ENSA Module 8 VPN and IPSec Concepts — Transcript
Full transcript
- 0:03[Music]
- 0:13hello there
- 0:14welcome to another video on
- 0:18enterprise networking security and
- 0:20automation version 7 or ansa
- 0:23so on this video we are going to cover
- 0:25module 8
- 0:27which discusses vpn and ipsec concepts
- 0:31all right
- 0:35okay so what we will learn on this
- 0:38module
- 0:40so basically the module covers vpn and
- 0:43ipsec concepts
- 0:44and at the end of the module we should
- 0:47be able to explain how vpns
- 0:48and ipsec are used to secure a site to
- 0:52site and their remote access
- 0:53connectivity
- 0:55so this includes the following topic
- 0:58title and its objectives so for the vpn
- 1:00technology
- 1:02we should be able to describe the
- 1:04benefits of a vpn technology
- 1:07for the types of vpn describe different
- 1:10types of vpns
- 1:12and ipsec explain how the ipsec
- 1:15framework is used
- 1:17to secure a network traffic
- 1:21okay so let's start we are going to
- 1:24discuss
- 1:25first the vpn technology or the virtual
- 1:28private
- 1:29network so basically
- 1:32vpn is
- 1:35to secure a network traffic between
- 1:38sites
- 1:39and users organization uses
- 1:42virtual private networks to create an
- 1:45end-to-end private network connections
- 1:48so a vpn is a virtual in that it carries
- 1:52information
- 1:53within a private network but that
- 1:56information is actually transported
- 1:58over the public network as you see here
- 2:00on the diagram
- 2:02right so a vpn is a private
- 2:07in that the traffic is encrypted to keep
- 2:09the data confidential
- 2:11while it is transported over the public
- 2:13network or
- 2:14the internet so the figure shows a
- 2:17collection of various types of vpns
- 2:20managed by an enterprise main site
- 2:25so the tunnel enables the remote sites
- 2:28which includes the business partners
- 2:31with cisco routers okay a regional
- 2:34office
- 2:34with a cisco asa firewall
- 2:38and a smallhole office home office or
- 2:40soho
- 2:41with a cisco router and a mobile worker
- 2:45using a cisco any connect
- 2:48okay so these sites here are connected
- 2:51to the main site
- 2:53using a channel which enables remote
- 2:55sites and users
- 2:57to access main sites network resource
- 2:59securely
- 3:02all right so what are the benefits of
- 3:06vpns
- 3:07so modern vpns now support encryption
- 3:10features
- 3:11such as the ipsec or the internet
- 3:14protocol security
- 3:17and the ssl or the secure socket layer
- 3:21so the major benefits of vpns includes
- 3:25cost savings security
- 3:29scalability and compatibility
- 3:35so vpns are commonly deployed in one of
- 3:37the following configurations
- 3:39so it is either side to side or remote
- 3:43access
- 3:45so a side to side vpn is created when a
- 3:48vpn terminating devices
- 3:50also called as a vpn gateways
- 3:55are pre-configured with information to
- 3:57establish a secure vpn
- 4:03vpn traffic is only encrypted between
- 4:06these devices
- 4:07so internal hosts has no knowledge
- 4:10that a vpn is being used
- 4:17all right so next is a side-to-side
- 4:21remote access vpns okay
- 4:24so a remote access vpn is dynamically
- 4:28created
- 4:28to establish a secure connection between
- 4:31a client
- 4:32and a vpn terminating device
- 4:35all right so for example a remote access
- 4:38ssl
- 4:39vpn is used when you check your banking
- 4:41information online
- 4:44okay next
- 4:48now there are many options available to
- 4:50secure an enterprise traffic
- 4:52so these solutions vary depending on who
- 4:55is managing the vpn so vpns can be
- 4:59managed and deployed as
- 5:00an enterprise vpns or a service provider
- 5:04vpns
- 5:06so when you say enterprise vpns these
- 5:09are common solutions for securing an
- 5:11enterprise traffic
- 5:12across the internet so a site-to-site
- 5:15and remote access vpns are created
- 5:18and managed by the enterprise using the
- 5:21ipsec
- 5:22and ssl vpns
- 5:26now on the other hand servicer service
- 5:29provider vpns
- 5:30created and managed by the provider
- 5:33network
- 5:34the provider uses the multi-protocol
- 5:37label switching or the mpls
- 5:39at a layer 2 or layer 3
- 5:42to secure or to create a secure channels
- 5:45between an enterprise sites
- 5:47effectively segregating the traffic from
- 5:49the customer's traffic
- 5:52so the figure here okay
- 5:55so listed different types of enterprise
- 5:58managed and service provider managed vpn
- 6:01deployments
- 6:03okay next
- 6:07so let's talk about the types of vpns
- 6:10okay so in the previous topic
