Cisco Glossary
Cisco technologies underpin networks in organisations of every size, from local switching and wireless access to secure wide-area networks, data centres, automation and cloud-managed infrastructure. This A–Z glossary explains important Cisco products, protocols, acronyms and networking concepts in practical language, making it useful for learners working towards Cisco certifications as well as anyone managing modern networks.
A
AAA
Authentication, Authorisation and Accounting, a framework for controlling who can access a network, what they can do and how their activity is recorded.
Access Control List (ACL)
A set of permit and deny rules used on network devices to control traffic according to criteria such as IP address, protocol or port.
Access Point (AP)
A device that provides wireless clients with access to a wired network.
ACI
Cisco Application Centric Infrastructure, a policy-driven data-centre networking architecture built around Cisco Nexus switches and centralised controllers.
Anycast
An addressing method in which the same IP address is advertised from multiple locations and traffic is routed to an appropriate nearby destination.
ARP
Address Resolution Protocol, used on IPv4 networks to discover the MAC address associated with a local IP address.
ASIC
Application-Specific Integrated Circuit, specialised hardware used in switches and routers to process network traffic at high speed.
Autonomous System (AS)
A group of IP networks and routers under one administrative control that presents a common routing policy to other networks.
Authentication
The process of confirming the identity of a user, device or system before access is granted.
Authorisation
The process of determining which resources or actions an authenticated user or device is permitted to access.
Automation
The use of software, APIs and repeatable workflows to configure, operate and troubleshoot networks with less manual intervention.
B
Bandwidth
The maximum amount of data a network link can carry over a period of time, normally expressed in bits per second.
BFD
Bidirectional Forwarding Detection, a protocol that rapidly detects failures between two forwarding devices so routing can converge more quickly.
BGP
Border Gateway Protocol, the routing protocol used to exchange reachability information between autonomous systems and widely used on the internet.
BPDU
Bridge Protocol Data Unit, a message exchanged by switches participating in Spanning Tree Protocol.
Bridge
A Layer 2 device or function that forwards Ethernet frames between network segments based on MAC addresses.
Broadcast
A transmission sent from one device to every device within the same broadcast domain.
Broadcast Domain
A group of devices that receive the same Layer 2 broadcast traffic, commonly bounded by a router or VLAN boundary.
Buffer
Temporary memory used by a network device to hold packets when they cannot be forwarded immediately.
C
Campus Network
A network connecting users, devices and services across buildings or a local organisational site.
Catalyst
Cisco's family of enterprise switching, wireless and related networking platforms.
Catalyst Center
Cisco's central platform for managing, automating and assuring enterprise networks, formerly known as Cisco DNA Center.
CCIE
Cisco Certified Internetwork Expert, Cisco's expert-level career certification designation for advanced technical skills.
CCNA
Cisco Certified Network Associate, an associate-level certification covering broad networking and related technology fundamentals.
CCNP
Cisco Certified Network Professional, Cisco's professional-level certification family for deeper expertise in technology areas such as enterprise, security, wireless and data centre.
CCST
Cisco Certified Support Technician, an entry-level Cisco certification family covering foundational networking or cybersecurity skills.
CDP
Cisco Discovery Protocol, a Cisco protocol that allows directly connected Cisco devices to advertise information about themselves to neighbours.
CEF
Cisco Express Forwarding, a high-performance Layer 3 switching mechanism used by Cisco devices to make forwarding decisions efficiently.
CIDR
Classless Inter-Domain Routing, a method of representing IP networks using a prefix length such as /24 instead of older class-based addressing.
Cisco IOS
Cisco Internetwork Operating System, the traditional network operating system used across many Cisco routing and switching platforms.
Cisco IOS XE
A modern Cisco network operating system built on a Linux-based architecture and widely used on Catalyst enterprise platforms.
Cisco Modeling Labs (CML)
Cisco's network simulation platform for building virtual topologies using Cisco network operating system images.
CLI
Command-Line Interface, the text-based environment used to configure, monitor and troubleshoot many Cisco devices.
Cloud-Managed Networking
A model in which network configuration, monitoring and policy are managed through a cloud-hosted platform such as the Cisco Meraki dashboard.
Collision Domain
A network segment where simultaneous Ethernet transmissions could collide, a concept mainly associated with older shared-media Ethernet.
