Chapter 6 — Session 9: GRE, IPSec, AH, ESP & IKE
Now we’re continuing the Internet-layer protocols from Session 8. This session is mainly about tunneling and security.
Your Chapter 6 source specifically includes GRE, IPSec, AH, ESP, and IKE as protocols you need to recognize.
📋 Topics to Mark Off
⬜ GRE
⬜ GRE Tunneling
⬜ GRE Encapsulation
⬜ Passenger Protocol
⬜ GRE Security
⬜ GRE Overhead
⬜ IPSec
⬜ GRE vs. IPSec
⬜ GRE over IPSec
⬜ AH — Authentication Header
⬜ AH Authentication
⬜ AH Integrity
⬜ AH vs. ESP
⬜ ESP — Encapsulating Security Payload
⬜ ESP Encryption
⬜ ESP Authentication
⬜ ESP Integrity
⬜ Anti-Replay
⬜ IKE — Internet Key Exchange
⬜ Security Association — SA
⬜ IKE Phase 1
⬜ IKE Phase 2
🚇 1. GRE — Generic Routing Encapsulation
GRE = Generic Routing Encapsulation
GRE is a:
Tunneling protocol
It can take another protocol and encapsulate it inside an IP tunnel.
Your chapter gives examples such as carrying routing protocols and IPv6 traffic through a GRE tunnel.
Think:
Original traffic
↓
┌─────────────────┐
│ GRE TUNNEL │
│ 📦 Traffic │
└─────────────────┘
↓
IP Network🧠 Memory
GRE = Put traffic inside a tunnel
📦 Encapsulation
This word is important.
Encapsulation
means:
Put one piece of network traffic inside another.
Imagine putting a package inside another package:
📦 Original packet ↓ Put inside GRE ↓ 📦 [ 📦 Original packet ] ↓ Send through tunnel
That's the basic GRE idea.
🧳 Passenger Protocol
Your source uses the term:
Passenger protocol
This means:
The protocol being carried inside the GRE tunnel.
For example:
GRE Tunnel
┌───────────────────┐
│ IPv6 │ ← Passenger
│ OSPF │
│ EIGRP │
└───────────────────┘GRE can carry different Layer 3 protocols because its header identifies what type of protocol is being encapsulated.
🧠
Passenger = what's riding inside the tunnel
🚨 GRE Does NOT Provide Security
This is probably the biggest GRE fact to memorize.
GRE does NOT encrypt traffic.
Your chapter says GRE:
Is stateless
Has no flow control
Provides no security
Adds at least 24 bytes of overhead
So:
GRE
✅ Tunneling ✅ Encapsulation ❌ Encryption ❌ Security
🧠 Memory
GRE = tunnel, NOT protection
🔐 2. IPSec — Internet Protocol Security
Now we add security.
IPSec = Internet Protocol Security
IPSec provides a:
Secure method for tunneling traffic across an IP network
Unlike GRE, IPSec provides security for the traffic.
Think:
Internet 🌎
↓
🔐 IPSec Tunnel
════════════════════
Encrypted / protected
════════════════════🧠 Memory
IPSec = Secure IP tunnel
🆚 GRE vs. IPSec
Here's the important distinction:
GRE | IPSec |
|---|---|
Creates tunnels | Secures traffic |
Can carry multiple protocol types | Provides security |
Supports traffic such as multicast/broadcast | Source notes limitations with multicast/broadcast |
No encryption | Security/encryption available |
Adds overhead | Adds security processing |
Your source explains that GRE can carry traffic that IPSec alone does not support, including broadcast, multicast, and multiprotocol traffic.
🧠
GRE = Carry it
IPSec = Protect it
⭐ GRE over IPSec
This is where they become powerful together.
GRE
↓
Carries the traffic
+
IPSec
↓
Secures the trafficGRE over IPSec
Think:
🔐 IPSec Security ┌─────────────────────────┐ │ GRE Tunnel │ │ │ │ Routing / Multicast │ │ Other protocols │ └─────────────────────────┘
Your chapter specifically says GRE with IPSec allows routing protocols, multicast, and multiprotocol traffic to cross the network securely.
🧠 Memory
GRE carries it. IPSec protects it.
🛡 3. AH — Authentication Header
IPSec has two major security protocols in your chapter:
AH
and
ESP
Your source identifies Authentication Header (AH) and Encapsulating Security Payload (ESP) as the two primary IPSec security protocols.
✅ What Does AH Do?
AH = Authentication Header
AH focuses on:
Authentication + Integrity
It verifies that the packet:
Came from the expected source
Has not been altered
Your source says AH authenticates both the data and IP header using a one-way hash.
Think:
Packet sent
↓
AH hash created
↓
Packet arrives
↓
Hash checked
↓
Same?
✅ Packet authentic
Different?
❌ Packet changed🚨 AH Does NOT Encrypt
This is EXAM GOLD.
AH does not provide encryption.
