YouTube2Text

Other Useful Protocols - CompTIA Network+ N10-009 - 1.4 — Transcript

by Professor Messer · 1,359 words · 200 segments · language en · Watch on YouTube

Full transcript

  1. 0:02there will be many times as a network
  2. 0:03professional when you'd like to know if
  3. 0:05a device is on the network and operating
  4. 0:08and one protocol that can provide you
  5. 0:10with that is icmp this is the internet
  6. 0:13control message protocol you can think
  7. 0:16of this as a way to check in with that
  8. 0:18device very similar to sending a text
  9. 0:20message to see if you get a response
  10. 0:22back from someone icmp is another
  11. 0:25protocol carried by IP but it doesn't
  12. 0:27use TCP or UDP instead icmp is its own
  13. 0:32protocol although icmp can be used for a
  14. 0:35number of administrative tasks it's most
  15. 0:37commonly associated with a way to send a
  16. 0:40message to a device to see if it's alive
  17. 0:42and operating on the network and see if
  18. 0:44you can get a response back from that
  19. 0:46device whenever you use the Ping command
  20. 0:49to Ping an IP address on the network
  21. 0:52it's using icmp to provide that ping
  22. 0:55functionality but icmp can also provide
  23. 0:58you with information about other things
  24. 1:00that may be happening on the network for
  25. 1:02example if you're trying to access a
  26. 1:03network that is not accessible from your
  27. 1:05location icmp will give you a message
  28. 1:08that that network is not reachable or
  29. 1:10icmp can tell you that the time to live
  30. 1:13that's inside of data that you've sent
  31. 1:15has expired and it's received an icmp
  32. 1:18time exceeded message from that device
  33. 1:22another common protocol on our network
  34. 1:24is gr or the generic routing
  35. 1:27encapsulation protocol if you're
  36. 1:29creating a tunnel Tel between two
  37. 1:30endpoints this is commonly done with
  38. 1:33vpns for example you're creating this
  39. 1:35tunnel using gr this allows us to
  40. 1:39encapsulate information within an IP
  41. 1:41packet send it across this gr tunnel and
  42. 1:44decapsulate it on the other side this
  43. 1:47does not however provide encryption of
  44. 1:50this data we'll need to provide
  45. 1:51additional VPN protocols to encrypt the
  46. 1:54data that we are encapsulating in a gr
  47. 1:57tunnel these vpm protocols are referred
  48. 2:00to as virtual private Network protocols
  49. 2:03and it's very common to use these vpm
  50. 2:05protocols to encrypt or protect any data
  51. 2:08being sent across one of those tunnels
  52. 2:11it's often common to use a purpose-built
  53. 2:13appliance to provide this encryption and
  54. 2:16decryption process at the central point
  55. 2:19we refer to this as a VPN concentrator
  56. 2:22sometimes this is a standalone unit but
  57. 2:24it's very often integrated into an
  58. 2:26existing firewall that's connected to
  59. 2:28the network these concentr ERS are often
  60. 2:30Hardware devices with specialized
  61. 2:32encryption Hardware built into the
  62. 2:34device to add efficiency and throughput
  63. 2:37but if you have a limited number of
  64. 2:38users it's also possible to use your VPN
  65. 2:41concentrator as software in an operating
  66. 2:44system this is a common sight tosite VPN
  67. 2:47configuration where a corporate Network
  68. 2:49may be connected to a remote site over a
  69. 2:52public network such as the internet
  70. 2:54we'll have VPN concentrators which are
  71. 2:56usually firewalls or routers those are
  72. 2:59connecting these two sites together over
  73. 3:02the internet but all of this traffic
  74. 3:04that's being sent across that public
  75. 3:06internet is being encrypted using this
  76. 3:08VPN technology one of the popular
  77. 3:11protocols used to provide that level of
  78. 3:14encryption over those tunnels is IPC
  79. 3:17this stands for Internet Protocol
  80. 3:19security and it's one of the most
  81. 3:20popular ways to encrypt data being sent
  82. 3:23across these vpns not only does IPC
  83. 3:27provide encryption for confidentiality
  84. 3:29it can also provide digital signatures
  85. 3:31of every packet which includes integrity
  86. 3:33and anti-replay functionality this is
  87. 3:36also a very common protocol and it can
  88. 3:38be used across many different
  89. 3:39manufacturer devices for example you
  90. 3:42might have a firewall from one
  91. 3:43manufacturer on one side of a VPN tunnel
  92. 3:46and a firewall from a completely
  93. 3:48different manufacturer on the other side
  94. 3:50of the VPN tunnel because IPC is such a
  95. 3:53standard protocol those two firewalls
  96. 3:55can easily connect to each other and
  97. 3:57transfer information over that I IPC
  98. 4:00tunnel when you're using IPC there are
  99. 4:02commonly two primary protocols that are
  100. 4:04in use one is the authentication header
  101. 4:07or ah and the other is the encapsulation
  102. 4:10security payload or
  103. 4:12ESP in order for IPC to be able to send
  104. 4:16this encrypted data across the network
  105. 4:18we first need to create this tunnel and
  106. 4:20we do this by performing a series of
  107. 4:22steps prior to sending any data those
  108. 4:25steps are referred to as the internet
  109. 4:27key exchange or Ike internet key
