Chapter 20: Securing DMVPN Tunnels
Introduction
Overview provided by Cisco on secure transport mechanisms in DMVPN (Dynamic Multipoint Virtual Private Network).
Chapter 20 Content
This chapter covers the following topics:
Elements of Secure Transport
IPsec Fundamentals
IPsec Tunnel Protection
Elements of Secure Transport
Core principles that guarantee data security in networks:
Data confidentiality: Keeps data private and viewable only by authorized users. This is maintained through encryption.
Data integrity: Ensures that data remains accurate and unmodified during transmission, typically using digital signatures or checksums.
Data availability: Guarantees network access is always available to allow data transport, often achieved through redundancy and designing for failover.
Importance of Secure Transport
Businesses may lose customers if they cannot guarantee the security of customer information, highlighting the importance of confidentiality, integrity, and availability.
Typical WAN Network
The conventional method for securing data assumes the entire controlled infrastructure is secure, with encryption required only when data travels over public internet connections.
Internet as WAN Transport
When using the internet as a transport medium for WAN data:
Lack of guarantees: The internet cannot assure data confidentiality or integrity by itself.
IPsec Integration: To maintain these attributes for DMVPN tunnels using the internet, IPsec encryption is added. This set of standards is defined in RFC 2401.
IPsec Fundamentals
DMVPN tunnels lack encryption by default but can be secured through IPsec.
Components of IPsec Security Architecture:
Security Protocols
Security Associations (SAs)
Key Management (using IKE - Internet Key Exchange)
Functions of IPsec with DMVPN Tunnels
Provides the following security functions:
Origin Authentication: Users authenticate the origin of information either through static Pre-Shared Keys or dynamic certificate-based methods.
Data Confidentiality: Ensures only authorized users can see the data through encryption.
Data Integrity: Utilizes hashing algorithms to ensure packets are unchanged while in transit.
Replay Detection: Safeguards data by preventing unauthorized capture and re-insertion of traffic.
Periodic Rekeying: Security keys are regenerated every specific time period or traffic volume, enhancing security.
Perfect Forward Secrecy: Ensures future keys aren't compromised even if one key is compromised.
Security Protocols in IPsec
Two primary protocols are utilized for achieving data integrity and confidentiality:
Authentication Header (AH): Provides security features such as integrity and source authentication, employing protocol number 51 in the IP header.
Encapsulating Security Payload (ESP): Engages in data confidentiality and authentication, utilizing protocol number 50 in the IP header.
Key Management and Security Associations
Key Management: Refers to protocols and methods for distributing and managing encryption keys, typically using IKE with IKEv2 offering various advantages (e.g., EAP support, reduction in bandwidth).
Security Associations (SAs):
IKE SA: Manages key management and functions utilizing IPsec SAs.
IPsec SA: Provides secure data transmission functions across different sites, characterized as unidirectional requiring paired inbound and outbound parameters.
DMVPN Packet Headers and ESP Modes
ESP Modes of Operation:
Tunnel Mode: Encrypts the entire packet, adding new IPsec headers.
Transport Mode: Only the payload is encrypted and authenticated, based on original IP headers.
DMVPN without IPsec: Incorporates GRE headers, adding 24 bytes of overhead (20 bytes for GRE IP header and 4 bytes for GRE flags).
DMVPN with IPsec: Each mode introduces specific overheads including ESP structure.
IPsec Tunnel Protection
Essential to enable IPsec on all DMVPN devices; mismatches can prevent tunnel establishment.
Authentication Scenarios
Pre-Shared Key Authentication Steps:
Establishment of IKEv2 configurations, including keyrings, profiles, transform sets, and profiles.
IKEv2 Keyring Steps
The process for creating a keyring involves:
Creation of the keyring with
crypto ikev2 keyring keyring-name.Peer configuration with
peer peer-name.Specify the IP address with
address network subnet-mask.Define pre-shared key.
IKEv2 Profile Configuration Steps
Includes defining the IKEv2 profile, matching peers, associating with optional configurations, and defining authentication methods.
IPsec Transform Set
Specifies parameters for the IPsec transport protocols (e.g., ESP).
Commands utilized include creation definitions and mode specifications.
IPsec Profile
Merges both transform set and IKEv2 profile, crucial for operationalizing security parameters.
Tunnel Encryption Procedures
Linking the IPsec profile to the DMVPN tunnel interface with shared security associations using
tunnel protection ipsec profile profile-name [shared].Each encrypted packet receives a unique sequence number for replay detection.
Advanced Features
Dead Peer Detection (DPD): Monitors peer connection by sending periodic queries.
NAT Keepalives: Preserves NAT mappings during distant peer connections, utilizing minimal UDP packets.
Configuration and Verification of IPsec DMVPN
Example configurations provided for implementing such protection in practical deployments.
Verification commands include
show dmvpn detailandshow crypto ipsec safor status checking and security association details.
IKEv2 Protection Overview
IKEv2 enhances router security against threats like denial of service by limiting simultaneous session establishment and employing cookie challenges to validate sessions under logical attacks.
Example Configuration for IKEv2 Protection
R41 minimizes session limits and employs cookie challenges to safeguard against intrusions under high load conditions.
Key Topics and Terms for Review
Key terms discussed in the chapter for examination preparedness:
Authentication Header (AH)
Encapsulating Security Payload (ESP)
Data confidentiality, integrity, availability
Replay detection
Security association (SA)
Command Reference for DMVPN and IPsec
Commands detailed for configuring IKEv2 keyrings, profiles, IPsec transform sets, and profiles, enabling efficient implementation and management of secure tunnels.
Command Reference Syntax
Examples of syntax for typical command operations, such as configuring a keyring, profile, transform set, and final commands for encryption functionalities.