VPN Flashcards

1
Q

What is AH?

A

Authentication Header
Offers:
1) Authenticity
2) Integrity
3) Authenticates IP header and payload

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
2
Q

What is ESP?

A

Encapsulating Security Payload
Offers:
1) Authenticity
2) Integrity
3) Confidentiality
4) Packet Payload is encrypted

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
3
Q

What is NAT-Traversal?

A

Network Address Translation-Traversal (NAT-T) is a method for getting around IP address translation issues encountered when data protected by IPsec passes through a NAT device for address translation. Any changes to the IP addressing, which is the function of NAT, causes IKE to discard packets. After detecting one or more NAT devices along the datapath during Phase 1 exchanges, NAT-T adds a layer of User Datagram Protocol (UDP) encapsulation to IPsec packets so they are not discarded after address translation. NAT-T encapsulates both IKE and ESP traffic within UDP with port 4500 used as both the source and destination port.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
4
Q

What Protocol and port used in NAT-Traversal?

A

UDP 4500

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
5
Q

What is the maximum number of propagated routes for AWS?

A

100

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
6
Q

What are two ways to propagated routes?

A

1) Static routing
2) Dynamic routing with BGP

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
7
Q

What are the two routing mechanisms supported by a Virtual Private Gateway (VGW)?

A

1) Static routing
2) BGP

How well did you know this?
1
Not at all
2
3
4
5
Perfectly