Overlay Protocols Flashcards
What is Generic Routing Encapsulation?
A layer 3 over layer 3 encapsulation protocol
What are some common use cases of GRE?
Site to site vpn (with IPsec)
Multicast traffic over unicast
IPv6 over ipv4 (for devices which do not support ipv6)
What 3 data security features does IP sec offer?
Encryption
Data integrity
Authentication
What is the connection establishment process of IPsec?
Peers authenticate and share symmetric crypto keys
Once connected an IPSec tunnel is formed.
What is internet key exchange (IKE)?
Protocol used by IPsec to exchange crypto keys using diffie Hellman algorithm.
A SA (security association) is formed over UDP port 500
What is Encapsulating Security Payload (ESP)?
Encryption and authentication mechanism used by IPsec
What ESP header fields ensure authentication and integrity ?
Security parameter index : identifies which Packets to SA
Sequence number : prevents replay attacks
Integrity check value : calculates checksum over unencrypted data
What are ESPs 2 modes of operation?
Transport: only IP payload is encrypted. Source and destination IP is left intact and assigned protocol 50
Tunnel: entire IP packet is encrypted. ESP then appends it’s own IP information with the tunnel source and destination.
What is Location/ID Separation Protocol?
Protocol designed to reduce growth of global routing tables.
How does LISP work?
LISP routers advertise their prefix’s (endpoint IDs) to a map resolver/map server (mutuality reachable by each site)
EIDs are mapped to RLOC (routing locators) by mr/ms servers and relayed to LISP routers searching for a prefix
What UDP port does LISP use for map request and reply’s?
Port 4342
What are the 3 types of LISP router?
Ingress tunnel router (ITR)
Egress tunnel router (ETR)
Ingress/egress router (xTR)
What is a ingress tunnel routers role?
Encapsulate endpoint traffic inside LISP packet and forwards to a ETR RLOC
iTR also send EID-to-RLOC requests to map server
What is a egress tunnel routers role?
ETR decapsulate packets received by ITR and forward to the EID address.
What is a RLOC
The IP address of a ETR router which is globally reachable.