Chapter 6 — Session 9: GRE, IPSec, AH, ESP & IKE


Now we’re continuing the Internet-layer protocols from Session 8. This session is mainly about tunneling and security.

Your Chapter 6 source specifically includes GRE, IPSec, AH, ESP, and IKE as protocols you need to recognize.

📋 Topics to Mark Off

  • ⬜ GRE

  • ⬜ GRE Tunneling

  • ⬜ GRE Encapsulation

  • ⬜ Passenger Protocol

  • ⬜ GRE Security

  • ⬜ GRE Overhead

  • ⬜ IPSec

  • ⬜ GRE vs. IPSec

  • ⬜ GRE over IPSec

  • ⬜ AH — Authentication Header

  • ⬜ AH Authentication

  • ⬜ AH Integrity

  • ⬜ AH vs. ESP

  • ⬜ ESP — Encapsulating Security Payload

  • ⬜ ESP Encryption

  • ⬜ ESP Authentication

  • ⬜ ESP Integrity

  • ⬜ Anti-Replay

  • ⬜ IKE — Internet Key Exchange

  • ⬜ Security Association — SA

  • ⬜ IKE Phase 1

  • ⬜ IKE Phase 2


🚇 1. GRE — Generic Routing Encapsulation

GRE = Generic Routing Encapsulation

GRE is a:

Tunneling protocol

It can take another protocol and encapsulate it inside an IP tunnel.

Your chapter gives examples such as carrying routing protocols and IPv6 traffic through a GRE tunnel.

Think:

Original traffic
      ↓
┌─────────────────┐
│   GRE TUNNEL    │
│  📦 Traffic     │
└─────────────────┘
      ↓
   IP Network

🧠 Memory

GRE = Put traffic inside a tunnel


📦 Encapsulation

This word is important.

Encapsulation

means:

Put one piece of network traffic inside another.

Imagine putting a package inside another package:

📦 Original packet ↓ Put inside GRE ↓ 📦 [ 📦 Original packet ] ↓ Send through tunnel

That's the basic GRE idea.


🧳 Passenger Protocol

Your source uses the term:

Passenger protocol

This means:

The protocol being carried inside the GRE tunnel.

For example:

GRE Tunnel

┌───────────────────┐
│ IPv6              │ ← Passenger
│ OSPF              │
│ EIGRP              │
└───────────────────┘

GRE can carry different Layer 3 protocols because its header identifies what type of protocol is being encapsulated.

🧠

Passenger = what's riding inside the tunnel


🚨 GRE Does NOT Provide Security

This is probably the biggest GRE fact to memorize.

GRE does NOT encrypt traffic.

Your chapter says GRE:

  • Is stateless

  • Has no flow control

  • Provides no security

  • Adds at least 24 bytes of overhead

So:

GRE

✅ Tunneling ✅ Encapsulation ❌ Encryption ❌ Security

🧠 Memory

GRE = tunnel, NOT protection


🔐 2. IPSec — Internet Protocol Security

Now we add security.

IPSec = Internet Protocol Security

IPSec provides a:

Secure method for tunneling traffic across an IP network

Unlike GRE, IPSec provides security for the traffic.

Think:

Internet 🌎
      ↓

🔐 IPSec Tunnel
════════════════════
Encrypted / protected
════════════════════

🧠 Memory

IPSec = Secure IP tunnel


🆚 GRE vs. IPSec

Here's the important distinction:

GRE

IPSec

Creates tunnels

Secures traffic

Can carry multiple protocol types

Provides security

Supports traffic such as multicast/broadcast

Source notes limitations with multicast/broadcast

No encryption

Security/encryption available

Adds overhead

Adds security processing

Your source explains that GRE can carry traffic that IPSec alone does not support, including broadcast, multicast, and multiprotocol traffic.

🧠

GRE = Carry it

IPSec = Protect it


⭐ GRE over IPSec

This is where they become powerful together.