- 6:14you learned about the basics of vpn
- 6:18here you will learn about the types of
- 6:20vpn
- 6:22so vpns have become the logical solution
- 6:26for remote access connectivity for many
- 6:28reasons
- 6:30so as shown here on the diagram the
- 6:32remote access the vpn
- 6:34remote and mobile users characterized by
- 6:39a user computer here with a browser and
- 6:41cisco any connect secure mobility client
- 6:45okay so vpn
- 6:48users here are securely connected to the
- 6:52enterprise by creating an encrypted
- 6:54channel in between
- 6:55okay so the remote users can securely
- 6:58replicate their
- 6:59enterprise security access including
- 7:02email
- 7:02and network applications so the remote
- 7:05access vpns
- 7:07also allow contractors and partners to
- 7:10have limited access to the specific
- 7:11servers
- 7:12web pages or files as required
- 7:17okay so this means that these users can
- 7:20contribute to the
- 7:22business productivity without
- 7:23compromising the network security
- 7:27okay so
- 7:30next is a client vpn connection
- 7:34okay and a client-less
- 7:38vpn okay so it's either a client-based
- 7:41or client-less vpn connection so let's
- 7:44start
- 7:44or discuss first the client-less vpn
- 7:47connection
- 7:48so this is the connection where ian is
- 7:52secured using a web browser
- 7:55ssl connection ssl is mostly used to
- 7:59protect http traffic
- 8:02okay or https
- 8:05and email protocols such as imap
- 8:08or pub3 so for example
- 8:13https is actually an http using an ssl
- 8:16panel
- 8:18so the ssl connection is first
- 8:20established
- 8:22and then data or http data
- 8:25is exchanged over the connection okay
- 8:28so that is using a browser
- 8:33now for the client based vpn connection
- 8:37okay vpn client software such as the
- 8:40cisco any connect here
- 8:43secure mobility client must be installed
- 8:45on the remote users
- 8:46and device okay it could be on a laptop
- 8:49or
- 8:50a pump top or a cell phone now
- 8:53client-based vpn users
- 8:56must initiate the vpn connection using
- 8:59the vpn client and then authenticate the
- 9:01destinations of vpn gateway
- 9:04okay so when the remote users are
- 9:06authenticated
- 9:08they have access to the corporate files
- 9:11and applications
- 9:12so the vpn client software encrypts
- 9:15traffic
- 9:16using the ipsec or ssl and forwards
- 9:20it over the internet to the destinations
- 9:22vpn gateway
- 9:24so that's how it works okay
- 9:27so the browser based here uses a client
- 9:30less
- 9:32okay vpn true ssl connection
- 9:36and the roaming users here
- 9:39uses a software called cisco and connect
- 9:42to connect to the enterprise
- 9:46all right next ssl vpns
- 9:51so when a client negotiates an ssl vpn
- 9:54connection
- 9:55with the vpn gateway it actually
- 9:58connects using
- 9:59tls or the transport layer security
- 10:03so tls is a newer version of ssl
- 10:06and is sometimes expressed as ssl over
- 10:09tls
- 10:10however both terms are often used
- 10:14interchangeably
- 10:16okay now ssl uses the public
- 10:19infrastructure and digital certificates
- 10:21to authenticate peers
- 10:23so the type of vpn method implemented is
- 10:26based
- 10:27on the access requirements of the users
- 10:30and organizations i.t processes
- 10:33so the table here compares ipsec
- 10:37and ssl remote access deployments okay
- 10:41so considering the application supported
- 10:44the authentication strength all right so
- 10:46encryption strength
- 10:48connection complexity and connection
- 10:50option
- 10:53okay so when we're talking about the
- 10:56application support
- 10:58so ipsec extensive all ip based
- 11:01application
- 11:02compared to that of ssl having unlimited
- 11:05only web-based applications and file
- 11:07sharing
- 11:08okay so when it comes to authentication
- 11:11strength
- 11:12okay so ipsec is strong so it uses a
- 11:15towing authentication
- 11:17with a shared keys or digital
- 11:19certificates
- 11:21okay so whereas ssl
- 11:24is moderate one-way or two-way
- 11:27authentication
- 11:29okay so for the encryption strength
- 11:32so ipsec is strong the key length is 56
- 11:36to 256 bits
- 11:40whereas for ssl it's moderate to strong
- 11:44so key length is at 40 to 256 bits
- 11:49connection complexity well i present
- 11:52medium
- 11:52requires vpn client installed on the
- 11:54host
- 11:56whereas ssl it just requires a web
- 11:59browser on the host
- 12:00so any web browsers will do okay
- 12:04and then last is the connection option
- 12:07so
- 12:07hypersec is limited only specific
