Terminology 3 Flashcards
(100 cards)
In an IP header, what is the protocol number for TCP?
6
In an IP header, what is the protocol number for UDP?
17
In an IP header, what is the protocol number for EIGRP?
88
In an IP header, what is the protocol number for OSPF?
89
In an IP header, what is the protocol number for IPv6?
41
In an IP header, what is the protocol number for GRE?
47
In an IP header, what is the protocol number for L2TP (Layer 2 Tunnelling Protocol)?
115
How are ICMP messages carried across a network?
As IP packets - They are encapsulated within IP datagrams.
What does GRE do?
Encapsulates other protocols inside IP tunnels
What are the parts of a GRE header?
Transport IP Header
GRE Header
Passenger IP Packet
What is the minimum overhead GRE adds to tunnelled packets?
24 bytes
What are 3 limitations of IPSec?
Does not support IP broadcast
Does not support IP multicast
Does not support multi-protocol traffic
How can you overcome the limitations of IPSec?
Run GRE over IPSec
What are the two primary security protocols used by IPSec?
Authentication Header (AH)
Encapsulating Security Payload (ESP)
How does AH work?
The sender generates a one-way hash of the whole packet, then the receiver generates the same hash, and compares them.
How much of the packet does AH authenticate?
The whole packet
What are the five components of ESP?
- Confidentiality
- Data Integrity
- Authentication
- Anti-Replay Service
- Traffic Flow Confidentiality
Which 4 cryptographic algorithms are defined for use with IPSec?
- HMAC-SHA1/SHA2 (for integrity and authenticity)
- TripleDES-CBC (confidentiality)
- AES-CBC 128 bit keys (confidentiality)
- AES-GCM ChaCha20-Poly1305 (Confidentiality and Authentication)
How does ESP counter replay attacks?
Use of sequence numbers
What needs to be enabled for ESP to provide traffic flow confidentiality?
Tunnel mode
What two things does the transport layer use port numbers for?
Identify the virtual circuit (source port)
Identify the upper layer process (destination port)
What is the class A usable network range?
1 to 126
That does a network address of all 0s designate?
This network
What is the network address 127 reserved for?
Network diagnostics (loopback)