Day 7 - VPN and IPsec Flashcards

1
Q

A __________ __________ __________ is an encrypted connection between private networks over a public network such as the internet

A

Virtual Private Network (VPN)

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
2
Q

Instead of using a dedicated __________ _____ connection such as a leased line, a __________ uses virtual connections called __________ ___________

A

Layer 2
VPN
VPN tunnels

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
3
Q

What are the 4 benefits of a VPN?

A

Cost savings
Security
Scalability
Compatibility with broadband technology

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
4
Q

What are some types of VPN access methods?

A

Site-to-Site VPN
Remote access VPN
GRE (Generic Routing Encapsulation
DMVPN (Dynamic Multipoint VPN)

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
5
Q

Solve for the type of VPN access method:

These types of VPNs connect entire networks to each other. For example, this type of VPN can connect a branch office network to a company HQ network

A

Site-to-Site VPN

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
6
Q

Solve for the type of VPN access method:

This type of VPN access method enables individual hosts such as telecommuters, mobile users and extranet consumers to access a company network securely over the internet. Typically uses a client based VPN connection

A

Remote-access VPN

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
7
Q

Solve for the type of VPN access method:

A standard IPsec VPN that is a non-secure site-to-site VPN tunneling protocol can support multicast and broadcast traffic needed for network layer protocols.

A

GRE (Generic routing encapsulation)

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
8
Q

Does GRE support encryption by default?

A

No

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
9
Q

Solve for GRE terms regarding the encapsulation process

__________ ___________ for the routing protocol
__________ ___________ for GRE
__________ ___________ for IPsec

A

Passenger protocol
Carrier protocol
Transport protocol

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
10
Q

Solve for the type of VPN access method:

Cisco proprietary solution for building many VPNs in an easy, dynamic, and scalable manner. Allows a network administrator to dynamically form hub-and-spoke tunnels and spoke-to-spoke tunnels

A

DMVPN (Dynamic Multipoint VPN)

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
11
Q

What two tunnels are there for DMVPN?

A

Hub-to-Spoke tunnels
Spoke-to-Spoke tunnels

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
12
Q

What technologies does DMVPN utilize?

A

NHRP (Next hop redundancy protocol)
IPsec encryption
mGRE
VTI
Service Provider MPLS

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
13
Q

VPNs secure data by __________ and __________ it

A

Encapsulating
Encrypting

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
14
Q

Encapsulation is also known as __________

A

Tunneling

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
15
Q

VPN tunneling uses 3 classes of protocols. What are they?

A

Carrier protocol
Encapsulating protocol
Passenger protocol

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
16
Q

What are the 4 VPN encryption algorithms?

A

DES (Data Encryption Standard)
3DES (Triple DES)
AES (Advanced Encryption Standard)
RSA (Rivest, Shamir and Adleman)

17
Q

What does HMAC stand for?

A

Hashed message authentication code

18
Q

What are the two HMAC algorithms?

19
Q

For VPN authentication with the device on the other end of the tunnel, what two peer authentication methods are used?

A

Pre-Shared key (PSK)
RSA Signature

20
Q

What are the two IPsec framework protocols?

A

AH (Authentication Header)
ESP (Encapsulating Security Payload)

21
Q

This is an open standard configuration for a site to site VPN and it does not support multicast

A

IPSec Tunnel

22
Q

This type of VPN configuration added support for multicast but doesn’t support encryption on it’s own so it has to be paired with IPSec Tunnel

A

GRE (Generic Routing Encapsulation) over IPSec Tunnel

23
Q

This type of VPN configuration is used between Cisco devices, often site to site VPNs and is Cisco proprietary and supports multicast

A

IPSec VTI (Virtual Tunnel Interface)

24
Q

This type of VPN configuration is a simple and scalable hub and spoke style that enables direct full mesh connectivity between all offices

A

DMVPN (Dynamic Multipoint VPN)

25
Very similar to DMVPN. Newer technology and it's Cisco proprietary
FlexVPN
26
What is different about Layer 3 MPLS vs. Layer 2 MPLS?
The CE devices do not peer with the PE devices. The entire provider network is transparent to the customer
27
What does VPLS stand for and how many sites can it support and what layer does it run at?
- Virtual Private LAN Service - 2 or more sites - Layer 2