GRE
↓
Carries the traffic

+

IPSec
↓
Secures the traffic

GRE over IPSec

Think:

🔐 IPSec Security ┌─────────────────────────┐ │ GRE Tunnel │ │ │ │ Routing / Multicast │ │ Other protocols │ └─────────────────────────┘

Your chapter specifically says GRE with IPSec allows routing protocols, multicast, and multiprotocol traffic to cross the network securely.

🧠 Memory

GRE carries it. IPSec protects it.


🛡 3. AH — Authentication Header

IPSec has two major security protocols in your chapter:

AH

and

ESP

Your source identifies Authentication Header (AH) and Encapsulating Security Payload (ESP) as the two primary IPSec security protocols.


✅ What Does AH Do?

AH = Authentication Header

AH focuses on:

Authentication + Integrity

It verifies that the packet:

  • Came from the expected source

  • Has not been altered

Your source says AH authenticates both the data and IP header using a one-way hash.

Think:

Packet sent
   ↓

AH hash created

   ↓

Packet arrives

   ↓

Hash checked

   ↓

Same?
✅ Packet authentic

Different?
❌ Packet changed

🚨 AH Does NOT Encrypt

This is EXAM GOLD.

AH does not provide encryption.

It can prove:

"This packet is authentic and wasn't changed."

But it does NOT hide the packet contents.

AH

✅ Authentication ✅ Integrity ❌ Encryption

Your source explicitly says AH does not provide encryption services.

🧠 Memory

AH = Authenticate, not Hide

AH = Authentication Header.


🔒 4. ESP — Encapsulating Security Payload

ESP = Encapsulating Security Payload

ESP provides more security functionality.

The huge one:

Encryption / Confidentiality

Your chapter says ESP can provide:

  • Confidentiality

  • Data-origin authentication

  • Integrity

  • Anti-replay protection

  • Traffic-flow confidentiality


🔐 ESP Confidentiality

Confidentiality basically means:

Encryption

The sender encrypts data so someone sniffing the traffic cannot simply read it.

Original:
PASSWORD123

      ↓
     ESP

Encrypted:
8dj$92jd!#

Your source explains that ESP encryption helps prevent eavesdropping.

🧠 Memory

ESP = Encrypts Secure Payload

Again, memory trick—not the literal acronym.


✅ ESP Integrity

ESP also helps verify:

The data wasn't changed during transmission.

If someone modifies the protected data:

Original

📦 ABC123 Attacker changes it 📦 XYZ123 ↓ Integrity check ↓ ❌ Something changed

Your chapter lists data integrity as one of ESP's protections.


👤 ESP Authentication

ESP can also authenticate the source.

Think:

"Did this protected traffic actually come from the expected endpoint?"

Your source includes data-origin authentication as an ESP capability.


🔁 Anti-Replay Protection

Another important IPSec concept is:

Anti-Replay

A replay attack occurs when an attacker captures valid traffic and later sends the same traffic again.

Example:

✅ Legit packet ↓ Attacker copies it 👀 ↓ Later... ↓ Attacker sends copy again

ESP can use sequence information to help detect duplicate/replayed traffic.

Your chapter specifically describes anti-replay protection and sequence numbers being used to defeat replay attacks.

🧠 Memory

Anti-Replay = Don't accept the same old packet again


🆚 AH vs. ESP

This is VERY testable.

AH

Authentication ✅
Integrity ✅
Encryption ❌

ESP

Encryption 

✅ Authentication ✅ Integrity ✅ Anti-Replay ✅

🧠 Best Memory

AH = Authenticate

ESP = Encrypt + Protect


🔑 5. IKE — Internet Key Exchange

Now we need a way for two IPSec endpoints to agree on:

What security should we use?

That's where:

IKE

comes in.

IKE = Internet Key Exchange

IKE is used to:

Negotiate IPSec security

Your chapter says IKE negotiates Security Associations (SAs) between endpoints.

🧠 Memory

IKE = IPSec negotiation


🤝 Security Association — SA

A Security Association defines things such as:

  • Authentication

  • Encryption

  • IPSec protocols

Basically:

The security rules both endpoints agree to use.