- 12:11devices with specific configurations can
- 12:13connect
- 12:14whereas ssl extensive any device
- 12:18with a web browser can connect
- 12:21all right next
- 12:26so types of vpns side to side hypersex
- 12:29vpns
- 12:30okay so side to side
- 12:34vpns connect networks across an
- 12:36untrusted network
- 12:37such as the internet so we are talking
- 12:39about the public
- 12:40network here okay so
- 12:44and hosts sends and receives
- 12:47normally unencrypted cpip traffic
- 12:50through a vpn gateway
- 12:52so the vpn terminating is
- 12:55typically called a vpn gateway a vpn
- 12:59gateway device could be a router or a
- 13:01firewall
- 13:02as shown in the figure here okay so
- 13:04which uses a router here
- 13:06and a firewall on the other end so for
- 13:09example
- 13:10the cisco adaptive security appliance or
- 13:13the asa
- 13:15shown on the right side of this figure
- 13:17okay it's a standalone firewall device
- 13:20that combines firewall vpn concentrator
- 13:23and intrusion prevention functionality
- 13:25into a software
- 13:26image okay
- 13:30next is the vpn gateway encapsulates
- 13:34and encrypts outbound traffic from a
- 13:37site and sends the traffic through a vpn
- 13:39tunnel
- 13:40to the vpn gateway at the target site
- 13:44so the receiving vpn gateway strips the
- 13:46headers
- 13:48decrypts the content and relates the
- 13:50packet towards the target
- 13:52host inside the fry bit network
- 13:55so side to side vpns are typically
- 13:57created and secured
- 13:59using an ip security or ipsec
- 14:03okay next
- 14:07so agree over ipsec so when you say gri
- 14:11it's a generic routing encapsulation
- 14:13this is an unsecured
- 14:15side-to-side vpn tunneling protocol so
- 14:18i'll show you
- 14:20how to configure gri on the next video
- 14:24so a grid panel can encapsulate various
- 14:27network layers
- 14:29as well as the multicast and broadcast
- 14:30traffic
- 14:32okay so grid does not by default support
- 14:36encryption
- 14:37and therefore it does not provide a
- 14:39secure vpn tunnel
- 14:40so it just provides connectivity between
- 14:42the two end nodes
- 14:44all right so a grid packet can be
- 14:47encapsulated into an ipsec
- 14:49packet to forward it securely to the
- 14:52destination vpn gateway
- 14:56so therefore routing protocols will not
- 14:58exchange routing information over an
- 15:00ipsec
- 15:01vpn okay so the standard ipsec vpn
- 15:06non-gri okay can create a secure tunnel
- 15:09for unicast traffic
- 15:13okay so to solve this problem
- 15:16we can encapsulate routing protocol
- 15:19using a green
- 15:20packet and that encapsulates the grid
- 15:22packet into an ipesec packet
- 15:24to forward it securely to the
- 15:26destination vpn gateway
- 15:28so encapsulating green into an ipsec
- 15:30allows multicast routing protocol
- 15:32updates
- 15:34to be secured through a vpn
- 15:38okay so we can combine the green
- 15:41and ipsec to provide a secure vpn
- 15:44connectivity
- 15:47all right next so
- 15:50the terms used to describe the
- 15:52encapsulation for gree over ipsec tunnel
- 15:55are passenger protocol carrier protocol
- 15:58and
- 15:58transport protocol so we are talking
- 16:01about three protocols here
- 16:03combined okay so the passenger protocol
- 16:06this is an original packet that is to be
- 16:08encapsulated by gri
- 16:10so it could be an ipv for our ipv6
- 16:12packet
- 16:13a routing update and more
- 16:16now for the carrier protocol gree is
- 16:19a carrier protocol that encapsulates the
- 16:21original passenger packet
- 16:24and transport protocol this is the
- 16:27protocol that would actually be used to
- 16:30forward the packet
- 16:31so this could be either ipb4
- 16:35for ipv6 okay
- 16:38so i p here is for the transport
- 16:41protocol
- 16:42green is the carrier protocol
- 16:45okay and this one here the ip the tcp
- 16:48and the data these are the passenger
- 16:50protocols
- 16:52okay next
- 16:56so for example you're gonna have here
- 16:59the branch
- 17:00okay and the headquarter so the brands
- 17:04and the headquarters need to exchange
- 17:05ospf routing information
- 17:07over the ipsec vpn here
- 17:10okay so agree over ipsec is used to
- 17:13support the routing protocol traffic
- 17:15over the ipsec vpn so specifically the
- 17:18ospf packets
- 17:19example uh passenger protocol
- 17:23would be encapsulated by gri or a
- 17:25carrier protocol and subsequently
- 17:27encapsulated
- 17:28in an ipsec vpn tunnel okay
- 17:32so with that with the combinations of
- 17:34gree and ipsec
- 17:35for sure we'll gonna have a secure vpn
- 17:38connection