Control Plane
The part of a network device or architecture responsible for learning topology, building routing information and making control decisions.
CoPP
Control Plane Policing, a mechanism used to protect the control plane by limiting selected traffic destined for the device itself.
Core Layer
The high-speed backbone layer in a hierarchical enterprise network design, intended to move traffic efficiently between major network areas.
D
Data Plane
The part of a network device that actually forwards packets and frames according to information created by the control plane.
Default Gateway
The router address a host uses to reach destinations outside its own local subnet.
Default Route
A route used when no more specific route exists, represented in IPv4 as 0.0.0.0/0.
DHCP
Dynamic Host Configuration Protocol, used to automatically provide clients with IP addresses and other network settings.
DMVPN
Dynamic Multipoint VPN, a Cisco-supported architecture for building scalable encrypted connections between multiple sites.
DNS
Domain Name System, the distributed service that translates names such as websites into IP addresses and provides other naming information.
DNA Center
The former name for Cisco Catalyst Center, retained in older documentation and course material.
DTP
Dynamic Trunking Protocol, a Cisco protocol that can negotiate whether an Ethernet link operates as a trunk.
Duplex
The ability of a link to transmit and receive data, with full duplex allowing both directions at the same time.
Dynamic Routing
The use of routing protocols such as OSPF, EIGRP or BGP to learn and update routes automatically.
E
ECMP
Equal-Cost Multi-Path routing, where traffic can use multiple routes that have the same routing metric.
Edge
The part of a network closest to users, devices, remote sites or external networks.
EIGRP
Enhanced Interior Gateway Routing Protocol, an advanced distance-vector routing protocol originally developed by Cisco.
Encapsulation
The process of adding protocol information around data as it moves down the networking stack for transmission.
Encryption
The conversion of readable data into a protected form that can only be understood by authorised parties with the required key.
Endpoint
A device or application that connects to a network, such as a laptop, phone, server, camera or IoT device.
Enterprise Network
The networking infrastructure used by an organisation to connect users, sites, applications and services securely.
EtherChannel
A Cisco technology that combines multiple physical Ethernet links into one logical link for greater bandwidth and resilience.
Ethernet
The dominant wired LAN technology, defined by IEEE 802.3 standards and used by switches, routers and endpoint devices.
EVPN
Ethernet VPN, a control-plane technology commonly paired with VXLAN to distribute Layer 2 and Layer 3 reachability information across data-centre fabrics.
F
Fabric
A network architecture in which multiple devices operate together as an integrated connectivity system.
Fast Convergence
The ability of a network to detect a failure and establish a working alternative path quickly.
FHRP
First Hop Redundancy Protocol, a category of protocols such as HSRP that provide a resilient default gateway for hosts.
Firewall
A security system that inspects and controls network traffic according to defined security rules.
FlexConnect
A Cisco wireless mode that allows access points at remote sites to switch selected traffic locally while remaining centrally managed.
Flow
A sequence of packets sharing common characteristics such as source, destination, protocol and port numbers.
FQDN
Fully Qualified Domain Name, the complete domain name identifying a host or service within DNS.
Fragmentation
The division of an IP packet into smaller pieces so it can cross a network path with a lower supported packet size.
Full Duplex
A link mode that allows data to be transmitted and received simultaneously.
G
Gateway
A device or service that connects different networks and provides a path for traffic leaving the local network.
Gigabit Ethernet
Ethernet operating at one gigabit per second, commonly written as 1 GbE.
Global Routing Table
The main routing table on a router, separate from any additional routing tables created for VRFs.
Gratuitous ARP
An unsolicited ARP message used by a device to announce or verify an IPv4-to-MAC address mapping on a local network.
GRE
Generic Routing Encapsulation, a tunnelling protocol that can carry different network protocols inside IP packets.
Group Policy
A collection of access or security settings applied to users, devices or traffic according to their identity or role.
H
Half Duplex
A link mode where communication can occur in both directions but not at the same time.
Hop
One Layer 3 forwarding step as a packet passes through a router on its way to a destination.
Hop Count
The number of routers or Layer 3 forwarding steps between source and destination.
HSRP
Hot Standby Router Protocol, a Cisco first-hop redundancy protocol that presents hosts with a resilient virtual default gateway.
