Other Useful Protocols - CompTIA Network+ N10-009 - 1.4 — Transcript
Full transcript
- 0:02there will be many times as a network
- 0:03professional when you'd like to know if
- 0:05a device is on the network and operating
- 0:08and one protocol that can provide you
- 0:10with that is icmp this is the internet
- 0:13control message protocol you can think
- 0:16of this as a way to check in with that
- 0:18device very similar to sending a text
- 0:20message to see if you get a response
- 0:22back from someone icmp is another
- 0:25protocol carried by IP but it doesn't
- 0:27use TCP or UDP instead icmp is its own
- 0:32protocol although icmp can be used for a
- 0:35number of administrative tasks it's most
- 0:37commonly associated with a way to send a
- 0:40message to a device to see if it's alive
- 0:42and operating on the network and see if
- 0:44you can get a response back from that
- 0:46device whenever you use the Ping command
- 0:49to Ping an IP address on the network
- 0:52it's using icmp to provide that ping
- 0:55functionality but icmp can also provide
- 0:58you with information about other things
- 1:00that may be happening on the network for
- 1:02example if you're trying to access a
- 1:03network that is not accessible from your
- 1:05location icmp will give you a message
- 1:08that that network is not reachable or
- 1:10icmp can tell you that the time to live
- 1:13that's inside of data that you've sent
- 1:15has expired and it's received an icmp
- 1:18time exceeded message from that device
- 1:22another common protocol on our network
- 1:24is gr or the generic routing
- 1:27encapsulation protocol if you're
- 1:29creating a tunnel Tel between two
- 1:30endpoints this is commonly done with
- 1:33vpns for example you're creating this
- 1:35tunnel using gr this allows us to
- 1:39encapsulate information within an IP
- 1:41packet send it across this gr tunnel and
- 1:44decapsulate it on the other side this
- 1:47does not however provide encryption of
- 1:50this data we'll need to provide
- 1:51additional VPN protocols to encrypt the
- 1:54data that we are encapsulating in a gr
- 1:57tunnel these vpm protocols are referred
- 2:00to as virtual private Network protocols
- 2:03and it's very common to use these vpm
- 2:05protocols to encrypt or protect any data
- 2:08being sent across one of those tunnels
- 2:11it's often common to use a purpose-built
- 2:13appliance to provide this encryption and
- 2:16decryption process at the central point
- 2:19we refer to this as a VPN concentrator
- 2:22sometimes this is a standalone unit but
- 2:24it's very often integrated into an
- 2:26existing firewall that's connected to
- 2:28the network these concentr ERS are often
- 2:30Hardware devices with specialized
- 2:32encryption Hardware built into the
- 2:34device to add efficiency and throughput
- 2:37but if you have a limited number of
- 2:38users it's also possible to use your VPN
- 2:41concentrator as software in an operating
- 2:44system this is a common sight tosite VPN
- 2:47configuration where a corporate Network
- 2:49may be connected to a remote site over a
- 2:52public network such as the internet
- 2:54we'll have VPN concentrators which are
- 2:56usually firewalls or routers those are
- 2:59connecting these two sites together over
- 3:02the internet but all of this traffic
- 3:04that's being sent across that public
- 3:06internet is being encrypted using this
- 3:08VPN technology one of the popular
- 3:11protocols used to provide that level of
- 3:14encryption over those tunnels is IPC
- 3:17this stands for Internet Protocol
- 3:19security and it's one of the most
- 3:20popular ways to encrypt data being sent
- 3:23across these vpns not only does IPC
- 3:27provide encryption for confidentiality
- 3:29it can also provide digital signatures
- 3:31of every packet which includes integrity
- 3:33and anti-replay functionality this is
- 3:36also a very common protocol and it can
- 3:38be used across many different
- 3:39manufacturer devices for example you
- 3:42might have a firewall from one
- 3:43manufacturer on one side of a VPN tunnel
- 3:46and a firewall from a completely
- 3:48different manufacturer on the other side
- 3:50of the VPN tunnel because IPC is such a
- 3:53standard protocol those two firewalls
- 3:55can easily connect to each other and
- 3:57transfer information over that I IPC
- 4:00tunnel when you're using IPC there are
- 4:02commonly two primary protocols that are
- 4:04in use one is the authentication header
- 4:07or ah and the other is the encapsulation
- 4:10security payload or
- 4:12ESP in order for IPC to be able to send
- 4:16this encrypted data across the network
- 4:18we first need to create this tunnel and
- 4:20we do this by performing a series of
- 4:22steps prior to sending any data those
- 4:25steps are referred to as the internet
- 4:27key exchange or Ike internet key
- 4:30exchange allows both sides of the
