0 drops Terraform from the topic list and keeps Ansible.
AI on v1.1Generative AI creates text or a config draft. Predictive AI estimates what happens next. Machine learning finds a pattern in data. You still verify the result before you apply it.
Chef and Puppet ExtraNot on the v1.1 list. Do not pick them as the current configuration-management answer.

Frequently asked questions

Are these notes the official Cisco exam topics?

No. They are an original summary of the public 200-301 v1.1 exam topics. Confirm the current PDF with Cisco before you book.

What do the Extra and v2.0 tags mean?

Extra marks a useful idea the v1.1 topic list does not name, such as Chef and Puppet. v2.0 marks an idea that belongs to the blueprint that opens on February 3, 2027. Learn the unmarked items first if you test on v1.1.

Which route does a Cisco router prefer?

The longest matching prefix wins. If two sources offer that same prefix, the lower administrative distance wins. Metric is compared only inside one routing protocol.

Continue the CCNA study path

Turn the tables into recall, then test them.

CCNA hub →
Available

Overview

Exam format, pass/fail scoring, six domain weights, and the February 2027 v2.0 change.

Available · You are here

Core Notes

Reference notes for addresses, VLANs, spanning tree, OSPF, services, security, and automation.

Available

Flashcards & Memory Notes

40 recall cards in four decks, plus memory notes for masks, administrative distance, and syslog.

Available

Practice Exams

200 original questions with custom exams, explanations, and an unofficial percentage.

Related Tools

Useful companions while you study.

All study topics →