HTTP
Hypertext Transfer Protocol, the application protocol used to transfer web content and interact with many web-based network interfaces.
HTTPS
HTTP protected by TLS encryption, widely used for secure browser and API access to network services.
Hub
An older Layer 1 Ethernet device that repeats incoming signals to every other port rather than selectively forwarding frames.
Hybrid Cloud
An architecture combining private or on-premises infrastructure with public cloud services.
Hypervisor
Software or firmware that creates and runs virtual machines on physical hardware.
I
ICMP
Internet Control Message Protocol, used for network diagnostics and error reporting, including by the ping command.
IGP
Interior Gateway Protocol, a routing protocol used within one autonomous system, such as OSPF, EIGRP or IS-IS.
Interface
A physical or logical connection through which a network device sends and receives traffic.
Intent-Based Networking
An approach where administrators describe desired outcomes and software translates them into network configuration, policy and assurance.
Inter-VLAN Routing
The Layer 3 routing required for devices in different VLANs to communicate with one another.
IP
Internet Protocol, the Layer 3 protocol used to address and route packets across interconnected networks.
IP Address
A logical address assigned to a network interface so it can communicate using Internet Protocol.
IPsec
A suite of protocols that authenticates and encrypts IP traffic, commonly used for VPN connections.
IPv4
The widely deployed version of Internet Protocol using 32-bit addresses such as 192.0.2.10.
IPv6
The newer Internet Protocol version using 128-bit addresses and designed to provide a vastly larger address space than IPv4.
IOS XR
A Cisco network operating system designed for high-scale service provider and carrier-class routing platforms.
IS-IS
Intermediate System to Intermediate System, a link-state interior routing protocol used particularly in large enterprise and service-provider networks.
ISE
Cisco Identity Services Engine, a policy and network access control platform used to identify users and devices and apply access decisions.
J
Jitter
Variation in packet delay over time, which can affect real-time applications such as voice and video.
Jitter Buffer
Temporary storage used in real-time communications to smooth variations in packet arrival times.
JSON
JavaScript Object Notation, a lightweight structured data format widely used by network APIs and automation tools.
Jumbo Frame
An Ethernet frame larger than the traditional 1500-byte payload, used in some networks to improve efficiency for suitable workloads.
K
Keepalive
A periodic message used to confirm that a neighbour, connection or network service is still available.
Key Chain
A configuration mechanism that stores one or more authentication keys for use by supported networking protocols.
Key Exchange
The process by which communicating parties securely establish cryptographic keys for an encrypted session.
Kubernetes
An open-source platform for deploying and managing containerised applications, often connected to enterprise and data-centre networking infrastructure.
L
LACP
Link Aggregation Control Protocol, the IEEE standard protocol used to negotiate and manage bundled Ethernet links.
LAN
Local Area Network, a network covering a limited geographic area such as an office, building or campus.
Latency
The time taken for data to travel from one point in a network to another.
Layer 2
The Data Link layer of the OSI model, associated with Ethernet frames, switches, MAC addresses and VLANs.
Layer 3
The Network layer of the OSI model, associated with IP addressing and routing between networks.
Lightweight Access Point
A Cisco wireless access point designed to receive centralised control and configuration from a wireless controller or cloud management platform.
Link Aggregation
The combination of multiple physical links into one logical connection for additional bandwidth and resilience.
Link-State Routing
A routing approach where routers build a topology database from information about network links, as used by OSPF and IS-IS.
LLDP
Link Layer Discovery Protocol, an IEEE standard that lets directly connected devices advertise identity and capability information.
Load Balancing
The distribution of traffic or workload across multiple paths or resources to improve performance and resilience.
Local Preference
A BGP attribute used inside an autonomous system to indicate the preferred outbound path, with higher values normally preferred.
Loopback Interface
A logical interface that is not tied to a physical port and is commonly used for stable management or routing protocol addresses.
M
MAC Address
A hardware-level address used to identify an Ethernet or wireless network interface on a local network.
MAC Address Table
A switch table mapping learned MAC addresses to the ports or interfaces through which they can be reached.
MAB
MAC Authentication Bypass, a network access method that uses a device's MAC address when it cannot perform stronger authentication such as 802.1X.
Management Plane
The functions and protocols used by administrators and software tools to configure and monitor network devices.
