3 - VPN Flashcards
VPN
Virtual Private Network,
Provides access to secure private networks
VPN Protocols
PPTP (Point to point)
- obsolete
L2F (Layer 2 Forwarding)
L2TP (L2 Tunnelling)
IPSec
VPN Encryption Modes
Tunnel Mode
- protects packet from header to payload
- more resources useful if destination should be hidden
Transport Mode
- only protects payload
- doesn’t conceal endpoint identity
Software VPN Advantages
- Easy install
- Decent conneciton speed
- Portable
Software VPN Disadvantages
- Difficult to configure
- VPN Server is exposed
Hardware VPN Advantages
- Designed for routing
- Designed for good security
- Big network organisations
Hardware VPN Disadvantages
- Cost
- CHecking compatibility with other devices
IPSec services examples
- Access control
- COnnectionless integrity
- Data origin authentication
- Rejection of replayed packets
- Confidentiality
IPSec Packet
IP Header
IPSec Header
Secure IP Payload
IPsec VPN negotiation
A and B
1. A sends traffic to B
2. RouterA and RouterB negotiate an IKE Phase 1 session
3. Then an IKE Phase 2 session
4. Info exchanged via IPsec tunnel
5. tunnel terminated