IPsec Flashcards

1
Q

IKE - Internet Key Exchange

A

IKE helps IPsec securely exchange cryptographic keys between distant devices.

Key Management can be preconfigured with Internet Security Association and Key Management Protocol(ISAKMP) or with a manual key configuration.

IKE and ISAKMP are often used interchangeably.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
2
Q

What does IKE - Internet Key Exchange protect

A

The IKE tunnel protects the SA negotiations.
After the SAs are in place, IPsec protects the data that the devices exchange.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
3
Q

Phase 1 of IKE - Internet Key Exchange

A

Authenticates and protects the identities of the IPSec peers

Negotiates a matching IKE SA policy between peers to protect the IKE exchange

Performs an authenticated Diffie-Hellman exchange with the end result of having matching shared secret keys

Sets up a secure tunnel to negotiate IKE phase 2 parameters

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
4
Q

Where does Internet Key Exchange occur in

A

Main Mode & Aggressive mode.

The difference between the two is that Main mode requires the exchange of 6 messages while Aggressive mode requires only 3 exchanges.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
5
Q

Phase 2 of IKE - Internet Key Exchange

A

Negotiates IPSec SA parameters protected by an existing IKE SA

Establishes IPSec security associations

Periodically renegotiates IPSec SAs to ensure security

Optionally performs an additional Diffie-Hellman exchange

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
6
Q

Security Associations (SAs)

A

SAs is a relationship between the sender and a receiver that describes how the peers will use IPsec security services to protect network traffic.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
7
Q

What does Security Associations contain

A

All the security parameters needed to securely transport packets between the peers or hosts.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
8
Q

Parameters of Security Associations

A

Security Parameter Index (SPI) - is a number to identify the SA

IP Destination Address- the address of the destination device

Security Protocol: AH or ESP

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
9
Q

Ipsec Transmission

A

if u care go tested and skipping

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
10
Q

Verify IPsec statements

A

ref image

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
11
Q

View Policy statement

A

RouterA# show crypto isakmp policy

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
12
Q

View Crypto IPsec SA statement

A

RouterA# show crypto ipsec sa

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
13
Q

View Configured Crypto Maps statement

A

RouterA# show crypto map

How well did you know this?
1
Not at all
2
3
4
5
Perfectly