YouTube2Text

ENSA Module 8 VPN and IPSec Concepts — Transcript

by Santelmo · 5,132 words · 1,057 segments · language en · Watch on YouTube

Full transcript

  1. 0:03[Music]
  2. 0:13hello there
  3. 0:14welcome to another video on
  4. 0:18enterprise networking security and
  5. 0:20automation version 7 or ansa
  6. 0:23so on this video we are going to cover
  7. 0:25module 8
  8. 0:27which discusses vpn and ipsec concepts
  9. 0:31all right
  10. 0:35okay so what we will learn on this
  11. 0:38module
  12. 0:40so basically the module covers vpn and
  13. 0:43ipsec concepts
  14. 0:44and at the end of the module we should
  15. 0:47be able to explain how vpns
  16. 0:48and ipsec are used to secure a site to
  17. 0:52site and their remote access
  18. 0:53connectivity
  19. 0:55so this includes the following topic
  20. 0:58title and its objectives so for the vpn
  21. 1:00technology
  22. 1:02we should be able to describe the
  23. 1:04benefits of a vpn technology
  24. 1:07for the types of vpn describe different
  25. 1:10types of vpns
  26. 1:12and ipsec explain how the ipsec
  27. 1:15framework is used
  28. 1:17to secure a network traffic
  29. 1:21okay so let's start we are going to
  30. 1:24discuss
  31. 1:25first the vpn technology or the virtual
  32. 1:28private
  33. 1:29network so basically
  34. 1:32vpn is
  35. 1:35to secure a network traffic between
  36. 1:38sites
  37. 1:39and users organization uses
  38. 1:42virtual private networks to create an
  39. 1:45end-to-end private network connections
  40. 1:48so a vpn is a virtual in that it carries
  41. 1:52information
  42. 1:53within a private network but that
  43. 1:56information is actually transported
  44. 1:58over the public network as you see here
  45. 2:00on the diagram
  46. 2:02right so a vpn is a private
  47. 2:07in that the traffic is encrypted to keep
  48. 2:09the data confidential
  49. 2:11while it is transported over the public
  50. 2:13network or
  51. 2:14the internet so the figure shows a
  52. 2:17collection of various types of vpns
  53. 2:20managed by an enterprise main site
  54. 2:25so the tunnel enables the remote sites
  55. 2:28which includes the business partners
  56. 2:31with cisco routers okay a regional
  57. 2:34office
  58. 2:34with a cisco asa firewall
  59. 2:38and a smallhole office home office or
  60. 2:40soho
  61. 2:41with a cisco router and a mobile worker
  62. 2:45using a cisco any connect
  63. 2:48okay so these sites here are connected
  64. 2:51to the main site
  65. 2:53using a channel which enables remote
  66. 2:55sites and users
  67. 2:57to access main sites network resource
  68. 2:59securely
  69. 3:02all right so what are the benefits of
  70. 3:06vpns
  71. 3:07so modern vpns now support encryption
  72. 3:10features
  73. 3:11such as the ipsec or the internet
  74. 3:14protocol security
  75. 3:17and the ssl or the secure socket layer
  76. 3:21so the major benefits of vpns includes
  77. 3:25cost savings security
  78. 3:29scalability and compatibility
  79. 3:35so vpns are commonly deployed in one of
  80. 3:37the following configurations
  81. 3:39so it is either side to side or remote
  82. 3:43access
  83. 3:45so a side to side vpn is created when a
  84. 3:48vpn terminating devices
  85. 3:50also called as a vpn gateways
  86. 3:55are pre-configured with information to
  87. 3:57establish a secure vpn
  88. 4:03vpn traffic is only encrypted between
  89. 4:06these devices
  90. 4:07so internal hosts has no knowledge
  91. 4:10that a vpn is being used
  92. 4:17all right so next is a side-to-side
  93. 4:21remote access vpns okay
  94. 4:24so a remote access vpn is dynamically
  95. 4:28created
  96. 4:28to establish a secure connection between
  97. 4:31a client
  98. 4:32and a vpn terminating device
  99. 4:35all right so for example a remote access
  100. 4:38ssl
  101. 4:39vpn is used when you check your banking
  102. 4:41information online
  103. 4:44okay next
  104. 4:48now there are many options available to
  105. 4:50secure an enterprise traffic
  106. 4:52so these solutions vary depending on who
  107. 4:55is managing the vpn so vpns can be
  108. 4:59managed and deployed as
  109. 5:00an enterprise vpns or a service provider
  110. 5:04vpns
  111. 5:06so when you say enterprise vpns these
  112. 5:09are common solutions for securing an
  113. 5:11enterprise traffic
  114. 5:12across the internet so a site-to-site
  115. 5:15and remote access vpns are created
  116. 5:18and managed by the enterprise using the
  117. 5:21ipsec
  118. 5:22and ssl vpns
  119. 5:26now on the other hand servicer service
  120. 5:29provider vpns
  121. 5:30created and managed by the provider
  122. 5:33network
  123. 5:34the provider uses the multi-protocol
  124. 5:37label switching or the mpls
  125. 5:39at a layer 2 or layer 3
  126. 5:42to secure or to create a secure channels
  127. 5:45between an enterprise sites
  128. 5:47effectively segregating the traffic from
  129. 5:49the customer's traffic
  130. 5:52so the figure here okay
  131. 5:55so listed different types of enterprise
  132. 5:58managed and service provider managed vpn
  133. 6:01deployments
  134. 6:03okay next
  135. 6:07so let's talk about the types of vpns
  136. 6:10okay so in the previous topic