It can prove:
"This packet is authentic and wasn't changed."
But it does NOT hide the packet contents.
AH
✅ Authentication ✅ Integrity ❌ Encryption
Your source explicitly says AH does not provide encryption services.
🧠 Memory
AH = Authenticate, not Hide
AH = Authentication Header.
🔒 4. ESP — Encapsulating Security Payload
ESP = Encapsulating Security Payload
ESP provides more security functionality.
The huge one:
Encryption / Confidentiality
Your chapter says ESP can provide:
Confidentiality
Data-origin authentication
Integrity
Anti-replay protection
Traffic-flow confidentiality
🔐 ESP Confidentiality
Confidentiality basically means:
Encryption
The sender encrypts data so someone sniffing the traffic cannot simply read it.
Original:
PASSWORD123
↓
ESP
Encrypted:
8dj$92jd!#Your source explains that ESP encryption helps prevent eavesdropping.
🧠 Memory
ESP = Encrypts Secure Payload
Again, memory trick—not the literal acronym.
✅ ESP Integrity
ESP also helps verify:
The data wasn't changed during transmission.
If someone modifies the protected data:
Original
📦 ABC123 Attacker changes it 📦 XYZ123 ↓ Integrity check ↓ ❌ Something changed
Your chapter lists data integrity as one of ESP's protections.
👤 ESP Authentication
ESP can also authenticate the source.
Think:
"Did this protected traffic actually come from the expected endpoint?"
Your source includes data-origin authentication as an ESP capability.
🔁 Anti-Replay Protection
Another important IPSec concept is:
Anti-Replay
A replay attack occurs when an attacker captures valid traffic and later sends the same traffic again.
Example:
✅ Legit packet ↓ Attacker copies it 👀 ↓ Later... ↓ Attacker sends copy again
ESP can use sequence information to help detect duplicate/replayed traffic.
Your chapter specifically describes anti-replay protection and sequence numbers being used to defeat replay attacks.
🧠 Memory
Anti-Replay = Don't accept the same old packet again
🆚 AH vs. ESP
This is VERY testable.
AH
Authentication ✅
Integrity ✅
Encryption ❌ESP
Encryption ✅ Authentication ✅ Integrity ✅ Anti-Replay ✅
🧠 Best Memory
AH = Authenticate
ESP = Encrypt + Protect
🔑 5. IKE — Internet Key Exchange
Now we need a way for two IPSec endpoints to agree on:
What security should we use?
That's where:
IKE
comes in.
IKE = Internet Key Exchange
IKE is used to:
Negotiate IPSec security
Your chapter says IKE negotiates Security Associations (SAs) between endpoints.
🧠 Memory
IKE = IPSec negotiation
🤝 Security Association — SA
A Security Association defines things such as:
Authentication
Encryption
IPSec protocols
Basically:
The security rules both endpoints agree to use.
Your chapter explicitly says an SA defines the authentication, encryption, and IPSec protocols used for the connection.
Think:
Router A:
"I want AES."
Router B:
"I support AES."
↓
🤝 Security Association
↓
Secure IPSec connection🔑 IKE Phase 1
Your chapter divides IKE into two phases.
Phase 1
The endpoints agree on the initial security parameters.
Your source says they agree on things including:
Hash
Authentication
Group
Lifetime
Encryption
Then they authenticate and create an initial secure tunnel.
Don't overcomplicate it.
🧠 Think:
Phase 1 = Build the secure relationship
🔐 IKE Phase 2
Then:
Phase 2 negotiates IPSec itself
The already-secure Phase 1 tunnel protects the Phase 2 negotiation.
Phase 2 determines the IPSec transform information, including things such as AH/ESP, encryption, hashing, and tunnel mode.
🧠 Think:
Phase 1 = Secure the negotiation
Phase 2 = Build the IPSec connection
Your source says the key takeaway for Network+ is simply that IKE negotiates the IPSec tunnel in two phases.
🚨 EXAM SCENARIO #1
A company wants to tunnel routing-protocol traffic between two offices, but GRE by itself does not protect the data.
What solution makes sense?
✅ GRE over IPSec
Why?
GRE carries the traffic.
IPSec secures it.
🚨 EXAM SCENARIO #2
An administrator needs packet authentication and integrity but does not need encryption.
Which IPSec protocol?
✅ AH
🚨 EXAM SCENARIO #3
An administrator needs confidentiality/encryption for IPSec traffic.
Which protocol?
✅ ESP
🚨 EXAM SCENARIO #4
Two VPN endpoints need to negotiate the security settings used by IPSec.
Which protocol?
✅ IKE
🎴 Flashcards
⭐ 1
What is GRE primarily used for?
A. DNS resolution
B. Tunneling and encapsulating other protocols
C. Assigning IP addresses
D. Email encryption
✅ GRE
⭐ 2 — EXAM GOLD
Does GRE provide encryption by itself?
