VPN Flashcards
(27 cards)
What does VPN stand for?
Virtual Private Network
What is the main purpose of a VPN?
To securely connect remote users or sites over an untrusted network like the internet
What are the two main types of VPNs?
Remote Access VPN and Site-to-Site VPN
Which VPN type is used for connecting a single user to a private network?
Remote Access VPN
Which VPN type is used to connect two networks together securely?
Site-to-Site VPN
What are two protocols used to establish VPNs at Layer 3?
IPsec and GRE
What does IPsec stand for?
Internet Protocol Security
What are the three main functions of IPsec?
Confidentiality; Integrity; and Authentication
Which protocol in IPsec provides encryption?
Encapsulating Security Payload (ESP)
Which protocol in IPsec provides authentication and integrity?
Authentication Header (AH)
What are the two main IPsec tunnel modes?
Tunnel mode and Transport mode
What mode is typically used in Site-to-Site VPNs?
Tunnel mode
What mode is typically used in host-to-host VPNs?
Transport mode
Which ports does IKE (Internet Key Exchange) use?
UDP 500 and UDP 4500 (for NAT traversal)
What is the purpose of IKE in IPsec?
To negotiate and establish secure keys for the VPN
What is a GRE tunnel?
A tunneling protocol that encapsulates a wide variety of network layer protocols
What is a disadvantage of GRE?
It does not provide encryption or security by itself
How can you add security to a GRE tunnel?
Combine GRE with IPsec
What is DMVPN?
Dynamic Multipoint VPN – a Cisco solution for scalable; secure VPNs
What technology does DMVPN rely on?
NHRP (Next Hop Resolution Protocol) and multipoint GRE
What is the function of NHRP in DMVPN?
It maps public IP addresses to tunnel IPs
What is the benefit of DMVPN over traditional Site-to-Site VPNs?
It allows spoke-to-spoke tunnels without static configurations
What is SSL VPN?
A VPN that uses the SSL/TLS protocol to secure the connection; often through a web browser
What is a common use case for SSL VPNs?
Secure remote access via web browser without a full VPN client