  110. 4:30exchange allows both sides of the
  111. 4:32conversation to agree on the encryption
  112. 4:34and decryption keys that will be used
  113. 4:36for the duration of that VPN tunnel we
  114. 4:39refer to this agreement as a security
  115. 4:42Association or an sa there are two
  116. 4:45phases to this key exchange process the
  117. 4:48first phase commonly uses Diffy Helman
  118. 4:50to create a shared secret key for both
  119. 4:53sides of the conversation this usually
  120. 4:55operates using UDP Port 500 and we refer
  121. 4:59to this as as ISAC camp this is the
  122. 5:01Internet Security Association and Key
  123. 5:04Management protocol in phase two we
  124. 5:06coordinate which Cipher should be used
  125. 5:08for the encryption and the key sizes
  126. 5:10that would be appropriate and it
  127. 5:12negotiates both the inbound and outbound
  128. 5:14security Association to be used for this
  129. 5:17IPC tunnel so visually with phase one
  130. 5:21we're building the ISA Camp tunnel over
  131. 5:23UDP Port 500 in phase two we're
  132. 5:26including the encrypted data over the
  133. 5:29encaps ation security payload or ESP
  134. 5:32tunnel this gives us the foundation we
  135. 5:34need to be able to send this encrypted
  136. 5:36data over the IPC tunnel if you're
  137. 5:39building your own IP tunnel you may be
  138. 5:42asked whether you'd like to use
  139. 5:43transport mode or tunnel mode both of
  140. 5:46these work differently and will protect
  141. 5:49data in different ways let's take the
  142. 5:51original packet which includes an IP
  143. 5:53header and some data within that IP
  144. 5:55packet we would like to send that over
  145. 5:57an IPC tunnel if we use trans transport
  146. 6:00mode to send this IPC data we're going
  147. 6:02to insert an IPC header between the IP
  148. 6:06header and the data all of that is going
  149. 6:08to be in the clear anything within the
  150. 6:10data portion of that IP packet will be
  151. 6:12encrypted and then the ipct trailer put
  152. 6:15at the end of the packet notice that the
  153. 6:18original Ip header is not encrypted when
  154. 6:20using transport mode and if someone does
  155. 6:23capture this data they'll be able to see
  156. 6:25the original Ip header and be able to
  157. 6:28understand where this traffic is
  158. 6:29intended to go even if they can't see
  159. 6:32the encrypted data within the packet a
  160. 6:34much more secure method of using an IP
  161. 6:37SEC tunnel is tunnel mode in tunnel mode
  162. 6:40the original Ip header in data is all
  163. 6:43encrypted and even if you capture this
  164. 6:45data you'll never know what the original
  165. 6:48destination is for this data tunnel mode
  166. 6:51adds a new IP header which includes the
  167. 6:53destination of the IPC concentrator and
  168. 6:56includes the same IPC headers and IPC
  169. 6:59trailers that we saw in transport mode
  170. 7:02it's probably not too surprising that
  171. 7:04most implementations of IPC are going to
  172. 7:06use the tunnel mode to ensure the
  173. 7:08highest level of encryption of your
  174. 7:10original data earlier we mentioned the
  175. 7:13two protocols that you commonly see
  176. 7:15associated with IPC one of those
  177. 7:18protocols is the authentication header
  178. 7:20or ah ah is used to validate the
  179. 7:24information that you're receiving over
  180. 7:25an IPC tunnel and if you're only using
  181. 7:28Authentication header mode you're
  182. 7:30sending all of this information over the
  183. 7:32network in the clear but you're
  184. 7:34including some additional hashing to
  185. 7:36ensure the Integrity of this data
  186. 7:39however in most cases we want to be able
  187. 7:41to encrypt the data that we're sending
  188. 7:43over the IPC tunnel and for that reason
  189. 7:46we'll use encapsulation security payload
  190. 7:48or ESP this protocol is going to encrypt
  191. 7:52that original data and encrypt the
  192. 7:54trailer that we're associating with the
  193. 7:57and then put around this pack a new IP
  194. 8:00header an ESP header and an Integrity
  195. 8:03check value at the end of the packet
  196. 8:06this is going to encrypt all of your
  197. 8:07original data but also provide the
  198. 8:10authentication that you need to ensure
  199. 8:12that the data is received properly on
  200. 8:14the other side

About this transcript

This page contains the full transcript of Other Useful Protocols - CompTIA Network+ N10-009 - 1.4 by Professor Messer, generated from the public captions YouTube serves with the video. The transcript has 1,359 words across 200 segments, with the original timestamps preserved so you can click any line to jump to that moment in the embedded player.

What you can do with it

Use the transcript to take notes, quote the speaker, build a study guide, generate a summary with ChatGPT or Claude via the YouTube Summary tool, or export it as a timed subtitle file with YouTube to SRT. You can also re-open it in the transcriber to translate the transcript into 100+ languages.

Free YouTube transcript tool

YouTube2Text is a free YouTube transcript generator — no signup, no daily limit. Paste any YouTube link and get the full transcript instantly, with timestamps, click-to-jump, translation to 100+ languages, AI prompts for ChatGPT, Claude, and Gemini, and exports to TXT, SRT, VTT, or Markdown.