- 17:39between a branch and a headquarter
- 17:44okay
- 17:47all right so the next one is a dynamic
- 17:51multi-point vpns
- 17:53okay so side to side ipsec vps and grid
- 17:56over ibsec
- 17:57are not sufficient when the enterprise
- 18:00adds many more sites
- 18:02okay so the dynamic multi-point vpn
- 18:05is a cisco software solution for
- 18:08building multiple vpns
- 18:09in an easy dynamic and scalable manner
- 18:13okay so dynamic multi-point vpn or dm
- 18:17vpn
- 18:18is a cisco software solution for
- 18:20building
- 18:21multiple vpns in an easy dynamic
- 18:24scalable
- 18:26manner so like other vpn types dmvpn
- 18:30relies on ipsec to provide secure
- 18:34transport
- 18:34over public networks such as the
- 18:37internet
- 18:38okay so
- 18:42it uses a hab and spoke configuration to
- 18:45establish a full mesh topology
- 18:47so when they haven't spoke okay so we
- 18:49have different branches
- 18:51okay so serves as the spoke and maybe
- 18:54the main site
- 18:55serves as the hub okay
- 18:59so a spoke sites establish a secure vpn
- 19:01channels with a hub
- 19:02site okay and then its
- 19:06site is configured using a multi-point
- 19:09generic routing encapsulation or mg
- 19:13the m grid tunnel interface allows a
- 19:15single degree interface
- 19:17to dynamically support the multiple
- 19:19ipsec tunnels
- 19:21so therefore when the new site requires
- 19:24a secure connection
- 19:26the same configuration on the hub site
- 19:28would support the tunnel
- 19:30so no additional configuration would be
- 19:33required
- 19:35okay so spoke sites can also obtain
- 19:38information about each other
- 19:40and alternatively build direct tunnels
- 19:43between themselves
- 19:44so we call it hope or spoke bespoke
- 19:46tunnels
- 19:50okay
- 19:52right so the next one is the ipsec
- 19:55virtual tunnel interface
- 19:57or the vti so the vti simplifies the
- 20:00configuration process
- 20:02required to support multiple sites and
- 20:04the remote access
- 20:07so like dmvpns ipsec
- 20:11virtual channel interface or vti
- 20:14simplifies the configuration process
- 20:16required to support multiple sites and
- 20:18remote access
- 20:19so ipsec vti configurations are applied
- 20:22to
- 20:22the virtual interface instead of static
- 20:24mapping the ips accessions the
- 20:27physical interface
- 20:32okay so the ipsec vti is capable of
- 20:35sending and receiving both
- 20:37ip unicast and multicast encrypted
- 20:39traffic
- 20:40so therefore routing protocols are
- 20:43automatically supported
- 20:44without having to configure degree
- 20:46channels that's a good thing about the
- 20:47ipsec vti
- 20:49okay so the ipsec vti can be configured
- 20:52between sites
- 20:53or in a hub and spoke topology
- 21:00okay
- 21:02okay so the next type of vpn is a
- 21:05service provider
- 21:06mpls vpns so traditional service
- 21:10provider wants solutions
- 21:12such as list lines frame relay
- 21:15and atm connections are inherently
- 21:20secure in their designs okay so we've
- 21:23talked about this technology
- 21:25on the previous video
- 21:28so today service provider uses the mpls
- 21:31in their core network
- 21:33so traffic is forwarded through the mpls
- 21:35backbone
- 21:36using labels so traffic is secure
- 21:39because service provider customers
- 21:41cannot see each other's traffic
- 21:44so mpls can provide clients with managed
- 21:47vpn solutions so therefore
- 21:49securing traffic between client sites is
- 21:52the responsibility of
- 21:54the service provider so there are two
- 21:57types of mpls vpn solutions supported by
- 22:00service providers so these are the layer
- 22:023
- 22:03mpls vpn and the layer 2
- 22:06mpls vpn so as the name implies
- 22:10they differ and operates on different
- 22:13layers
- 22:14okay so layer three and layer two
- 22:20all right now let's talk about ipsec now
- 22:26okay now on this powerpoint
- 22:29okay the official powerpoint of cisco so
- 22:32this includes
- 22:33a video okay so to see this video
- 22:37you can go ahead and log into your
- 22:39nethacker account and see this video
- 22:41all right so for this video lecture
- 22:44so i'm going to skip this one okay
- 22:50so let's talk about the ipsec
- 22:52technologies
- 22:53so ipsec is an ietf standard
- 22:57that defines how a vpn can be secured
- 23:00across
- 23:00ip networks so ipsec protects
- 23:04and authenticates ip packets between
- 23:06source and destination
- 23:08and provides these essential security
- 23:09functions
- 23:11ipsec can only protect traffic from
- 23:14layer 4 through layer 7.
