IPSec

0.0(0)
Studied by 0 people
call kaiCall Kai
learnLearn
examPractice Test
spaced repetitionSpaced Repetition
heart puzzleMatch
flashcardsFlashcards
GameKnowt Play
Card Sorting

1/23

encourage image

There's no tags or description

Looks like no tags are added yet.

Last updated 12:27 PM on 6/21/26
Name
Mastery
Learn
Test
Matching
Spaced
Call with Kai
Chat

No analytics yet

Send a link to your students to track their progress

24 Terms

1
New cards

Why would we want to use IP Security ? (Regarding IEEE 802.11i)

Previously, we discussed of security between hosts directly connected (over a wireless network), but many security concerns are shared across layers

2
New cards

Give examples of security concerns shared across layers.

Disallowing links to untrusted sites
Authenticating all incoming traffic from a site
Encrypting all outgoing traffic from a site

3
New cards

What can provide IPSec ?

IPSec can provide application-independent and technology-independent security services such as Authentication, Confidentiality and Key management

4
New cards

What are the different applications of IPSec ?

Secure branch connectivity over the Internet
Secure Remote Access over the Internet
Secure Communication Channels across Organizations
Additional Layer of Security to app-layer security

5
New cards

What are IPSEC documents ?

Authentication Header : IP message authentication but is today replaced by ESP
Encapsulating Security Payload : combined encryption and authentication of IP packets
Internet Key Exchange : defines key management schemes for IPsec
Cryptographic algorithms : recommended cipher suites

6
New cards

What are the IPSec services ?

Access control
Connection-less integrity
Data origin authentication
Rejection of replayed packets
Confidentiality
Limited traffic flow confidentiality

7
New cards

What services do ESP protocol provide ?

Connection-less Integrity
Data Origin Authentication
Anti-replay service
Confidentiality
Traffic Flow Confidentiality

8
New cards

What do ESP packets contain ?

Payload Data
Next Header
Padding
Integrity Check Value which provides integrity
IV value

9
New cards

What does IKE add comparing to DH ?

It uses cookies to counter clogging attacks
It enables the two parties to negotiate a modular group specifying the global parameters of the DH key exchange
It uses nonces to protect against replay attacks
It enables the exchange of DH public key values
It authenticates the DH exchange to counter MiTM attacks

10
New cards

What are SAs in IPSec ?

Security Associations are one-way logical connections between a sender and a receiver and it defines the parameters of security services to be used for protecting traffic

11
New cards

How are SAs uniquely identified ?

Security Parameters Index : to identify the related security parameters at the receiver of the packet
IP Destination Address : IP of the destination end point
Security Protocol Identifier : specify whether it is AH or ESP

12
New cards

What is the Transport Mode ?

Only traffic from transport-layer is encrypted and authenticated so traffic analysis is possible

13
New cards

What is the Tunnel Mode ?

Packets from IP-layer are entirely encrypted (both header and payload) and authenticated so no routers on the path can see the original IP header

14
New cards

Why is Tunnel Mode preferable to Transport Mode when configuring a VPN tunnel between two gateways?

Tunnel Mode is preferable because it protects the entire original IP packet

15
New cards

What are the main functions of the Security Policy Database (SPD) ?

SPD defines what to do on the traffic based on criteria like IP addresses and ports. It decides if traffic should be Bypassed (no protection), Discarded or Protected (IPSec) and map it to a particular SA

16
New cards

What are the main functions of the Security Association Database (SAD) ?

It is a database defining the parameters associated with each SA used to process the packets that the SPD has decided to protect

17
New cards

Explain how the anti-replay mechanism in ESP works. What does the receiver do when it receives a duplicate or old packet?

This mechanism is based on last valid received Sequence Number and we advance the window if a valid packet is received
If a packet’s sequence number goes out of the sliding window or if it matches a bit already marked as received within the window then the packet is dropped

18
New cards

What is the main difference in protection offered by AH and ESP?

Both AH and ESP provide data integrity, authentication and anti-replay but only ESP provides confidentiality through encryption

19
New cards

True or False: In Transport Mode, the IP header is encrypted. Justify your answer.

False : in Transport Mode only the IP payload is encrypted so routers can read the IP header to deliver the packet

20
New cards

Which of the following is not a service provided by IPSec ESP? (A. Confidentiality, B. Authentication, C. Replay protection, D. Traffic routing)

D. Traffic routing

21
New cards

What role does the PRF play in key derivation in IPSec?

In IPSec, the Pseudo Random Function is a cryptographic tool that generates key materials and authentication hashes from a single shared secret

22
New cards

What are the advantages of implementing security at the network layer compared to the application or transport layer ?

It is application-independent so applications do not need to be reconfigured to be secure
Security policies can be enforced for all host traffic at a single choke point

23
New cards

Key Management in IPSec ?

4 keys are required : transmit and receive pairs. Two types of key management defined in IPSec :
Manual : manual configuration of the keys by system administrator
Automatic : on-demand creation of keys via an automated system. Today, standard is Internet Key Exchange protocol based on DH

24
New cards

What are the disadvantages of implementing security at the network layer compared to the application or transport layer ?

It lacks context about users and applications (uses only addresses and ports)
Encapsulating and encrypting every network packet can cause significant latency