Overlay Tunnels - IPSec Fundamentals
15 important questions on Overlay Tunnels - IPSec Fundamentals
Which two modes of transport are supported by traditional IPSec?
2. Transport Mode (Only encrypts packet payload, packet routed by original IP Headers)
What are the 4 Headers/Trailers used by IPSec?
2. ESP Header
3. ESP Trailer
4. ESP Auth Trailer
Which data encryption algorithms and hash algorithms should be avoided?
1. DES
2. 3DES
Hash Algorithm
1. MD5
- Higher grades + faster learning
- Never study anything twice
- 100% sure, 100% understanding
Which Diffie-Helman groups should be avoided?
What is the Internet Key Exchange (IKE) protocol used for?
These SAs or Tunnels are used to carry Control Plane and Data Plane traffic for IPSec.
Which versions of IKE are there and what are important differences?
IKEv2 has the following improvements:
1. EAP (Certificate based authentication)
2. Anti-DOS capabilities
3. Fewer messages to establish SA
What is the Internet Security Assocation Key Management Protocol (ISAKMP)?
It uses port 500 for communication between peers.
IKE is the ISAKMP implementation using the Oakley and Skeme key exchange.
Which two phases does IKEv1 go through to setup a VPN Tunnel?
Phase 2: Establish unidirectional IPSec SAs
Which 2 modes can IKEv1 use in Phase 1 negotiation?
2. Aggressive Mode (Faster, less safe, less (3) messages)
How is the method used to establish the IPSec SA called and how many messages does it need.
Instead of the 9 messages in main mode or 6 in aggressive mode with IKEv1, IKEv2 only uses 4 messages. What are the stages it goes through?
Stage 2: Second exchange IKE_AUTH (authenticate previous messages, exchange identities and certificates. Then establish IKE_SA and Child SA (IPSec SA))
What are 5 IPSec VPN protocols available on Cisco devices?
2. Cisco DMVPM (Cisco only)
3. Cisco GET-VPN (Cisco only)
4. FlexVPN (Cisco only)
5. Remote Access VPN (Cisco only)
What is Cisco Dynamic Multipoint VPN (DMVPN)?
What is Cisco Group Encrypted Transport VPN (GET VPN)?
What is Cisco FlexVPN?
Uses virtual access interfaces.
The question on the page originate from the summary of the following study material:
- A unique study and practice tool
- Never study anything twice again
- Get the grades you hope for
- 100% sure, 100% understanding