VPN / IPSEC Flashcards

1
Q

GRE

A

Generic Routing Encapsulation: tunnel between two endpoints

  • encapsulates traffic inside of ip
  • no encryption! –> use VPN
How well did you know this?
1
Not at all
2
3
4
5
Perfectly
2
Q

IPSec

A

Internet Protocol Security: CIA + anti-replay for L3

- encryption and packet signing

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
3
Q

AH

A

Authentication Header: hash of the packet and a shared key –> provides authentication

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
4
Q

DMVPN

A

Dynamic Multipoint VPN:

  • dynamic mesh, built on-demand using mGRE (multipoint Generic Router Encapsulation)
How well did you know this?
1
Not at all
2
3
4
5
Perfectly
5
Q

anti-replay in IPSec

A

checks sequence numbers on all packets prior to transmission

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
6
Q

5 IPSec steps

A
  1. key exchange request
  2. IKE phase 1
  3. IKE phase 2
  4. Data transfer
  5. Tunnel termination
How well did you know this?
1
Not at all
2
3
4
5
Perfectly
7
Q

IKE 2 modes:

A

Internet Key Exchange

main mode: 3 two-way exchanges between the peers (algorithms, DH to generate shared secret key, authentication)

aggressive mode: way faster but less secure –> everything is suggested by the receiver

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
8
Q

SA

A

Security Association : negotiated in IKE phase 1, used for ISAKMP

includes authentication method, encryption method, DH groups, expiration time, shared secret key

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
9
Q

IKE phase 2

A

negociate SA to set up the IPSec Tunnel

uses Quick Mode to negotiate shared IPsec policy

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
10
Q

VPN HEADEND

A

VPN concentrator used to terminate IPSEC vpn tunnels within a router or other device

How well did you know this?
1
Not at all
2
3
4
5
Perfectly