- 23:18i'll repeat ipsec can only protect
- 23:20traffic from layer
- 23:22four through layer seven
- 23:25okay so this ipsec technologies
- 23:28provides the following security
- 23:30functions so you've got confidentiality
- 23:32integrity origin authentication
- 23:36and the daffy helmet okay so when we've
- 23:39talked about confidentiality
- 23:41it uses encryption algorithms to prevent
- 23:44cyber criminals from reading the packet
- 23:46contents
- 23:47so that's confidentiality okay
- 23:50integrity it uses a hash algorithm or
- 23:53hashing algorithm
- 23:55to ensure that the packets have not been
- 23:57altered between the source
- 23:59and destination or while in transit
- 24:03origin authentication uses the ike
- 24:07protocol
- 24:08to authenticate source and destination
- 24:11and the daffy helmet
- 24:12is used to secure the key exchange
- 24:16okay so ipsec technologies basically
- 24:19uses a lot of protocols
- 24:23and security measures to ensure that the
- 24:25connection between
- 24:26sites are safe and secure
- 24:30all right so we will be covering all
- 24:32those protocols
- 24:34which ensures ipsec technologies
- 24:37a secure connection
- 24:40okay now
- 24:46so ipsec is not bound to any specific
- 24:48rules
- 24:49for secure communications so ipsec can
- 24:52easily integrate
- 24:53new security technologies without
- 24:56updating the
- 24:57ipsec standards okay
- 25:00so ipsec standards or iberisik
- 25:03technologies
- 25:04covers the ipsec protocols for the
- 25:06financiality
- 25:08integrity authentication and the deputy
- 25:11helmet
- 25:12okay so the currently available
- 25:14technologies
- 25:16are aligned to their specific security
- 25:18function
- 25:19so the open slot shown in the ipsec
- 25:22framework
- 25:23on this figure okay
- 25:28so we have to have a combinations
- 25:31of this choices here okay so to come up
- 25:35with our own combo
- 25:37okay so the open slot shown in the
- 25:40ibiseg framework in the figure can be
- 25:43filled with
- 25:44any of the choice that are available for
- 25:47that i project function
- 25:48to create a unique security association
- 25:51or
- 25:52sa okay now let's talk about the ipsec
- 25:56protocol first
- 25:57so the choices for ipsec protocol
- 26:00includes authentication header
- 26:02okay or ah or
- 26:05encapsulation security protocol esp
- 26:10a h authenticates the layer 3 packet
- 26:13esp encrypts the layer 3 packet
- 26:17all right so therefore we could have a
- 26:20combination of the both
- 26:22of are combinations of these two
- 26:26okay now when we combined ah and dsp
- 26:31okay so that is rarely used
- 26:35as this combination will not
- 26:36successfully traverse
- 26:38in a network address translations device
- 26:40or not device
- 26:46next is confidentiality okay so
- 26:50what do we have in confidentiality so
- 26:52encryption ensures confidentiality
- 26:54of the layer 3 packet so choices
- 26:57includes
- 26:58desk okay or the data encryption
- 27:00standards
- 27:02triple desk or 3ds
- 27:06you also have the aes or the advanced
- 27:08encryption standard
- 27:10or the software optimized encryption
- 27:13algorithm seal so
- 27:16no encryption is also an option
- 27:21okay so you could have combinations with
- 27:24hypersex
- 27:25and then without encryption
- 27:28okay all right so the next one
- 27:32is integrity so integrity ensures that
- 27:35the data arrives
- 27:36unchanged at the destination using a
- 27:39hash algorithm
- 27:41so this includes the md5
- 27:45okay or the message digest 5 and
- 27:48sha which means secure house algorithm
- 27:51[Music]
- 27:52okay the next one is authentication
- 27:57so ipsec uses an ike
- 28:01okay or the interna internet key
- 28:03exchange
- 28:04to authenticate the users and devices
- 28:07that can carry out communication
- 28:08independently
- 28:10so ikey uses several types of
- 28:13authentication
- 28:15the plain username and password okay so
- 28:18one time password biometrics
- 28:22and pressured case or ps case which are
- 28:25which is common
- 28:26and also it could be a digital
- 28:28certificate using
- 28:30the rsa algorithm or the real diverse
- 28:33chamier adelman rsa algorithm
- 28:37okay so for the authentication the
- 28:40choice is ours
- 28:42which either we use psk okay or the
- 28:45pre-shared keys
- 28:47and the rsa
- 28:50all right so the last one is a defe
- 28:54helman
- 28:55so ipsec uses the dh algorithm to
- 28:58provide a public key exchange
- 28:59method for two peers to establish a
- 29:02shared secret key
- 29:04so there are several different groups to
- 29:07choose from
- 29:07including the age 14 15 16
- 29:11or days 19 20 21 and 24
- 29:15so dh1 2 and 5 are no longer