  137. 6:14you learned about the basics of vpn
  138. 6:18here you will learn about the types of
  139. 6:20vpn
  140. 6:22so vpns have become the logical solution
  141. 6:26for remote access connectivity for many
  142. 6:28reasons
  143. 6:30so as shown here on the diagram the
  144. 6:32remote access the vpn
  145. 6:34remote and mobile users characterized by
  146. 6:39a user computer here with a browser and
  147. 6:41cisco any connect secure mobility client
  148. 6:45okay so vpn
  149. 6:48users here are securely connected to the
  150. 6:52enterprise by creating an encrypted
  151. 6:54channel in between
  152. 6:55okay so the remote users can securely
  153. 6:58replicate their
  154. 6:59enterprise security access including
  155. 7:02email
  156. 7:02and network applications so the remote
  157. 7:05access vpns
  158. 7:07also allow contractors and partners to
  159. 7:10have limited access to the specific
  160. 7:11servers
  161. 7:12web pages or files as required
  162. 7:17okay so this means that these users can
  163. 7:20contribute to the
  164. 7:22business productivity without
  165. 7:23compromising the network security
  166. 7:27okay so
  167. 7:30next is a client vpn connection
  168. 7:34okay and a client-less
  169. 7:38vpn okay so it's either a client-based
  170. 7:41or client-less vpn connection so let's
  171. 7:44start
  172. 7:44or discuss first the client-less vpn
  173. 7:47connection
  174. 7:48so this is the connection where ian is
  175. 7:52secured using a web browser
  176. 7:55ssl connection ssl is mostly used to
  177. 7:59protect http traffic
  178. 8:02okay or https
  179. 8:05and email protocols such as imap
  180. 8:08or pub3 so for example
  181. 8:13https is actually an http using an ssl
  182. 8:16panel
  183. 8:18so the ssl connection is first
  184. 8:20established
  185. 8:22and then data or http data
  186. 8:25is exchanged over the connection okay
  187. 8:28so that is using a browser
  188. 8:33now for the client based vpn connection
  189. 8:37okay vpn client software such as the
  190. 8:40cisco any connect here
  191. 8:43secure mobility client must be installed
  192. 8:45on the remote users
  193. 8:46and device okay it could be on a laptop
  194. 8:49or
  195. 8:50a pump top or a cell phone now
  196. 8:53client-based vpn users
  197. 8:56must initiate the vpn connection using
  198. 8:59the vpn client and then authenticate the
  199. 9:01destinations of vpn gateway
  200. 9:04okay so when the remote users are
  201. 9:06authenticated
  202. 9:08they have access to the corporate files
  203. 9:11and applications
  204. 9:12so the vpn client software encrypts
  205. 9:15traffic
  206. 9:16using the ipsec or ssl and forwards
  207. 9:20it over the internet to the destinations
  208. 9:22vpn gateway
  209. 9:24so that's how it works okay
  210. 9:27so the browser based here uses a client
  211. 9:30less
  212. 9:32okay vpn true ssl connection
  213. 9:36and the roaming users here
  214. 9:39uses a software called cisco and connect
  215. 9:42to connect to the enterprise
  216. 9:46all right next ssl vpns
  217. 9:51so when a client negotiates an ssl vpn
  218. 9:54connection
  219. 9:55with the vpn gateway it actually
  220. 9:58connects using
  221. 9:59tls or the transport layer security
  222. 10:03so tls is a newer version of ssl
  223. 10:06and is sometimes expressed as ssl over
  224. 10:09tls
  225. 10:10however both terms are often used
  226. 10:14interchangeably
  227. 10:16okay now ssl uses the public
  228. 10:19infrastructure and digital certificates
  229. 10:21to authenticate peers
  230. 10:23so the type of vpn method implemented is
  231. 10:26based
  232. 10:27on the access requirements of the users
  233. 10:30and organizations i.t processes
  234. 10:33so the table here compares ipsec
  235. 10:37and ssl remote access deployments okay
  236. 10:41so considering the application supported
  237. 10:44the authentication strength all right so
  238. 10:46encryption strength
  239. 10:48connection complexity and connection
  240. 10:50option
  241. 10:53okay so when we're talking about the
  242. 10:56application support
  243. 10:58so ipsec extensive all ip based
  244. 11:01application
  245. 11:02compared to that of ssl having unlimited
  246. 11:05only web-based applications and file
  247. 11:07sharing
  248. 11:08okay so when it comes to authentication
  249. 11:11strength
  250. 11:12okay so ipsec is strong so it uses a
  251. 11:15towing authentication
  252. 11:17with a shared keys or digital
  253. 11:19certificates
  254. 11:21okay so whereas ssl
  255. 11:24is moderate one-way or two-way
  256. 11:27authentication
  257. 11:29okay so for the encryption strength
  258. 11:32so ipsec is strong the key length is 56
  259. 11:36to 256 bits
  260. 11:40whereas for ssl it's moderate to strong
  261. 11:44so key length is at 40 to 256 bits
  262. 11:49connection complexity well i present
  263. 11:52medium
  264. 11:52requires vpn client installed on the
  265. 11:54host
  266. 11:56whereas ssl it just requires a web
  267. 11:59browser on the host
  268. 12:00so any web browsers will do okay
  269. 12:04and then last is the connection option
  270. 12:07so
  271. 12:07hypersec is limited only specific
