Day 7 - VPN and IPsec Flashcards

1
Q

A __________ __________ __________ is an encrypted connection between private networks over a public network such as the internet

A

Virtual Private Network (VPN)

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
2
Q

Instead of using a dedicated __________ _____ connection such as a leased line, a __________ uses virtual connections called __________ ___________

A

Layer 2
VPN
VPN tunnels

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
3
Q

What are the 4 benefits of a VPN?

A

Cost savings
Security
Scalability
Compatibility with broadband technology

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
4
Q

What are some types of VPN access methods?

A

Site-to-Site VPN
Remote access VPN
GRE (Generic Routing Encapsulation
DMVPN (Dynamic Multipoint VPN)

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
5
Q

Solve for the type of VPN access method:

These types of VPNs connect entire networks to each other. For example, this type of VPN can connect a branch office network to a company HQ network

A

Site-to-Site VPN

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
6
Q

Solve for the type of VPN access method:

This type of VPN access method enables individual hosts such as telecommuters, mobile users and extranet consumers to access a company network securely over the internet. Typically uses a client based VPN connection

A

Remote-access VPN

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
7
Q

Solve for the type of VPN access method:

A standard IPsec VPN that is a non-secure site-to-site VPN tunneling protocol can support multicast and broadcast traffic needed for network layer protocols.

A

GRE (Generic routing encapsulation)

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
8
Q

Does GRE support encryption by default?

A

No

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
9
Q

Solve for GRE terms regarding the encapsulation process

__________ ___________ for the routing protocol
__________ ___________ for GRE
__________ ___________ for IPsec

A

Passenger protocol
Carrier protocol
Transport protocol

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
10
Q

Solve for the type of VPN access method:

Cisco proprietary solution for building many VPNs in an easy, dynamic, and scalable manner. Allows a network administrator to dynamically form hub-and-spoke tunnels and spoke-to-spoke tunnels

A

DMVPN (Dynamic Multipoint VPN)

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
11
Q

What two tunnels are there for DMVPN?

A

Hub-to-Spoke tunnels
Spoke-to-Spoke tunnels

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
12
Q

What technologies does DMVPN utilize?

A

NHRP (Next hop redundancy protocol)
IPsec encryption
mGRE
VTI
Service Provider MPLS

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
13
Q

VPNs secure data by __________ and __________ it

A

Encapsulating
Encrypting

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
14
Q

Encapsulation is also known as __________

A

Tunneling

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
15
Q

VPN tunneling uses 3 classes of protocols. What are they?

A

Carrier protocol
Encapsulating protocol
Passenger protocol

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
16
Q

What are the 4 VPN encryption algorithms?

A

DES (Data Encryption Standard)
3DES (Triple DES)
AES (Advanced Encryption Standard)
RSA (Rivest, Shamir and Adleman)

17
Q

What does HMAC stand for?

A

Hashed message authentication code

18
Q

What are the two HMAC algorithms?

A

MD5
SHA-1

19
Q

For VPN authentication with the device on the other end of the tunnel, what two peer authentication methods are used?

A

Pre-Shared key (PSK)
RSA Signature

20
Q

What are the two IPsec framework protocols?

A

AH (Authentication Header)
ESP (Encapsulating Security Payload)

21
Q

This is an open standard configuration for a site to site VPN and it does not support multicast

A

IPSec Tunnel

22
Q

This type of VPN configuration added support for multicast but doesn’t support encryption on it’s own so it has to be paired with IPSec Tunnel

A

GRE (Generic Routing Encapsulation) over IPSec Tunnel

23
Q

This type of VPN configuration is used between Cisco devices, often site to site VPNs and is Cisco proprietary and supports multicast

A

IPSec VTI (Virtual Tunnel Interface)

24
Q

This type of VPN configuration is a simple and scalable hub and spoke style that enables direct full mesh connectivity between all offices

A

DMVPN (Dynamic Multipoint VPN)

25
Q

Very similar to DMVPN. Newer technology and it’s Cisco proprietary

A

FlexVPN

26
Q

What is different about Layer 3 MPLS vs. Layer 2 MPLS?

A

The CE devices do not peer with the PE devices. The entire provider network is transparent to the customer

27
Q

What does VPLS stand for and how many sites can it support and what layer does it run at?

A
  • Virtual Private LAN Service
  • 2 or more sites
  • Layer 2