- 29:19recommended okay now this ipsec
- 29:22technologies
- 29:23would allow the administrator to come up
- 29:27with a great combinations
- 29:30okay to have a secure
- 29:33point-to-point or side-to-side
- 29:35connectivity
- 29:38all right okay
- 29:41so let's have an example of security
- 29:45association here
- 29:47or sa okay so select take a look at the
- 29:50sa example number one so ipsec protocol
- 29:53uses
- 29:54ah okay so no confidentiality because
- 29:59encryption
- 30:00is it's an option or you could have
- 30:04without encryption adopted all right
- 30:07so integrity uses an md5 authentication
- 30:10is psk
- 30:11daffy helmand sdh16
- 30:14so daffy helmet is just used to secure
- 30:17the keys
- 30:18so it doesn't um
- 30:21encrypt or provide encryptions for the
- 30:23data okay
- 30:26now on the security association two here
- 30:29okay so it uses or it prefer esp
- 30:32confidentiality uses aes integrity is
- 30:36sha authentication is rsa and d3 helmand
- 30:39uses dh24
- 30:42okay so an sa is the basic building
- 30:46block
- 30:46of ipsec so on the next video i'll show
- 30:50you how to configure an ipsec
- 30:52okay so it's just that on this
- 30:54presentation or video
- 30:56we are going to cover only the concepts
- 30:58of
- 30:59vpn and ipsec now when establishing a
- 31:03vpn link
- 31:04the peers must share the same essay
- 31:07so to negotiate key exchange parameters
- 31:11so establish a shared key authenticate
- 31:13each other and negotiate encryption
- 31:15parameters
- 31:16so if you have used an sa with this
- 31:19combination on router one
- 31:21okay just make sure on the other end you
- 31:24have the same combinations or same combo
- 31:27okay so notice that sa example one is
- 31:31using
- 31:32without encryption here that's possible
- 31:36it is allowed okay
- 31:40next the ipsec protocol encapsulation
- 31:45so choosing the ipsec protocol
- 31:47encapsulation is the first building
- 31:48block of the framework
- 31:50so you have to choose first on ipsec
- 31:53okay confidentiality integrity
- 31:56authentication and the daffy helmet okay
- 32:00so the ipsec encapsulates packets using
- 32:03the ah
- 32:04or the espr encapsulation security
- 32:07protocol
- 32:09so the ah it provides data
- 32:11authentication and integrity
- 32:13but it does not provide data
- 32:15confidentiality or encryption
- 32:18all right so all text is transported and
- 32:20encrypted
- 32:23okay next
- 32:26esp it provides confidentiality by
- 32:30performing encryption on the ip packet
- 32:33esp provides authentication
- 32:36for the inner ip packet and esp header
- 32:39so authentication provides data origin
- 32:42authentication
- 32:43and data integrity so although both
- 32:46encryption and authentication are
- 32:48optional in esp
- 32:49at a minimum one of the most or
- 32:52one of them must be selected
- 32:56okay so again
- 33:00the choice of ah or esp establishes
- 33:03which other building blocks are
- 33:04available so ah
- 33:06is appropriate only when confidentiality
- 33:10is not required or permitted
- 33:12okay and esp provides both
- 33:15confidentiality
- 33:17and authentication
- 33:20okay so again be careful on
- 33:23building your own combo okay for these
- 33:26security associations as your sa
- 33:29is the building block of the ipersec
- 33:34okay next let's talk about
- 33:37confidentiality
- 33:39okay so confidentiality is achieved
- 33:42by encrypting the data as shown here on
- 33:45the diagram
- 33:47okay so the degree of confidentiality
- 33:49depends
- 33:50on the encryption algorithm and the
- 33:53length of the key used
- 33:54in encryption algorithm right
- 33:57so if someone tries to hack the key
- 34:01through a brute force attack the number
- 34:04of possibilities to try
- 34:06is a function of the length of that key
- 34:09so the time to process the all
- 34:12possibilities
- 34:13is a function of the computer power
- 34:17of the attacking device so the shorter
- 34:19the key
- 34:21the easier it is to break okay so a
- 34:2464-bit key
- 34:27can take approximately one year to break
- 34:29with a relatively sophisticated computer
- 34:32okay can you imagine that so 64 bit
- 34:36one year of course you're gonna have the
- 34:39most sophisticated computer to do that
- 34:42okay so what if you have 128 bit
- 34:47okay so with 128 b
- 34:50or bit okay the same machine can
- 34:53take roughly 10 raised to the 19 or that
- 34:56would be
- 34:5810 quintillion years to decrypt
- 35:01okay so well the higher the number of
- 35:04bits
- 35:06okay so the secure your data is
- 35:10all right
- 35:15next concentration so the encryption
- 35:18algorithm highlighted in the figure
- 35:20are all symmetric key cryptosystems
- 35:24okay so this uses 56-bit key