  272. 12:11devices with specific configurations can
  273. 12:13connect
  274. 12:14whereas ssl extensive any device
  275. 12:18with a web browser can connect
  276. 12:21all right next
  277. 12:26so types of vpns side to side hypersex
  278. 12:29vpns
  279. 12:30okay so side to side
  280. 12:34vpns connect networks across an
  281. 12:36untrusted network
  282. 12:37such as the internet so we are talking
  283. 12:39about the public
  284. 12:40network here okay so
  285. 12:44and hosts sends and receives
  286. 12:47normally unencrypted cpip traffic
  287. 12:50through a vpn gateway
  288. 12:52so the vpn terminating is
  289. 12:55typically called a vpn gateway a vpn
  290. 12:59gateway device could be a router or a
  291. 13:01firewall
  292. 13:02as shown in the figure here okay so
  293. 13:04which uses a router here
  294. 13:06and a firewall on the other end so for
  295. 13:09example
  296. 13:10the cisco adaptive security appliance or
  297. 13:13the asa
  298. 13:15shown on the right side of this figure
  299. 13:17okay it's a standalone firewall device
  300. 13:20that combines firewall vpn concentrator
  301. 13:23and intrusion prevention functionality
  302. 13:25into a software
  303. 13:26image okay
  304. 13:30next is the vpn gateway encapsulates
  305. 13:34and encrypts outbound traffic from a
  306. 13:37site and sends the traffic through a vpn
  307. 13:39tunnel
  308. 13:40to the vpn gateway at the target site
  309. 13:44so the receiving vpn gateway strips the
  310. 13:46headers
  311. 13:48decrypts the content and relates the
  312. 13:50packet towards the target
  313. 13:52host inside the fry bit network
  314. 13:55so side to side vpns are typically
  315. 13:57created and secured
  316. 13:59using an ip security or ipsec
  317. 14:03okay next
  318. 14:07so agree over ipsec so when you say gri
  319. 14:11it's a generic routing encapsulation
  320. 14:13this is an unsecured
  321. 14:15side-to-side vpn tunneling protocol so
  322. 14:18i'll show you
  323. 14:20how to configure gri on the next video
  324. 14:24so a grid panel can encapsulate various
  325. 14:27network layers
  326. 14:29as well as the multicast and broadcast
  327. 14:30traffic
  328. 14:32okay so grid does not by default support
  329. 14:36encryption
  330. 14:37and therefore it does not provide a
  331. 14:39secure vpn tunnel
  332. 14:40so it just provides connectivity between
  333. 14:42the two end nodes
  334. 14:44all right so a grid packet can be
  335. 14:47encapsulated into an ipsec
  336. 14:49packet to forward it securely to the
  337. 14:52destination vpn gateway
  338. 14:56so therefore routing protocols will not
  339. 14:58exchange routing information over an
  340. 15:00ipsec
  341. 15:01vpn okay so the standard ipsec vpn
  342. 15:06non-gri okay can create a secure tunnel
  343. 15:09for unicast traffic
  344. 15:13okay so to solve this problem
  345. 15:16we can encapsulate routing protocol
  346. 15:19using a green
  347. 15:20packet and that encapsulates the grid
  348. 15:22packet into an ipesec packet
  349. 15:24to forward it securely to the
  350. 15:26destination vpn gateway
  351. 15:28so encapsulating green into an ipsec
  352. 15:30allows multicast routing protocol
  353. 15:32updates
  354. 15:34to be secured through a vpn
  355. 15:38okay so we can combine the green
  356. 15:41and ipsec to provide a secure vpn
  357. 15:44connectivity
  358. 15:47all right next so
  359. 15:50the terms used to describe the
  360. 15:52encapsulation for gree over ipsec tunnel
  361. 15:55are passenger protocol carrier protocol
  362. 15:58and
  363. 15:58transport protocol so we are talking
  364. 16:01about three protocols here
  365. 16:03combined okay so the passenger protocol
  366. 16:06this is an original packet that is to be
  367. 16:08encapsulated by gri
  368. 16:10so it could be an ipv for our ipv6
  369. 16:12packet
  370. 16:13a routing update and more
  371. 16:16now for the carrier protocol gree is
  372. 16:19a carrier protocol that encapsulates the
  373. 16:21original passenger packet
  374. 16:24and transport protocol this is the
  375. 16:27protocol that would actually be used to
  376. 16:30forward the packet
  377. 16:31so this could be either ipb4
  378. 16:35for ipv6 okay
  379. 16:38so i p here is for the transport
  380. 16:41protocol
  381. 16:42green is the carrier protocol
  382. 16:45okay and this one here the ip the tcp
  383. 16:48and the data these are the passenger
  384. 16:50protocols
  385. 16:52okay next
  386. 16:56so for example you're gonna have here
  387. 16:59the branch
  388. 17:00okay and the headquarter so the brands
  389. 17:04and the headquarters need to exchange
  390. 17:05ospf routing information
  391. 17:07over the ipsec vpn here
  392. 17:10okay so agree over ipsec is used to
  393. 17:13support the routing protocol traffic
  394. 17:15over the ipsec vpn so specifically the
  395. 17:18ospf packets
  396. 17:19example uh passenger protocol
  397. 17:23would be encapsulated by gri or a
  398. 17:25carrier protocol and subsequently
  399. 17:27encapsulated
  400. 17:28in an ipsec vpn tunnel okay
  401. 17:32so with that with the combinations of
  402. 17:34gree and ipsec
  403. 17:35for sure we'll gonna have a secure vpn
