AWS IPSEC Flashcards
In IPSEC what is an SA used for?
The SA holds the one-way relationship between sender and receiver defined by the SA parameters.
- One SA for inbound traffic
- One SA for outbound traffic
What is IKE?
IKE is an internet key exchange and is used to set up the security associations. There are two IKE version IKEv1 and IKEv2. An example of IKE is strong strongswan on linux.
What ports does IKEv2 use?
UDP Port Number=500 (controle path)
UDP Port Number=4500 (controle path)
IP Protocol Type=ESP (value 50 and 51) (data path)
In IPSec what are the two IP headers used
?
AH and ESP
This is the AH header in IPSec?
It is the auth header, in the IP layer, it is the packets sent over the wire. AH only authenticates the IP packet.
This is the ESP header in IPSec?
It is the IP packets and is encrypted, authenticated and its integrity is checked.
In IPSec is there a data plane and a control plane?
Yes data travels over the data plane, this when we send the ESP packets, the control plane uses
How can you monitor the V PN tunnels?
CloudWatch enables you to monitor the tunnel health and activity.
Whet the AWS VPN, must the client or AWS send data to establish the tunnel?
The client, AWS will never send data.