- 35:283ds uses three independent 56 bit
- 35:31that's why it's called 3ds okay
- 35:34and then the aes offers three different
- 35:37key lengths so 128
- 35:39192 and 256 bits
- 35:43seal is a stream cipher which
- 35:46means it encrypts data continuously
- 35:49rather than encrypting blocks of data
- 35:51so seal uses 160 bitkey
- 35:54so the higher the number okay or the
- 35:57higher number of bit
- 35:58so the more secure your data is so the
- 36:01encryption algorithms
- 36:02in here would merely depend
- 36:05depend on the administrator
- 36:10okay
- 36:12okay so let's have an integrity test
- 36:15here
- 36:16okay when we're talking about data
- 36:17integrity that means that the data that
- 36:19is received is exactly the same data
- 36:21that was sent
- 36:24okay so potentially data could be
- 36:27intercepted
- 36:28and modified so for example on this
- 36:31diagram
- 36:32okay so we have here paid to alex 100
- 36:36okay and then
- 36:40the ending hash pay to jeremy one
- 36:42thousand dollars
- 36:44okay so in here
- 36:49so assuming that the check is
- 36:52100 that's written to pay alex right
- 36:56the check is then mailed to alex but it
- 36:59is intercepted by
- 37:01a threat actor maybe okay
- 37:05the threat actor changes the name on the
- 37:07check
- 37:08and make it jeremy so when it was sent
- 37:12it was alex but somewhere along the way
- 37:14all right
- 37:15it was changed to jeremy and that 100
- 37:18there
- 37:19become 1000.
- 37:22okay so the threat actor changes the
- 37:24name of the check
- 37:26to jeremy and the amount of the check to
- 37:291 000
- 37:29and attempts to cash it all right so
- 37:33depending on the quality
- 37:34of the forgery in the altered check
- 37:37the attacker could be successful okay
- 37:41so again when we've talked about
- 37:43integrity
- 37:44the data that was sent should be the
- 37:47same data
- 37:48that is to be received okay
- 37:52or the data that is received is exactly
- 37:55the same data that was sent
- 37:58okay there should be no modifications
- 38:01while in transit
- 38:05all right so because
- 38:08vpn data is transported over the public
- 38:11internet so a method of proving
- 38:13data integrity is required to guarantee
- 38:16that the content has not been altered
- 38:18while in transit
- 38:20okay so the hash message authentication
- 38:24code or hmac
- 38:26is a data integrity algorithm that
- 38:28guarantees
- 38:30the integrity of the message using the
- 38:32hash value
- 38:34okay so it could be an md5
- 38:37okay which uses 128 bit shared secret
- 38:41key
- 38:41or the sha
- 38:45or the sha which uses 160 bit secret key
- 38:49okay so md5 or the variable length
- 38:52message
- 38:53and 128 bit shared key are combined and
- 38:56run
- 38:57through the hmac md5 has algorithm so
- 39:00the output is
- 39:01128 bit hash okay
- 39:05so we're talking about this now for sure
- 39:09the variable length message and the 160
- 39:11bit shared keys
- 39:13are combined and run through the hmac
- 39:16shell one algorithm and the output is
- 39:19160 bit
- 39:20hash all right so
- 39:24that's a lot of number of bits
- 39:28okay now let's talk about authentication
- 39:31so there are two hypersecure
- 39:32authentications
- 39:33used okay so you've got the pre-shared
- 39:36key or the psk
- 39:39and the rsa so
- 39:44when conducting business long distance
- 39:46you must know who is
- 39:49on the other hand of the phone email or
- 39:52fax
- 39:53so the same is true for vpn networks so
- 39:55the device on the other end of the vpn
- 39:57channel
- 39:58must be authenticated before the
- 40:00communication pass is considered secure
- 40:03okay now the figure here
- 40:07highlights the two peer authentication
- 40:09method
- 40:10okay so which includes the psk
- 40:14and trsa so psk is less secure
- 40:18and rsa is of course more secure
- 40:22now psk or the pre-shared key is
- 40:24combined with other information to form
- 40:26authentication key
- 40:28so psks are easy to configure manually
- 40:31but does not scale well because each
- 40:34ipsec
- 40:35must be configured with a psk for every
- 40:38other peer
- 40:39with which it communicates
- 40:43okay now for the rsa the local device
- 40:47drivers
- 40:49okay derives hash and encrypts it with
- 40:53its private key so the encryption hash
- 40:56is attached to the message
- 40:58and is forwarded to the remote end and
- 41:00acts like
- 41:01signature so at the remote end the
- 41:04encrypted hash
- 41:05the signature is genuine each peer
- 41:09must authenticate its opposite peer
- 41:11before the tunnel is considered
- 41:13secure okay so
- 41:17it uses digital certificates
- 41:20to authenticate appears
- 41:23all right now let's have the psk
