Domain 4 Flashcards
IKE
Internet Key Exchange uses diffie-hellman style of negotiation Use public key certificates
IPSec
IP Security
Which Port is IPSEC on
UDP port 500
Phase 2 of IPSec
Tunnel is created and is the “production channel”
What gets hashed in ESP Auth
old combined fields 3,4 and payload
Phase 1 of IPsec
Negotiation of tunnel
Define SPI in IPSec
Security Parameter Index (SPI) is an identification tag added to the header while using IPsec for tunneling the IP traffic
L2TP
Layer 2 tunneling protocol
what layer does IPSec operate on
Layer 3
ESP
Encapsulating Security Payload
When Combining two systems on a network with IPSec the risk is
There could be duplicate IPs
Define RFC 1918
Request for Comment 1918 (RFC 1918), “Address Allocation for Private Internets,”
MTU
Maximum Transmission Units
PPTP
Point-to-point tunneling protocol
ESP Header
Contains info showing which security association to ue and the packet sequence number
MPLS
Multi-protocol label switching
Define MPLS
Multiprotocol Label Switching (MPLS) is a routing technique in telecommunications networks that directs data from one node to the next based on short path labels rather than long network addresses
ESP Payload
Contains the encrypted part of the packet. If the encryption to use when the security association is establsihed
ISAKMP
Internet security association key management protocol
Characteristics of ISAKMP
Bi Directional. RFC 2048
ESP Trailer
May include padding (filler bytes) if requires by the encryption ALGO or to align fields
Authentication field (ESP Auth)
This field contains the integrity check (hash) of the ESP packet.
Steps of IPSec
- Sender created segment with port address set to 500 2. sender sends segment to device that is set to create and ipsec tunnel if “interesting traffic” shows up 3. interesting traffic arrives at device, device looks at layer 3 header and figures out where its going to tunnel to 4. device invokes ISAKMP and builds bi-directional tunnel 5. If key pairs, uses diffie hellmen called ISAKMP-Oakily 6. Security Parameter Index appears on each device 7. Enter Phase 2, creates permanent tunnel 8. Data is then passed between phase 2 tunnel
SSAE 16
Replaced SAS 70 Auditing Standard. Replaced by SSAE18