  404. 17:38connection
  405. 17:39between a branch and a headquarter
  406. 17:44okay
  407. 17:47all right so the next one is a dynamic
  408. 17:51multi-point vpns
  409. 17:53okay so side to side ipsec vps and grid
  410. 17:56over ibsec
  411. 17:57are not sufficient when the enterprise
  412. 18:00adds many more sites
  413. 18:02okay so the dynamic multi-point vpn
  414. 18:05is a cisco software solution for
  415. 18:08building multiple vpns
  416. 18:09in an easy dynamic and scalable manner
  417. 18:13okay so dynamic multi-point vpn or dm
  418. 18:17vpn
  419. 18:18is a cisco software solution for
  420. 18:20building
  421. 18:21multiple vpns in an easy dynamic
  422. 18:24scalable
  423. 18:26manner so like other vpn types dmvpn
  424. 18:30relies on ipsec to provide secure
  425. 18:34transport
  426. 18:34over public networks such as the
  427. 18:37internet
  428. 18:38okay so
  429. 18:42it uses a hab and spoke configuration to
  430. 18:45establish a full mesh topology
  431. 18:47so when they haven't spoke okay so we
  432. 18:49have different branches
  433. 18:51okay so serves as the spoke and maybe
  434. 18:54the main site
  435. 18:55serves as the hub okay
  436. 18:59so a spoke sites establish a secure vpn
  437. 19:01channels with a hub
  438. 19:02site okay and then its
  439. 19:06site is configured using a multi-point
  440. 19:09generic routing encapsulation or mg
  441. 19:13the m grid tunnel interface allows a
  442. 19:15single degree interface
  443. 19:17to dynamically support the multiple
  444. 19:19ipsec tunnels
  445. 19:21so therefore when the new site requires
  446. 19:24a secure connection
  447. 19:26the same configuration on the hub site
  448. 19:28would support the tunnel
  449. 19:30so no additional configuration would be
  450. 19:33required
  451. 19:35okay so spoke sites can also obtain
  452. 19:38information about each other
  453. 19:40and alternatively build direct tunnels
  454. 19:43between themselves
  455. 19:44so we call it hope or spoke bespoke
  456. 19:46tunnels
  457. 19:50okay
  458. 19:52right so the next one is the ipsec
  459. 19:55virtual tunnel interface
  460. 19:57or the vti so the vti simplifies the
  461. 20:00configuration process
  462. 20:02required to support multiple sites and
  463. 20:04the remote access
  464. 20:07so like dmvpns ipsec
  465. 20:11virtual channel interface or vti
  466. 20:14simplifies the configuration process
  467. 20:16required to support multiple sites and
  468. 20:18remote access
  469. 20:19so ipsec vti configurations are applied
  470. 20:22to
  471. 20:22the virtual interface instead of static
  472. 20:24mapping the ips accessions the
  473. 20:27physical interface
  474. 20:32okay so the ipsec vti is capable of
  475. 20:35sending and receiving both
  476. 20:37ip unicast and multicast encrypted
  477. 20:39traffic
  478. 20:40so therefore routing protocols are
  479. 20:43automatically supported
  480. 20:44without having to configure degree
  481. 20:46channels that's a good thing about the
  482. 20:47ipsec vti
  483. 20:49okay so the ipsec vti can be configured
  484. 20:52between sites
  485. 20:53or in a hub and spoke topology
  486. 21:00okay
  487. 21:02okay so the next type of vpn is a
  488. 21:05service provider
  489. 21:06mpls vpns so traditional service
  490. 21:10provider wants solutions
  491. 21:12such as list lines frame relay
  492. 21:15and atm connections are inherently
  493. 21:20secure in their designs okay so we've
  494. 21:23talked about this technology
  495. 21:25on the previous video
  496. 21:28so today service provider uses the mpls
  497. 21:31in their core network
  498. 21:33so traffic is forwarded through the mpls
  499. 21:35backbone
  500. 21:36using labels so traffic is secure
  501. 21:39because service provider customers
  502. 21:41cannot see each other's traffic
  503. 21:44so mpls can provide clients with managed
  504. 21:47vpn solutions so therefore
  505. 21:49securing traffic between client sites is
  506. 21:52the responsibility of
  507. 21:54the service provider so there are two
  508. 21:57types of mpls vpn solutions supported by
  509. 22:00service providers so these are the layer
  510. 22:023
  511. 22:03mpls vpn and the layer 2
  512. 22:06mpls vpn so as the name implies
  513. 22:10they differ and operates on different
  514. 22:13layers
  515. 22:14okay so layer three and layer two
  516. 22:20all right now let's talk about ipsec now
  517. 22:26okay now on this powerpoint
  518. 22:29okay the official powerpoint of cisco so
  519. 22:32this includes
  520. 22:33a video okay so to see this video
  521. 22:37you can go ahead and log into your
  522. 22:39nethacker account and see this video
  523. 22:41all right so for this video lecture
  524. 22:44so i'm going to skip this one okay
  525. 22:50so let's talk about the ipsec
  526. 22:52technologies
  527. 22:53so ipsec is an ietf standard
  528. 22:57that defines how a vpn can be secured
  529. 23:00across
  530. 23:00ip networks so ipsec protects
  531. 23:04and authenticates ip packets between
  532. 23:06source and destination
  533. 23:08and provides these essential security
  534. 23:09functions
  535. 23:11ipsec can only protect traffic from
  536. 23:14layer 4 through layer 7.