Meraki
Cisco's cloud-managed networking portfolio covering products such as switches, wireless access points, security appliances and cameras.
MFA
Multi-Factor Authentication, requiring more than one type of evidence to verify a user's identity.
MIB
Management Information Base, a structured collection of variables that can be monitored or managed through SNMP.
Model-Driven Telemetry
A modern approach to continuously streaming structured operational data from network devices to monitoring or analytics systems.
MPLS
Multiprotocol Label Switching, a forwarding technology that uses labels to move traffic through provider or large enterprise networks.
MTU
Maximum Transmission Unit, the largest packet or frame payload a network interface can transmit without fragmentation.
Multicast
A method of sending one stream of traffic efficiently to a selected group of receivers.
N
NAC
Network Access Control, technologies and policies that decide whether users and devices are permitted to connect to a network.
NAT
Network Address Translation, the modification of IP addressing information as traffic passes between networks.
Neighbour Adjacency
A relationship formed between directly or logically connected routing peers so they can exchange routing information.
NetFlow
A Cisco-developed technology for collecting metadata about IP traffic flows for monitoring, analysis and security purposes.
Network Assurance
The use of telemetry, analytics and validation to determine whether a network is delivering the intended connectivity and user experience.
Network Automation
The use of APIs, scripts, controllers and orchestration tools to perform network tasks consistently and repeatedly.
Network Controller
Software that provides centralised control, policy, automation or management for a group of network devices.
Network Segmentation
The division of a network into separate logical or physical areas to improve security, performance and manageability.
Network Topology
The arrangement of network devices and the connections between them.
Nexus
Cisco's family of high-performance switches designed primarily for data-centre networking.
NTP
Network Time Protocol, used to synchronise clocks across network devices and computer systems.
NX-OS
Cisco's data-centre network operating system used on many Nexus switching platforms.
O
OMP
Overlay Management Protocol, the control-plane protocol used in Cisco Catalyst SD-WAN to exchange routing, policy and service information.
OpenConfig
A vendor-neutral set of YANG models and APIs designed to provide consistent programmable management of network devices.
Optical Transceiver
A module that converts electrical network signals to and from light for transmission over fibre-optic cabling.
OSPF
Open Shortest Path First, a widely used link-state interior routing protocol that calculates efficient routes through an IP network.
OSPF Area
A logical grouping of OSPF routers and links used to reduce routing overhead and improve scalability.
Overlay
A logical network built on top of an underlying physical or IP transport network, often using tunnels or encapsulation.
Oversubscription
A design where the combined potential demand of downstream links exceeds available upstream capacity, based on the assumption that not all links will peak simultaneously.
P
Packet
A formatted unit of data carried at the network layer, normally containing source and destination addressing information.
Packet Loss
The failure of one or more packets to reach their destination, potentially causing reduced application quality or retransmissions.
PAT
Port Address Translation, a form of NAT that allows many internal devices to share one public IP address by translating transport-layer port numbers.
PoE
Power over Ethernet, technology that delivers electrical power and network data over the same Ethernet cable to devices such as access points and IP phones.
Port
A physical network interface on a device or, in TCP and UDP, a numerical identifier used to distinguish application services.
Port Channel
A logical interface formed by bundling multiple physical Ethernet links, commonly using EtherChannel and LACP.
Port Security
A switch feature that restricts which MAC addresses may use an access port and can respond to unauthorised devices.
Prefix
A block of IP addresses identified by a network address and prefix length, such as 192.0.2.0/24.
Prefix List
An ordered set of rules used to match IP network prefixes, often for controlling route advertisements or route filtering.
Private VLAN
A VLAN design that provides additional Layer 2 isolation between devices that would otherwise share the same VLAN.
Protocol
A defined set of rules and message formats that enables devices or applications to communicate.
Q
QinQ
An Ethernet technique that carries a customer VLAN tag inside an additional provider VLAN tag, also known as VLAN stacking.
QoS
Quality of Service, techniques used to classify, prioritise, queue, shape or police traffic so important applications receive suitable network treatment.
Queue
A temporary holding area for packets waiting to be transmitted through an interface.
Queuing
The process of organising packets into queues and deciding the order in which they are transmitted when a link is congested.
R
RADIUS
Remote Authentication Dial-In User Service, a protocol commonly used for centralised authentication, authorisation and accounting for network access.