Your chapter explicitly says an SA defines the authentication, encryption, and IPSec protocols used for the connection.

Think:

Router A:
"I want AES."

Router B:
"I support AES."

        ↓

🤝 Security Association

        ↓

Secure IPSec connection

🔑 IKE Phase 1

Your chapter divides IKE into two phases.

Phase 1

The endpoints agree on the initial security parameters.

Your source says they agree on things including:

  • Hash

  • Authentication

  • Group

  • Lifetime

  • Encryption

Then they authenticate and create an initial secure tunnel.

Don't overcomplicate it.

🧠 Think:

Phase 1 = Build the secure relationship


🔐 IKE Phase 2

Then:

Phase 2 negotiates IPSec itself

The already-secure Phase 1 tunnel protects the Phase 2 negotiation.

Phase 2 determines the IPSec transform information, including things such as AH/ESP, encryption, hashing, and tunnel mode.

🧠 Think:

Phase 1 = Secure the negotiation

Phase 2 = Build the IPSec connection

Your source says the key takeaway for Network+ is simply that IKE negotiates the IPSec tunnel in two phases.


🚨 EXAM SCENARIO #1

A company wants to tunnel routing-protocol traffic between two offices, but GRE by itself does not protect the data.

What solution makes sense?

✅ GRE over IPSec

Why?

GRE carries the traffic.

IPSec secures it.


🚨 EXAM SCENARIO #2

An administrator needs packet authentication and integrity but does not need encryption.

Which IPSec protocol?

✅ AH


🚨 EXAM SCENARIO #3

An administrator needs confidentiality/encryption for IPSec traffic.

Which protocol?

✅ ESP


🚨 EXAM SCENARIO #4

Two VPN endpoints need to negotiate the security settings used by IPSec.

Which protocol?

✅ IKE


🎴 Flashcards

⭐ 1

What is GRE primarily used for?

A. DNS resolution
B. Tunneling and encapsulating other protocols
C. Assigning IP addresses
D. Email encryption

✅ GRE


⭐ 2 — EXAM GOLD

Does GRE provide encryption by itself?

A. Yes

B. No

✅ No

GRE provides tunneling, not security.


⭐ 3

What is a passenger protocol in GRE?

A. The protocol managing encryption

B. The protocol being carried inside the GRE tunnel

C. The routing table

D. The TCP handshake

✅ B


⭐ 4

Which technology provides secure tunneling across an IP network?

A. ARP

B. GRE alone

C. IPSec

D. ICMP

✅ IPSec


⭐ 5 — Scenario

A company needs to carry routing-protocol traffic through a tunnel while also protecting that traffic.

Which solution BEST fits?

A. GRE only

B. IPSec only

C. GRE over IPSec

D. ARP over TCP

✅ GRE over IPSec


⭐ 6

Which two primary security protocols does your chapter associate with IPSec?

A. TCP and UDP

B. GRE and ARP

C. AH and ESP

D. ICMP and IP

✅ AH and ESP


⭐ 7 — EXAM GOLD

Which IPSec protocol provides authentication and integrity but does not provide encryption?

A. AH

B. ESP

C. GRE

D. IKE

✅ AH


⭐ 8

What does AH stand for?

A. Authentication Header

B. Authorization Header

C. Authentication Host

D. Advanced Hash

✅ Authentication Header


⭐ 9

Which statement correctly describes AH?

A. AH only provides encryption.

B. AH verifies authenticity/integrity but does not encrypt traffic.

C. AH is a routing protocol.

D. AH assigns encryption keys by itself.

✅ B


⭐ 10 — EXAM GOLD

Which IPSec protocol provides confidentiality through encryption?

A. AH

B. ESP

C. GRE

D. ARP

✅ ESP


⭐ 11

What does ESP stand for?

A. Encrypted Security Protocol

B. Encapsulating Security Payload

C. Ethernet Security Payload

D. Encapsulated Session Protocol

✅ B


⭐ 12

Which security feature helps prevent a captured valid packet from being sent again later?