  537. 23:18i'll repeat ipsec can only protect
  538. 23:20traffic from layer
  539. 23:22four through layer seven
  540. 23:25okay so this ipsec technologies
  541. 23:28provides the following security
  542. 23:30functions so you've got confidentiality
  543. 23:32integrity origin authentication
  544. 23:36and the daffy helmet okay so when we've
  545. 23:39talked about confidentiality
  546. 23:41it uses encryption algorithms to prevent
  547. 23:44cyber criminals from reading the packet
  548. 23:46contents
  549. 23:47so that's confidentiality okay
  550. 23:50integrity it uses a hash algorithm or
  551. 23:53hashing algorithm
  552. 23:55to ensure that the packets have not been
  553. 23:57altered between the source
  554. 23:59and destination or while in transit
  555. 24:03origin authentication uses the ike
  556. 24:07protocol
  557. 24:08to authenticate source and destination
  558. 24:11and the daffy helmet
  559. 24:12is used to secure the key exchange
  560. 24:16okay so ipsec technologies basically
  561. 24:19uses a lot of protocols
  562. 24:23and security measures to ensure that the
  563. 24:25connection between
  564. 24:26sites are safe and secure
  565. 24:30all right so we will be covering all
  566. 24:32those protocols
  567. 24:34which ensures ipsec technologies
  568. 24:37a secure connection
  569. 24:40okay now
  570. 24:46so ipsec is not bound to any specific
  571. 24:48rules
  572. 24:49for secure communications so ipsec can
  573. 24:52easily integrate
  574. 24:53new security technologies without
  575. 24:56updating the
  576. 24:57ipsec standards okay
  577. 25:00so ipsec standards or iberisik
  578. 25:03technologies
  579. 25:04covers the ipsec protocols for the
  580. 25:06financiality
  581. 25:08integrity authentication and the deputy
  582. 25:11helmet
  583. 25:12okay so the currently available
  584. 25:14technologies
  585. 25:16are aligned to their specific security
  586. 25:18function
  587. 25:19so the open slot shown in the ipsec
  588. 25:22framework
  589. 25:23on this figure okay
  590. 25:28so we have to have a combinations
  591. 25:31of this choices here okay so to come up
  592. 25:35with our own combo
  593. 25:37okay so the open slot shown in the
  594. 25:40ibiseg framework in the figure can be
  595. 25:43filled with
  596. 25:44any of the choice that are available for
  597. 25:47that i project function
  598. 25:48to create a unique security association
  599. 25:51or
  600. 25:52sa okay now let's talk about the ipsec
  601. 25:56protocol first
  602. 25:57so the choices for ipsec protocol
  603. 26:00includes authentication header
  604. 26:02okay or ah or
  605. 26:05encapsulation security protocol esp
  606. 26:10a h authenticates the layer 3 packet
  607. 26:13esp encrypts the layer 3 packet
  608. 26:17all right so therefore we could have a
  609. 26:20combination of the both
  610. 26:22of are combinations of these two
  611. 26:26okay now when we combined ah and dsp
  612. 26:31okay so that is rarely used
  613. 26:35as this combination will not
  614. 26:36successfully traverse
  615. 26:38in a network address translations device
  616. 26:40or not device
  617. 26:46next is confidentiality okay so
  618. 26:50what do we have in confidentiality so
  619. 26:52encryption ensures confidentiality
  620. 26:54of the layer 3 packet so choices
  621. 26:57includes
  622. 26:58desk okay or the data encryption
  623. 27:00standards
  624. 27:02triple desk or 3ds
  625. 27:06you also have the aes or the advanced
  626. 27:08encryption standard
  627. 27:10or the software optimized encryption
  628. 27:13algorithm seal so
  629. 27:16no encryption is also an option
  630. 27:21okay so you could have combinations with
  631. 27:24hypersex
  632. 27:25and then without encryption
  633. 27:28okay all right so the next one
  634. 27:32is integrity so integrity ensures that
  635. 27:35the data arrives
  636. 27:36unchanged at the destination using a
  637. 27:39hash algorithm
  638. 27:41so this includes the md5
  639. 27:45okay or the message digest 5 and
  640. 27:48sha which means secure house algorithm
  641. 27:51[Music]
  642. 27:52okay the next one is authentication
  643. 27:57so ipsec uses an ike
  644. 28:01okay or the interna internet key
  645. 28:03exchange
  646. 28:04to authenticate the users and devices
  647. 28:07that can carry out communication
  648. 28:08independently
  649. 28:10so ikey uses several types of
  650. 28:13authentication
  651. 28:15the plain username and password okay so
  652. 28:18one time password biometrics
  653. 28:22and pressured case or ps case which are
  654. 28:25which is common
  655. 28:26and also it could be a digital
  656. 28:28certificate using
  657. 28:30the rsa algorithm or the real diverse
  658. 28:33chamier adelman rsa algorithm
  659. 28:37okay so for the authentication the
  660. 28:40choice is ours
  661. 28:42which either we use psk okay or the
  662. 28:45pre-shared keys
  663. 28:47and the rsa
  664. 28:50all right so the last one is a defe
  665. 28:54helman
  666. 28:55so ipsec uses the dh algorithm to
  667. 28:58provide a public key exchange
  668. 28:59method for two peers to establish a
  669. 29:02shared secret key
  670. 29:04so there are several different groups to
  671. 29:07choose from
  672. 29:07including the age 14 15 16
  673. 29:11or days 19 20 21 and 24
  674. 29:15so dh1 2 and 5 are no longer