- 4:32conversation to agree on the encryption
- 4:34and decryption keys that will be used
- 4:36for the duration of that VPN tunnel we
- 4:39refer to this agreement as a security
- 4:42Association or an sa there are two
- 4:45phases to this key exchange process the
- 4:48first phase commonly uses Diffy Helman
- 4:50to create a shared secret key for both
- 4:53sides of the conversation this usually
- 4:55operates using UDP Port 500 and we refer
- 4:59to this as as ISAC camp this is the
- 5:01Internet Security Association and Key
- 5:04Management protocol in phase two we
- 5:06coordinate which Cipher should be used
- 5:08for the encryption and the key sizes
- 5:10that would be appropriate and it
- 5:12negotiates both the inbound and outbound
- 5:14security Association to be used for this
- 5:17IPC tunnel so visually with phase one
- 5:21we're building the ISA Camp tunnel over
- 5:23UDP Port 500 in phase two we're
- 5:26including the encrypted data over the
- 5:29encaps ation security payload or ESP
- 5:32tunnel this gives us the foundation we
- 5:34need to be able to send this encrypted
- 5:36data over the IPC tunnel if you're
- 5:39building your own IP tunnel you may be
- 5:42asked whether you'd like to use
- 5:43transport mode or tunnel mode both of
- 5:46these work differently and will protect
- 5:49data in different ways let's take the
- 5:51original packet which includes an IP
- 5:53header and some data within that IP
- 5:55packet we would like to send that over
- 5:57an IPC tunnel if we use trans transport
- 6:00mode to send this IPC data we're going
- 6:02to insert an IPC header between the IP
- 6:06header and the data all of that is going
- 6:08to be in the clear anything within the
- 6:10data portion of that IP packet will be
- 6:12encrypted and then the ipct trailer put
- 6:15at the end of the packet notice that the
- 6:18original Ip header is not encrypted when
- 6:20using transport mode and if someone does
- 6:23capture this data they'll be able to see
- 6:25the original Ip header and be able to
- 6:28understand where this traffic is
- 6:29intended to go even if they can't see
- 6:32the encrypted data within the packet a
- 6:34much more secure method of using an IP
- 6:37SEC tunnel is tunnel mode in tunnel mode
- 6:40the original Ip header in data is all
- 6:43encrypted and even if you capture this
- 6:45data you'll never know what the original
- 6:48destination is for this data tunnel mode
- 6:51adds a new IP header which includes the
- 6:53destination of the IPC concentrator and
- 6:56includes the same IPC headers and IPC
- 6:59trailers that we saw in transport mode
- 7:02it's probably not too surprising that
- 7:04most implementations of IPC are going to
- 7:06use the tunnel mode to ensure the
- 7:08highest level of encryption of your
- 7:10original data earlier we mentioned the
- 7:13two protocols that you commonly see
- 7:15associated with IPC one of those
- 7:18protocols is the authentication header
- 7:20or ah ah is used to validate the
- 7:24information that you're receiving over
- 7:25an IPC tunnel and if you're only using
- 7:28Authentication header mode you're
- 7:30sending all of this information over the
- 7:32network in the clear but you're
- 7:34including some additional hashing to
- 7:36ensure the Integrity of this data
- 7:39however in most cases we want to be able
- 7:41to encrypt the data that we're sending
- 7:43over the IPC tunnel and for that reason
- 7:46we'll use encapsulation security payload
- 7:48or ESP this protocol is going to encrypt
- 7:52that original data and encrypt the
- 7:54trailer that we're associating with the
- 7:57and then put around this pack a new IP
- 8:00header an ESP header and an Integrity
- 8:03check value at the end of the packet
- 8:06this is going to encrypt all of your
- 8:07original data but also provide the
- 8:10authentication that you need to ensure
- 8:12that the data is received properly on
- 8:14the other side
About this transcript
This page contains the full transcript of Other Useful Protocols - CompTIA Network+ N10-009 - 1.4 by Professor Messer, generated from the public captions YouTube serves with the video. The transcript has 1,359 words across 200 segments, with the original timestamps preserved so you can click any line to jump to that moment in the embedded player.
What you can do with it
Use the transcript to take notes, quote the speaker, build a study guide, generate a summary with ChatGPT or Claude via the YouTube Summary tool, or export it as a timed subtitle file with YouTube to SRT. You can also re-open it in the transcriber to translate the transcript into 100+ languages.
Free YouTube transcript tool
YouTube2Text is a free YouTube transcript generator — no signup, no daily limit. Paste any YouTube link and get the full transcript instantly, with timestamps, click-to-jump, translation to 100+ languages, AI prompts for ChatGPT, Claude, and Gemini, and exports to TXT, SRT, VTT, or Markdown.