GET VPN Flashcards
What is GET VPN
GETVPN (Group Encrypted Transport VPN) is a tunnel-less VPN technology meant for private networks like MPLS VPN where a single SA (Security Association) is used for all routers in a group.
What are 3 advantages of GET VPN?
- Its encryption allows for HIPPA and PCI compliant any-to-any tunneless VPNs between endpoints
- Establishes spoke-to-spoke connectivity faster than DMVPN
- Supports multicast and QOS
If GET VPN encrypts the entire packet how does it still uses the original IP header?
It uses “Tunnel Mode with Address Preservation” that copies the original source and destination from the inner IP header to the outer IP header
What are the 4 main components of GET VPN?
- Group Member (GM)
- Key Server (KS)
- Group Domain of Interpretation
- IPSec
What encryption method does GET VPN use?
ESP
What does the GET VPN Key Server do?
Group registration and authentication of Group Members
What are the 3 steps of Group Member registration?
- GM attempts to register with KS
- KS checks its group ID and IKE credentials
- KS then sends the group VPN policy, GM Key Encryption Key (KEK), and Traffic Encryption Key (TEK)
What is the Key Encryption Key (KEK) used for?
KS uses it to encrypt re-key messages, GM uses it to decrypt rekey messages
In GET VPN what is the Traffic Encryption Key (TEK) used for?
The TEK becomes the IPSec SA used by GMs to encrypt and decrypt normal traffic
What is Group Domain of Interpretation (GDOI)?
- Group key management protocol used between KS and GMs
- Protected with ISAKMP phase 1
How is Key Server redundancy accomplished?
Two or more Key Servers communicate with Cooperative Key Server Protocol authenticating each other and maintaining state.
When are 2 times that a KS sends rekeying messages
- When the existing IPSec SA is about to expire
- When the security policy is changed
What 2 methods can rekeying messages be sent in?
- Unicast
- Multicast
What is the advantage of Unicast mode?
- Upon receiving a new key the GM sends an acknowledgement back to the KS.
- If KS doesn’t receive an ACK after 3 transmissions the GM is deleted from the group
What is the advantage of Multicast mode?
It scales much better than unicast does.