  675. 29:19recommended okay now this ipsec
  676. 29:22technologies
  677. 29:23would allow the administrator to come up
  678. 29:27with a great combinations
  679. 29:30okay to have a secure
  680. 29:33point-to-point or side-to-side
  681. 29:35connectivity
  682. 29:38all right okay
  683. 29:41so let's have an example of security
  684. 29:45association here
  685. 29:47or sa okay so select take a look at the
  686. 29:50sa example number one so ipsec protocol
  687. 29:53uses
  688. 29:54ah okay so no confidentiality because
  689. 29:59encryption
  690. 30:00is it's an option or you could have
  691. 30:04without encryption adopted all right
  692. 30:07so integrity uses an md5 authentication
  693. 30:10is psk
  694. 30:11daffy helmand sdh16
  695. 30:14so daffy helmet is just used to secure
  696. 30:17the keys
  697. 30:18so it doesn't um
  698. 30:21encrypt or provide encryptions for the
  699. 30:23data okay
  700. 30:26now on the security association two here
  701. 30:29okay so it uses or it prefer esp
  702. 30:32confidentiality uses aes integrity is
  703. 30:36sha authentication is rsa and d3 helmand
  704. 30:39uses dh24
  705. 30:42okay so an sa is the basic building
  706. 30:46block
  707. 30:46of ipsec so on the next video i'll show
  708. 30:50you how to configure an ipsec
  709. 30:52okay so it's just that on this
  710. 30:54presentation or video
  711. 30:56we are going to cover only the concepts
  712. 30:58of
  713. 30:59vpn and ipsec now when establishing a
  714. 31:03vpn link
  715. 31:04the peers must share the same essay
  716. 31:07so to negotiate key exchange parameters
  717. 31:11so establish a shared key authenticate
  718. 31:13each other and negotiate encryption
  719. 31:15parameters
  720. 31:16so if you have used an sa with this
  721. 31:19combination on router one
  722. 31:21okay just make sure on the other end you
  723. 31:24have the same combinations or same combo
  724. 31:27okay so notice that sa example one is
  725. 31:31using
  726. 31:32without encryption here that's possible
  727. 31:36it is allowed okay
  728. 31:40next the ipsec protocol encapsulation
  729. 31:45so choosing the ipsec protocol
  730. 31:47encapsulation is the first building
  731. 31:48block of the framework
  732. 31:50so you have to choose first on ipsec
  733. 31:53okay confidentiality integrity
  734. 31:56authentication and the daffy helmet okay
  735. 32:00so the ipsec encapsulates packets using
  736. 32:03the ah
  737. 32:04or the espr encapsulation security
  738. 32:07protocol
  739. 32:09so the ah it provides data
  740. 32:11authentication and integrity
  741. 32:13but it does not provide data
  742. 32:15confidentiality or encryption
  743. 32:18all right so all text is transported and
  744. 32:20encrypted
  745. 32:23okay next
  746. 32:26esp it provides confidentiality by
  747. 32:30performing encryption on the ip packet
  748. 32:33esp provides authentication
  749. 32:36for the inner ip packet and esp header
  750. 32:39so authentication provides data origin
  751. 32:42authentication
  752. 32:43and data integrity so although both
  753. 32:46encryption and authentication are
  754. 32:48optional in esp
  755. 32:49at a minimum one of the most or
  756. 32:52one of them must be selected
  757. 32:56okay so again
  758. 33:00the choice of ah or esp establishes
  759. 33:03which other building blocks are
  760. 33:04available so ah
  761. 33:06is appropriate only when confidentiality
  762. 33:10is not required or permitted
  763. 33:12okay and esp provides both
  764. 33:15confidentiality
  765. 33:17and authentication
  766. 33:20okay so again be careful on
  767. 33:23building your own combo okay for these
  768. 33:26security associations as your sa
  769. 33:29is the building block of the ipersec
  770. 33:34okay next let's talk about
  771. 33:37confidentiality
  772. 33:39okay so confidentiality is achieved
  773. 33:42by encrypting the data as shown here on
  774. 33:45the diagram
  775. 33:47okay so the degree of confidentiality
  776. 33:49depends
  777. 33:50on the encryption algorithm and the
  778. 33:53length of the key used
  779. 33:54in encryption algorithm right
  780. 33:57so if someone tries to hack the key
  781. 34:01through a brute force attack the number
  782. 34:04of possibilities to try
  783. 34:06is a function of the length of that key
  784. 34:09so the time to process the all
  785. 34:12possibilities
  786. 34:13is a function of the computer power
  787. 34:17of the attacking device so the shorter
  788. 34:19the key
  789. 34:21the easier it is to break okay so a
  790. 34:2464-bit key
  791. 34:27can take approximately one year to break
  792. 34:29with a relatively sophisticated computer
  793. 34:32okay can you imagine that so 64 bit
  794. 34:36one year of course you're gonna have the
  795. 34:39most sophisticated computer to do that
  796. 34:42okay so what if you have 128 bit
  797. 34:47okay so with 128 b
  798. 34:50or bit okay the same machine can
  799. 34:53take roughly 10 raised to the 19 or that
  800. 34:56would be
  801. 34:5810 quintillion years to decrypt
  802. 35:01okay so well the higher the number of
  803. 35:04bits
  804. 35:06okay so the secure your data is
  805. 35:10all right
  806. 35:15next concentration so the encryption
  807. 35:18algorithm highlighted in the figure
  808. 35:20are all symmetric key cryptosystems