A. ARP caching

B. Flow control

C. Anti-replay

D. DNSSEC

✅ Anti-replay


⭐ 13

Which protocol negotiates IPSec Security Associations between endpoints?

A. AH

B. GRE

C. IKE

D. ARP

✅ IKE


⭐ 14

What does IKE stand for?

A. Internet Kernel Encryption

B. Internet Key Exchange

C. Internal Key Encapsulation

D. Internet Key Ethernet

✅ Internet Key Exchange


⭐ 15

What does an IPSec Security Association define?

A. DNS records

B. DHCP addresses

C. Authentication, encryption, and IPSec security settings

D. MAC-address mappings

✅ C


⭐ 16

What is the main purpose of IKE Phase 1?

A. Resolve the VPN gateway MAC address

B. Establish initial secure parameters and a secure relationship between endpoints

C. Transfer files

D. Configure DHCP

✅ B


⭐ 17

What primarily occurs during IKE Phase 2 in your chapter?

A. DNS resolution

B. ARP discovery

C. Negotiation of the IPSec connection and transform information

D. TCP connection teardown

✅ C


⭐ 18 — EXAM TRAP

Which statement correctly compares GRE and IPSec?

A. GRE encrypts traffic while IPSec only encapsulates it.

B. GRE provides tunneling, while IPSec provides security.

C. Both provide identical security.

D. Neither supports tunneling.

✅ B


🧠 Memory Board

🚇 GRE TUNNELING Carries other protocols "Passenger protocols" NO SECURITY ❌ NO ENCRYPTION ❌ 🔐 IPSec SECURE tunneling GRE + IPSec = Carry it + Protect it 🛡️ AH Authentication Header Authentication ✅ Integrity ✅ Encryption ❌ "Authenticate, not Hide" 🔒 ESP Encapsulating Security Payload Encryption ✅ Authentication ✅ Integrity ✅ Anti-Replay ✅ 🔑 IKE Internet Key Exchange Negotiates IPSec SA Security Association Defines security settings IKE Phase 1 = Build secure relationship IKE Phase 2 = Negotiate IPSec connection

🎯 Know These Cold

GRE = Tunneling / encapsulation

GRE provides NO encryption

GRE passenger protocol = traffic carried inside the tunnel

IPSec = Secure tunneling

GRE over IPSec = GRE carries traffic + IPSec protects it

AH = Authentication + integrity, NO encryption

ESP = Encryption/confidentiality + authentication + integrity + anti-replay

IKE = Negotiates IPSec

SA = Security Association

IKE Phase 1 = Initial secure relationship

IKE Phase 2 = Negotiate the IPSec connection

This completes the major Internet-layer security protocols in your Chapter 6 objectives.


GRE Encapsulation
🧠 Encapsulation = packet inside another packet.


Encapsulating Security Payload.
ESP can provide confidentiality, authentication, integrity, anti-replay, and limited traffic-flow confidentiality.
🧠 ESP = Encrypt + Protect.


IPSec secures traffic across IP networks using protections such as authentication, integrity, and encryption.
🧠
IPSec = secure IP tunneling.


IKE Phase 1 establishes initial secure parameters, authenticates the peers, and builds the secure relationship.
🧠
Phase 1 = build the secure relationship.


IKE Phase 2 negotiates the actual IPSec connection and transform information, including AH/ESP, encryption, hashing, and mode.
🧠
Phase 2 = negotiate the IPSec connection


A Security Association defines agreed authentication, encryption, and IPSec security settings.
🧠
SA = agreed security settings.


Anti-replay detects and rejects captured valid packets that are resent later.
🧠
Anti-Replay = don't accept the same old packet again.


GRE vs IPSec

GRE carries traffic through tunnels. IPSec protects traffic. GRE alone does not encrypt.


A passenger protocol is the protocol being carried inside the GRE tunnel, such as IPv6, OSPF, or EIGRP.
🧠
Passenger = what's riding inside GRE.


AH authenticates and protects integrity without encryption. ESP can provide encryption, integrity, authentication, and anti-replay.
🧠
AH = authenticate. ESP = encrypt + protect.