Download as pdf or txt
Download as pdf or txt
You are on page 1of 3

CCNA RnS V3 200-125

LAB : Configuration of IPSEC VPN

A Virtual Private Network (VPN) provides a secure tunnel across a public network such as
Internet. for organizations to connect users and offices together, without the high costs of
dedicated leased lines.

VPNs are used generally for :

 Client VPNs (Remote Access VPN)- To connect Office to home or “roaming” users
 Site-to-Site VPNs - To connect branch offices to a head office.

Types of VPN protocols

1. Internet Protocol Security or IPSec:

2. Layer 2 Tunneling Protocol (L2TP):

3. Point – to – Point Tunneling Protocol (PPTP):

4. Secure Sockets Layer (SSL) and Transport Layer Security (TLS):

5. OpenVPN:

6. Secure Shell (SSH)

Here we describe IPSec Site-to-Site VPN

IPSec:

IPSEC (Internet Protocol Security), is a suite of protocols, helps us to protect IP traffic on the
network layer.

4 core IPsec services:

 Confidentiality – It means encrypt the data.


 Integrity – It ensures that data has not been tampered or altered using hashing
algorithm.
 Authentication – It confirms the identity of the host sending data, using
 pre-shared keys or CA (Certificate Authority)
 Anti-replay – prevents duplication of encrypted packets

ASHISH 2XCCNA, 2XCCNP, CCIE SEC-WRITTEN


CCNA RnS V3 200-125

IPSEC Framework

Confidentiality (Encryption)

On the sending side data is encrypted and on the receiving side data needs to be decrypted.
There are mainly two type’s encryption/decryption keys:

Symmetric keys:

The same key is used to both encrypt and decrypt data. that is, the same key is used to
encrypt a packet (sending device) and to decrypt the packet (receiving device).

Examples of keys:

 DES (Data Encryption Standard) – 56-bit key


 3DES (Triple Data Encryption Standard) – 168-bit key
 AES (Advanced Encryption Standard) - 128, 192, or 256-bit key
 Blowfish – up to a 448-bit key

Asymmetric keys:

In this case two separate keys are required. One for encryption (the public key) and other is
for decryption (the private key).

Public keys are openly exchanged but Private keys are never exchanged.

ASHISH 2XCCNA, 2XCCNP, CCIE SEC-WRITTEN


CCNA RnS V3 200-125

........................CONTINUES.............................

MORE DETAILS IN MY CCNA RnS LAB GUIDE


Price is only 15 USD
Payment Method = PayPal

ASHISH 2XCCNA, 2XCCNP, CCIE SEC-WRITTEN

You might also like