Redundancy
The use of duplicate devices, links or services so that a failure does not cause the entire network function to stop.
RFC
Request for Comments, a publication series containing many of the technical standards and specifications used by internet protocols.
RIP
Routing Information Protocol, an older distance-vector routing protocol that uses hop count as its routing metric.
ROMMON
ROM Monitor, a low-level Cisco device environment used for bootstrapping, password recovery and troubleshooting startup problems.
Route
An entry that describes how a router can reach a particular destination network or prefix.
Route Map
A Cisco configuration structure used to match traffic or routes and apply actions for policy-based routing, redistribution, BGP and other features.
Route Reflector
A BGP router that reduces the need for a full mesh of internal BGP peerings by reflecting routes between clients.
Routed Port
A physical switch port configured as a Layer 3 interface rather than a Layer 2 switchport.
Router
A Layer 3 device that forwards packets between different IP networks.
Routing Protocol
A protocol used by routers to exchange reachability information and calculate preferred network paths.
Routing Table
A table of known destinations and next-hop information used by a router to make forwarding decisions.
RSTP
Rapid Spanning Tree Protocol, an IEEE protocol that provides faster Layer 2 convergence than the original Spanning Tree Protocol.
S
SASE
Secure Access Service Edge, an architecture that combines networking and cloud-delivered security capabilities for users, devices and sites.
SD-Access
Cisco Software-Defined Access, a campus architecture that uses policy, segmentation, automation and an overlay fabric to simplify enterprise networking.
SD-WAN
Software-Defined Wide Area Networking, an approach that centrally controls and optimises connectivity across branch, campus, data-centre and cloud locations.
Secure Access
Cisco's cloud-delivered security platform designed to provide secure access to internet, SaaS and private applications.
Secure Client
Cisco's endpoint client for secure connectivity and security capabilities, incorporating technology previously associated with Cisco AnyConnect.
Security Group Tag (SGT)
A Cisco TrustSec label that represents the security group or role of traffic and can be used to enforce policy independently of IP addressing.
Segment Routing
A routing architecture that directs packets through an ordered set of network segments without requiring a separate signalling protocol for every path.
SFP
Small Form-factor Pluggable, a removable transceiver module used to connect network devices to copper or fibre links.
Site-to-Site VPN
An encrypted VPN connection between two networks, commonly used to connect branches, data centres or cloud networks.
SLA
Service Level Agreement, a defined target for service performance or availability; network devices can also perform IP SLA measurements to test path behaviour.
SNMP
Simple Network Management Protocol, used to retrieve operational information and receive alerts from network devices.
SPAN
Switched Port Analyzer, a Cisco feature that copies selected traffic to a monitoring port for packet analysis.
SSID
Service Set Identifier, the network name advertised or used by a wireless LAN.
SSH
Secure Shell, an encrypted protocol commonly used for remote command-line administration of network devices.
StackWise
A family of Cisco technologies that allows multiple compatible Catalyst switches to operate together as a logical system.
Stateful Firewall
A firewall that tracks the state of network connections and uses that context when deciding whether to permit traffic.
Static Route
A manually configured route specifying how to reach a destination rather than learning the path from a routing protocol.
STP
Spanning Tree Protocol, used on switched Ethernet networks to prevent Layer 2 loops while maintaining redundant links.
Subnet
A logical subdivision of an IP network containing a defined range of addresses.
Subnet Mask
An IPv4 value that identifies which bits of an address represent the network and which identify hosts.
Switch
A network device that forwards Ethernet frames between connected devices, primarily using MAC address information.
Switching
The Layer 2 process of forwarding frames between interfaces within an Ethernet network.
Syslog
A standard mechanism used by network devices and systems to send event and diagnostic messages to a logging destination.
T
TACACS+
A protocol widely used with Cisco devices for centralised administrator authentication, authorisation and accounting.
TCP
Transmission Control Protocol, a connection-oriented transport protocol that provides reliable, ordered delivery of data.
Telemetry
Operational data exported by network devices for monitoring, analytics, assurance and troubleshooting.
Telnet
An older remote terminal protocol that sends data without encryption and is generally replaced by SSH for secure administration.
TFTP
Trivial File Transfer Protocol, a simple UDP-based file transfer protocol sometimes used for device configuration or image transfers.
