IPsec VPN Flashcards
What port does IKE use?
- UDP 500
- UDP 4500 with NAT-T
What VPN topology has the simplest configuration?
Hub-and-Spoke
What are some cases in which you wouldn’t want a Hub-and-Spoke VPN topology?
- If you want fault tolerance
- If you need direct communication between sites
What is the likely cause if an IPsec tunnel is not coming up and you get a negotiation failure error?
IPsec configuration mismatch, verify phase 1 and 2 configurations between both peers
What is the likely cause if an IPsec tunnel is unstable and you get an error saying DPD packet lost?
- ISP issue, check internet connection
- Enable NAT-Traversal
What must be done in the firewall policy for an IPsec tunnel to come up?
Create a policy accepting traffic on the IPsec tunnel
What setting determines whether a tunnel is used as primary or backup?
Routing
What are the two modes IPsec can operate in?
- Transport
- Tunnel
What authentication does IKEv1 support?
- XAuth
- PSK and certificate signature
What authentication does IKEv2 support instead of XAuth?
EAP
What is a reason to use mesh topology over hub-and-spoke?
- Hub-and-spoke branch offices must go through HQ is slower than a direct connection, especially if physically distant
- Mesh devices are directly connected and you can bypass HQ
- More fault tolerant
What are some remote gateway types in VPNs?
- Dialup User
- Static IP Address
- Dynamic DNS
When would you use Dialup User?
When the remote peer IP address is unknown
What is IKE Mode Config?
- An alternative to DHCP over IPsec
- A server assigns network settings to clients over IKE messages
What problem did NAT traversal solve?
- The ESP protocol has problems crossing devices that are performing NAT
- Solves the incompatibility between NAT and IPSec