- 41:26authentication demo here
- 41:28so the figure shows an example of psk
- 41:30authentication or depreciated key
- 41:33so the local device okay the
- 41:35authentication
- 41:36key and the integrity information are
- 41:39sent
- 41:40through a hash algorithm to form a hash
- 41:42for the local
- 41:43peer we called it hash l
- 41:47okay so one way authentication is
- 41:50established by sending hash l the remote
- 41:53device
- 41:55all right and then if the remote device
- 41:58can independently create
- 42:00the same hash the local device is
- 42:03authenticated
- 42:05so after the remote device authenticates
- 42:07the local device the authentication
- 42:09process begins
- 42:11in the opposite direction and all steps
- 42:14are repeated from the remote device to
- 42:17the local
- 42:18device all right so
- 42:21that's psk authentication
- 42:25okay how about the rsa authentication
- 42:29okay so at the local device
- 42:32the authentication key
- 42:35and the information or the identity
- 42:37information are sent
- 42:38through the has algorithm to form a hash
- 42:41for
- 42:42a local peer we call it hash l
- 42:46okay then the hash l is encrypted using
- 42:49the local device private encryption key
- 42:51this creates a digital signature
- 42:55all right now the digital signature
- 42:59and a digital certificate are forwarded
- 43:03to the remote device
- 43:07okay
- 43:11now the public encryption key for
- 43:13decrypting the signature is included in
- 43:15the digital certificate
- 43:17so the remote device verifies the
- 43:20digital signature
- 43:21by decrypting it using the public
- 43:24encryption key okay
- 43:26so the result is the hash l
- 43:30equals to the decrypted hash l the local
- 43:33device is
- 43:34authenticated so after the remote device
- 43:38authenticates the local device
- 43:40the authentication process begins in the
- 43:42opposite direction
- 43:44and all steps are repeated from the
- 43:47remote device
- 43:48to the local device okay
- 43:52so you're gonna have a complex
- 43:54authentication here or complex process
- 43:57making it a more secure okay
- 43:59connectivity
- 44:03all right so last one would be the
- 44:06secure key exchange
- 44:08with jeffy helman okay
- 44:11so encryption algorithm requires a
- 44:13symmetric
- 44:15shared secret key to perform encryption
- 44:17encryption
- 44:18so how do encrypting and decrypting
- 44:21devices get the
- 44:22shared secret key that's the question
- 44:25so the easiest key exchange method
- 44:28is to use a public key exchange method
- 44:30such as
- 44:31daffy helman as shown here okay
- 44:36so the fe helmet is used to provide
- 44:38security on the key
- 44:41now the dh group you choose must be
- 44:44strong enough
- 44:45and have enough bits to protect the
- 44:47ipsec keys during negotiation
- 44:50okay so for example dh group one
- 44:53is strong enough to support deaths and
- 44:553ds
- 44:56but not yes so another example
- 45:00if the encryption or authentication
- 45:01algorithms uses
- 45:03bit key the groups of 14 19 20 and 24
- 45:07are used
- 45:08so however if the encryption or
- 45:10authentication algorithms uses 256
- 45:13bit key or higher
- 45:16groups 24 23
- 45:1922 or 21 or use groups 21 or 24
- 45:24all right
- 45:28okay so the last part of this powerpoint
- 45:32presentation
- 45:33is the video on the ipsec transport and
- 45:35tunnel mode
- 45:37okay so same thing with the first video
- 45:39okay
- 45:40so to see this video you can go ahead
- 45:42and log in onto your netacad account
- 45:44okay so that ends up our discussion
- 45:48on vpn and ipsec technologies
- 45:51the configurations will be discussed and
- 45:53presented in the next video
- 45:55thank you
- 46:04you
About this transcript
This page contains the full transcript of ENSA Module 8 VPN and IPSec Concepts by Santelmo, generated from the public captions YouTube serves with the video. The transcript has 5,132 words across 1,057 segments, with the original timestamps preserved so you can click any line to jump to that moment in the embedded player.
What you can do with it
Use the transcript to take notes, quote the speaker, build a study guide, generate a summary with ChatGPT or Claude via the YouTube Summary tool, or export it as a timed subtitle file with YouTube to SRT. You can also re-open it in the transcriber to translate the transcript into 100+ languages.
Free YouTube transcript tool
YouTube2Text is a free YouTube transcript generator — no signup, no daily limit. Paste any YouTube link and get the full transcript instantly, with timestamps, click-to-jump, translation to 100+ languages, AI prompts for ChatGPT, Claude, and Gemini, and exports to TXT, SRT, VTT, or Markdown.