ThousandEyes
A Cisco internet and cloud intelligence platform that provides visibility into network paths, application experience and external dependencies.
TLS
Transport Layer Security, the cryptographic protocol widely used to protect application traffic such as HTTPS.
Topology
The logical or physical arrangement of devices, links and paths within a network.
Traffic Policing
A QoS technique that enforces a traffic rate and may drop or remark packets that exceed the configured limit.
Traffic Shaping
A QoS technique that buffers and delays excess traffic to smooth the transmission rate.
Transit
The carrying of network traffic through an intermediate network or device on the way to another destination.
Trunk
A Layer 2 link configured to carry traffic for multiple VLANs, commonly using IEEE 802.1Q tagging.
TTL
Time To Live, an IP header value reduced by each router to prevent packets circulating indefinitely.
U
UDP
User Datagram Protocol, a connectionless transport protocol with low overhead and no built-in guarantee of delivery.
Umbrella
A long-established Cisco cloud security brand associated with DNS-layer and secure internet access capabilities, much of which is now integrated into Cisco Secure Access.
Underlay
The physical or IP transport network that provides connectivity beneath an overlay network.
Unicast
One-to-one network communication from a single source to a single destination.
Uplink
A connection from an access device or lower network layer toward an upstream switch, router or aggregation layer.
URI
Uniform Resource Identifier, a string used to identify a resource and commonly encountered when working with REST APIs.
V
Virtual Interface
A logical network interface created in software rather than corresponding directly to a single physical port.
VLAN
Virtual Local Area Network, a logical Layer 2 broadcast domain that allows one switched infrastructure to be divided into separate networks.
VoIP
Voice over Internet Protocol, technology for carrying voice communications over IP networks.
vPC
Virtual Port Channel, a Cisco Nexus technology that allows a downstream device to form one logical port channel to two separate switches.
VPN
Virtual Private Network, an encrypted or logically isolated connection across another network such as the internet.
VRF
Virtual Routing and Forwarding, a technology that creates separate routing tables on the same router or Layer 3 switch.
VTP
VLAN Trunking Protocol, a Cisco protocol that can distribute VLAN information among switches within a VTP domain.
VXLAN
Virtual Extensible LAN, an overlay technology that encapsulates Layer 2 traffic across a Layer 3 IP network using a large identifier space.
W
WAN
Wide Area Network, a network connecting geographically separated sites over carrier, internet or private connectivity.
Webex
Cisco's collaboration platform for meetings, messaging, calling and related workplace communication services.
Wi-Fi 6
The Wi-Fi generation based on IEEE 802.11ax, designed to improve efficiency and performance in dense wireless environments.
Wi-Fi 7
The newer Wi-Fi generation based on IEEE 802.11be, providing higher throughput and lower latency through features such as multi-link operation.
Wireless Access Point
A device that provides Wi-Fi connectivity and bridges wireless clients to the wired network.
Wireless LAN Controller (WLC)
A platform used to centrally control and manage compatible wireless access points.
WPA2
A widely used Wi-Fi security standard based on IEEE 802.11i and AES encryption.
WPA3
A newer Wi-Fi security standard that strengthens authentication and encryption compared with WPA2.
WRED
Weighted Random Early Detection, a congestion avoidance technique that can drop selected packets before a queue becomes completely full.
X
X.509 Certificate
A standard digital certificate used to bind an identity to a public key for authentication and encrypted communications.
XML
Extensible Markup Language, a structured text format used by some network management protocols, APIs and configuration systems.
Y
YANG
A data modelling language used to describe network configuration and operational data for programmable management interfaces such as NETCONF and RESTCONF.
Z
Zero Touch Provisioning (ZTP)
An automated process that allows a new network device to obtain configuration or software with little or no manual setup at the installation site.
Zero Trust
A security model that requires continuous verification of users, devices and access context rather than assuming anything inside a network is automatically trusted.
Zone-Based Firewall
A Cisco firewall configuration model that applies security policy between logical security zones rather than directly between individual interfaces.
Explore related Cisco training and resources
Develop your networking skills with our Cisco training courses, explore the Cisco certification pathways, or review related concepts in our Cyber Security Glossary and Data Centre Glossary. You can also browse our full course catalogue.