  809. 35:24okay so this uses 56-bit key
  810. 35:283ds uses three independent 56 bit
  811. 35:31that's why it's called 3ds okay
  812. 35:34and then the aes offers three different
  813. 35:37key lengths so 128
  814. 35:39192 and 256 bits
  815. 35:43seal is a stream cipher which
  816. 35:46means it encrypts data continuously
  817. 35:49rather than encrypting blocks of data
  818. 35:51so seal uses 160 bitkey
  819. 35:54so the higher the number okay or the
  820. 35:57higher number of bit
  821. 35:58so the more secure your data is so the
  822. 36:01encryption algorithms
  823. 36:02in here would merely depend
  824. 36:05depend on the administrator
  825. 36:10okay
  826. 36:12okay so let's have an integrity test
  827. 36:15here
  828. 36:16okay when we're talking about data
  829. 36:17integrity that means that the data that
  830. 36:19is received is exactly the same data
  831. 36:21that was sent
  832. 36:24okay so potentially data could be
  833. 36:27intercepted
  834. 36:28and modified so for example on this
  835. 36:31diagram
  836. 36:32okay so we have here paid to alex 100
  837. 36:36okay and then
  838. 36:40the ending hash pay to jeremy one
  839. 36:42thousand dollars
  840. 36:44okay so in here
  841. 36:49so assuming that the check is
  842. 36:52100 that's written to pay alex right
  843. 36:56the check is then mailed to alex but it
  844. 36:59is intercepted by
  845. 37:01a threat actor maybe okay
  846. 37:05the threat actor changes the name on the
  847. 37:07check
  848. 37:08and make it jeremy so when it was sent
  849. 37:12it was alex but somewhere along the way
  850. 37:14all right
  851. 37:15it was changed to jeremy and that 100
  852. 37:18there
  853. 37:19become 1000.
  854. 37:22okay so the threat actor changes the
  855. 37:24name of the check
  856. 37:26to jeremy and the amount of the check to
  857. 37:291 000
  858. 37:29and attempts to cash it all right so
  859. 37:33depending on the quality
  860. 37:34of the forgery in the altered check
  861. 37:37the attacker could be successful okay
  862. 37:41so again when we've talked about
  863. 37:43integrity
  864. 37:44the data that was sent should be the
  865. 37:47same data
  866. 37:48that is to be received okay
  867. 37:52or the data that is received is exactly
  868. 37:55the same data that was sent
  869. 37:58okay there should be no modifications
  870. 38:01while in transit
  871. 38:05all right so because
  872. 38:08vpn data is transported over the public
  873. 38:11internet so a method of proving
  874. 38:13data integrity is required to guarantee
  875. 38:16that the content has not been altered
  876. 38:18while in transit
  877. 38:20okay so the hash message authentication
  878. 38:24code or hmac
  879. 38:26is a data integrity algorithm that
  880. 38:28guarantees
  881. 38:30the integrity of the message using the
  882. 38:32hash value
  883. 38:34okay so it could be an md5
  884. 38:37okay which uses 128 bit shared secret
  885. 38:41key
  886. 38:41or the sha
  887. 38:45or the sha which uses 160 bit secret key
  888. 38:49okay so md5 or the variable length
  889. 38:52message
  890. 38:53and 128 bit shared key are combined and
  891. 38:56run
  892. 38:57through the hmac md5 has algorithm so
  893. 39:00the output is
  894. 39:01128 bit hash okay
  895. 39:05so we're talking about this now for sure
  896. 39:09the variable length message and the 160
  897. 39:11bit shared keys
  898. 39:13are combined and run through the hmac
  899. 39:16shell one algorithm and the output is
  900. 39:19160 bit
  901. 39:20hash all right so
  902. 39:24that's a lot of number of bits
  903. 39:28okay now let's talk about authentication
  904. 39:31so there are two hypersecure
  905. 39:32authentications
  906. 39:33used okay so you've got the pre-shared
  907. 39:36key or the psk
  908. 39:39and the rsa so
  909. 39:44when conducting business long distance
  910. 39:46you must know who is
  911. 39:49on the other hand of the phone email or
  912. 39:52fax
  913. 39:53so the same is true for vpn networks so
  914. 39:55the device on the other end of the vpn
  915. 39:57channel
  916. 39:58must be authenticated before the
  917. 40:00communication pass is considered secure
  918. 40:03okay now the figure here
  919. 40:07highlights the two peer authentication
  920. 40:09method
  921. 40:10okay so which includes the psk
  922. 40:14and trsa so psk is less secure
  923. 40:18and rsa is of course more secure
  924. 40:22now psk or the pre-shared key is
  925. 40:24combined with other information to form
  926. 40:26authentication key
  927. 40:28so psks are easy to configure manually
  928. 40:31but does not scale well because each
  929. 40:34ipsec
  930. 40:35must be configured with a psk for every
  931. 40:38other peer
  932. 40:39with which it communicates
  933. 40:43okay now for the rsa the local device
  934. 40:47drivers
  935. 40:49okay derives hash and encrypts it with
  936. 40:53its private key so the encryption hash
  937. 40:56is attached to the message
  938. 40:58and is forwarded to the remote end and
  939. 41:00acts like
  940. 41:01signature so at the remote end the
  941. 41:04encrypted hash
  942. 41:05the signature is genuine each peer
  943. 41:09must authenticate its opposite peer
  944. 41:11before the tunnel is considered
  945. 41:13secure okay so
  946. 41:17it uses digital certificates
