Chapter 20: Securing DMVPN Tunnels


Introduction

  • Overview provided by Cisco on secure transport mechanisms in DMVPN (Dynamic Multipoint Virtual Private Network).

Chapter 20 Content

  • This chapter covers the following topics:

    • Elements of Secure Transport

    • IPsec Fundamentals

    • IPsec Tunnel Protection

Elements of Secure Transport

  • Core principles that guarantee data security in networks:

    • Data confidentiality: Keeps data private and viewable only by authorized users. This is maintained through encryption.

    • Data integrity: Ensures that data remains accurate and unmodified during transmission, typically using digital signatures or checksums.

    • Data availability: Guarantees network access is always available to allow data transport, often achieved through redundancy and designing for failover.

Importance of Secure Transport
  • Businesses may lose customers if they cannot guarantee the security of customer information, highlighting the importance of confidentiality, integrity, and availability.

Typical WAN Network

  • The conventional method for securing data assumes the entire controlled infrastructure is secure, with encryption required only when data travels over public internet connections.

Internet as WAN Transport
  • When using the internet as a transport medium for WAN data:

    • Lack of guarantees: The internet cannot assure data confidentiality or integrity by itself.

    • IPsec Integration: To maintain these attributes for DMVPN tunnels using the internet, IPsec encryption is added. This set of standards is defined in RFC 2401.

IPsec Fundamentals

  • DMVPN tunnels lack encryption by default but can be secured through IPsec.

  • Components of IPsec Security Architecture:

    • Security Protocols

    • Security Associations (SAs)

    • Key Management (using IKE - Internet Key Exchange)

Functions of IPsec with DMVPN Tunnels
  • Provides the following security functions:

    • Origin Authentication: Users authenticate the origin of information either through static Pre-Shared Keys or dynamic certificate-based methods.

    • Data Confidentiality: Ensures only authorized users can see the data through encryption.

    • Data Integrity: Utilizes hashing algorithms to ensure packets are unchanged while in transit.

    • Replay Detection: Safeguards data by preventing unauthorized capture and re-insertion of traffic.

    • Periodic Rekeying: Security keys are regenerated every specific time period or traffic volume, enhancing security.

    • Perfect Forward Secrecy: Ensures future keys aren't compromised even if one key is compromised.

Security Protocols in IPsec

  • Two primary protocols are utilized for achieving data integrity and confidentiality:

    • Authentication Header (AH): Provides security features such as integrity and source authentication, employing protocol number 51 in the IP header.

    • Encapsulating Security Payload (ESP): Engages in data confidentiality and authentication, utilizing protocol number 50 in the IP header.

Key Management and Security Associations

  • Key Management: Refers to protocols and methods for distributing and managing encryption keys, typically using IKE with IKEv2 offering various advantages (e.g., EAP support, reduction in bandwidth).

  • Security Associations (SAs):

    • IKE SA: Manages key management and functions utilizing IPsec SAs.

    • IPsec SA: Provides secure data transmission functions across different sites, characterized as unidirectional requiring paired inbound and outbound parameters.

DMVPN Packet Headers and ESP Modes

  • ESP Modes of Operation:

    • Tunnel Mode: Encrypts the entire packet, adding new IPsec headers.

    • Transport Mode: Only the payload is encrypted and authenticated, based on original IP headers.

  • DMVPN without IPsec: Incorporates GRE headers, adding 24 bytes of overhead (20 bytes for GRE IP header and 4 bytes for GRE flags).

  • DMVPN with IPsec: Each mode introduces specific overheads including ESP structure.

IPsec Tunnel Protection

  • Essential to enable IPsec on all DMVPN devices; mismatches can prevent tunnel establishment.

Authentication Scenarios
  • Pre-Shared Key Authentication Steps:

    • Establishment of IKEv2 configurations, including keyrings, profiles, transform sets, and profiles.

IKEv2 Keyring Steps

  • The process for creating a keyring involves:

    1. Creation of the keyring with crypto ikev2 keyring keyring-name.

    2. Peer configuration with peer peer-name.

    3. Specify the IP address with address network subnet-mask.

    4. Define pre-shared key.

IKEv2 Profile Configuration Steps
  • Includes defining the IKEv2 profile, matching peers, associating with optional configurations, and defining authentication methods.

IPsec Transform Set

  • Specifies parameters for the IPsec transport protocols (e.g., ESP).

  • Commands utilized include creation definitions and mode specifications.

IPsec Profile

  • Merges both transform set and IKEv2 profile, crucial for operationalizing security parameters.

Tunnel Encryption Procedures

  • Linking the IPsec profile to the DMVPN tunnel interface with shared security associations using tunnel protection ipsec profile profile-name [shared].

    • Each encrypted packet receives a unique sequence number for replay detection.

Advanced Features
  • Dead Peer Detection (DPD): Monitors peer connection by sending periodic queries.

  • NAT Keepalives: Preserves NAT mappings during distant peer connections, utilizing minimal UDP packets.

Configuration and Verification of IPsec DMVPN

  • Example configurations provided for implementing such protection in practical deployments.

  • Verification commands include show dmvpn detail and show crypto ipsec sa for status checking and security association details.

IKEv2 Protection Overview

  • IKEv2 enhances router security against threats like denial of service by limiting simultaneous session establishment and employing cookie challenges to validate sessions under logical attacks.

Example Configuration for IKEv2 Protection
  • R41 minimizes session limits and employs cookie challenges to safeguard against intrusions under high load conditions.

Key Topics and Terms for Review

  • Key terms discussed in the chapter for examination preparedness:

    • Authentication Header (AH)

    • Encapsulating Security Payload (ESP)

    • Data confidentiality, integrity, availability

    • Replay detection

    • Security association (SA)

Command Reference for DMVPN and IPsec

  • Commands detailed for configuring IKEv2 keyrings, profiles, IPsec transform sets, and profiles, enabling efficient implementation and management of secure tunnels.

Command Reference Syntax
  • Examples of syntax for typical command operations, such as configuring a keyring, profile, transform set, and final commands for encryption functionalities.