  947. 41:20to authenticate appears
  948. 41:23all right now let's have the psk
  949. 41:26authentication demo here
  950. 41:28so the figure shows an example of psk
  951. 41:30authentication or depreciated key
  952. 41:33so the local device okay the
  953. 41:35authentication
  954. 41:36key and the integrity information are
  955. 41:39sent
  956. 41:40through a hash algorithm to form a hash
  957. 41:42for the local
  958. 41:43peer we called it hash l
  959. 41:47okay so one way authentication is
  960. 41:50established by sending hash l the remote
  961. 41:53device
  962. 41:55all right and then if the remote device
  963. 41:58can independently create
  964. 42:00the same hash the local device is
  965. 42:03authenticated
  966. 42:05so after the remote device authenticates
  967. 42:07the local device the authentication
  968. 42:09process begins
  969. 42:11in the opposite direction and all steps
  970. 42:14are repeated from the remote device to
  971. 42:17the local
  972. 42:18device all right so
  973. 42:21that's psk authentication
  974. 42:25okay how about the rsa authentication
  975. 42:29okay so at the local device
  976. 42:32the authentication key
  977. 42:35and the information or the identity
  978. 42:37information are sent
  979. 42:38through the has algorithm to form a hash
  980. 42:41for
  981. 42:42a local peer we call it hash l
  982. 42:46okay then the hash l is encrypted using
  983. 42:49the local device private encryption key
  984. 42:51this creates a digital signature
  985. 42:55all right now the digital signature
  986. 42:59and a digital certificate are forwarded
  987. 43:03to the remote device
  988. 43:07okay
  989. 43:11now the public encryption key for
  990. 43:13decrypting the signature is included in
  991. 43:15the digital certificate
  992. 43:17so the remote device verifies the
  993. 43:20digital signature
  994. 43:21by decrypting it using the public
  995. 43:24encryption key okay
  996. 43:26so the result is the hash l
  997. 43:30equals to the decrypted hash l the local
  998. 43:33device is
  999. 43:34authenticated so after the remote device
  1000. 43:38authenticates the local device
  1001. 43:40the authentication process begins in the
  1002. 43:42opposite direction
  1003. 43:44and all steps are repeated from the
  1004. 43:47remote device
  1005. 43:48to the local device okay
  1006. 43:52so you're gonna have a complex
  1007. 43:54authentication here or complex process
  1008. 43:57making it a more secure okay
  1009. 43:59connectivity
  1010. 44:03all right so last one would be the
  1011. 44:06secure key exchange
  1012. 44:08with jeffy helman okay
  1013. 44:11so encryption algorithm requires a
  1014. 44:13symmetric
  1015. 44:15shared secret key to perform encryption
  1016. 44:17encryption
  1017. 44:18so how do encrypting and decrypting
  1018. 44:21devices get the
  1019. 44:22shared secret key that's the question
  1020. 44:25so the easiest key exchange method
  1021. 44:28is to use a public key exchange method
  1022. 44:30such as
  1023. 44:31daffy helman as shown here okay
  1024. 44:36so the fe helmet is used to provide
  1025. 44:38security on the key
  1026. 44:41now the dh group you choose must be
  1027. 44:44strong enough
  1028. 44:45and have enough bits to protect the
  1029. 44:47ipsec keys during negotiation
  1030. 44:50okay so for example dh group one
  1031. 44:53is strong enough to support deaths and
  1032. 44:553ds
  1033. 44:56but not yes so another example
  1034. 45:00if the encryption or authentication
  1035. 45:01algorithms uses
  1036. 45:03bit key the groups of 14 19 20 and 24
  1037. 45:07are used
  1038. 45:08so however if the encryption or
  1039. 45:10authentication algorithms uses 256
  1040. 45:13bit key or higher
  1041. 45:16groups 24 23
  1042. 45:1922 or 21 or use groups 21 or 24
  1043. 45:24all right
  1044. 45:28okay so the last part of this powerpoint
  1045. 45:32presentation
  1046. 45:33is the video on the ipsec transport and
  1047. 45:35tunnel mode
  1048. 45:37okay so same thing with the first video
  1049. 45:39okay
  1050. 45:40so to see this video you can go ahead
  1051. 45:42and log in onto your netacad account
  1052. 45:44okay so that ends up our discussion
  1053. 45:48on vpn and ipsec technologies
  1054. 45:51the configurations will be discussed and
  1055. 45:53presented in the next video
  1056. 45:55thank you
  1057. 46:04you

About this transcript

This page contains the full transcript of ENSA Module 8 VPN and IPSec Concepts by Santelmo, generated from the public captions YouTube serves with the video. The transcript has 5,132 words across 1,057 segments, with the original timestamps preserved so you can click any line to jump to that moment in the embedded player.

What you can do with it

Use the transcript to take notes, quote the speaker, build a study guide, generate a summary with ChatGPT or Claude via the YouTube Summary tool, or export it as a timed subtitle file with YouTube to SRT. You can also re-open it in the transcriber to translate the transcript into 100+ languages.

Free YouTube transcript tool

YouTube2Text is a free YouTube transcript generator — no signup, no daily limit. Paste any YouTube link and get the full transcript instantly, with timestamps, click-to-jump, translation to 100+ languages, AI prompts for ChatGPT, Claude, and Gemini, and exports to TXT, SRT, VTT, or Markdown.