A. Yes
B. No
✅ No
GRE provides tunneling, not security.
⭐ 3
What is a passenger protocol in GRE?
A. The protocol managing encryption
B. The protocol being carried inside the GRE tunnel
C. The routing table
D. The TCP handshake
✅ B
⭐ 4
Which technology provides secure tunneling across an IP network?
A. ARP
B. GRE alone
C. IPSec
D. ICMP
✅ IPSec
⭐ 5 — Scenario
A company needs to carry routing-protocol traffic through a tunnel while also protecting that traffic.
Which solution BEST fits?
A. GRE only
B. IPSec only
C. GRE over IPSec
D. ARP over TCP
✅ GRE over IPSec
⭐ 6
Which two primary security protocols does your chapter associate with IPSec?
A. TCP and UDP
B. GRE and ARP
C. AH and ESP
D. ICMP and IP
✅ AH and ESP
⭐ 7 — EXAM GOLD
Which IPSec protocol provides authentication and integrity but does not provide encryption?
A. AH
B. ESP
C. GRE
D. IKE
✅ AH
⭐ 8
What does AH stand for?
A. Authentication Header
B. Authorization Header
C. Authentication Host
D. Advanced Hash
✅ Authentication Header
⭐ 9
Which statement correctly describes AH?
A. AH only provides encryption.
B. AH verifies authenticity/integrity but does not encrypt traffic.
C. AH is a routing protocol.
D. AH assigns encryption keys by itself.
✅ B
⭐ 10 — EXAM GOLD
Which IPSec protocol provides confidentiality through encryption?
A. AH
B. ESP
C. GRE
D. ARP
✅ ESP
⭐ 11
What does ESP stand for?
A. Encrypted Security Protocol
B. Encapsulating Security Payload
C. Ethernet Security Payload
D. Encapsulated Session Protocol
✅ B
⭐ 12
Which security feature helps prevent a captured valid packet from being sent again later?
A. ARP caching
B. Flow control
C. Anti-replay
D. DNSSEC
✅ Anti-replay
⭐ 13
Which protocol negotiates IPSec Security Associations between endpoints?
A. AH
B. GRE
C. IKE
D. ARP
✅ IKE
⭐ 14
What does IKE stand for?
A. Internet Kernel Encryption
B. Internet Key Exchange
C. Internal Key Encapsulation
D. Internet Key Ethernet
✅ Internet Key Exchange
⭐ 15
What does an IPSec Security Association define?
A. DNS records
B. DHCP addresses
C. Authentication, encryption, and IPSec security settings
D. MAC-address mappings
✅ C
⭐ 16
What is the main purpose of IKE Phase 1?
A. Resolve the VPN gateway MAC address
B. Establish initial secure parameters and a secure relationship between endpoints
C. Transfer files
D. Configure DHCP
✅ B
⭐ 17
What primarily occurs during IKE Phase 2 in your chapter?
A. DNS resolution
B. ARP discovery
C. Negotiation of the IPSec connection and transform information
D. TCP connection teardown
✅ C
⭐ 18 — EXAM TRAP
Which statement correctly compares GRE and IPSec?
A. GRE encrypts traffic while IPSec only encapsulates it.
B. GRE provides tunneling, while IPSec provides security.
C. Both provide identical security.
D. Neither supports tunneling.
✅ B
🧠 Memory Board
🚇 GRE TUNNELING Carries other protocols "Passenger protocols" NO SECURITY ❌ NO ENCRYPTION ❌ 🔐 IPSec SECURE tunneling GRE + IPSec = Carry it + Protect it 🛡️ AH Authentication Header Authentication ✅ Integrity ✅ Encryption ❌ "Authenticate, not Hide" 🔒 ESP Encapsulating Security Payload Encryption ✅ Authentication ✅ Integrity ✅ Anti-Replay ✅ 🔑 IKE Internet Key Exchange Negotiates IPSec SA Security Association Defines security settings IKE Phase 1 = Build secure relationship IKE Phase 2 = Negotiate IPSec connection
🎯 Know These Cold
GRE = Tunneling / encapsulation
GRE provides NO encryption
GRE passenger protocol = traffic carried inside the tunnel
IPSec = Secure tunneling
GRE over IPSec = GRE carries traffic + IPSec protects it
AH = Authentication + integrity, NO encryption
ESP = Encryption/confidentiality + authentication + integrity + anti-replay
IKE = Negotiates IPSec
SA = Security Association
IKE Phase 1 = Initial secure relationship
IKE Phase 2 = Negotiate the IPSec connection
This completes the major Internet-layer security protocols in your Chapter 6 objectives.
GRE Encapsulation
🧠 Encapsulation = packet inside another packet.
Encapsulating Security Payload.
ESP can provide confidentiality, authentication, integrity, anti-replay, and limited traffic-flow confidentiality.
🧠 ESP = Encrypt + Protect.
IPSec secures traffic across IP networks using protections such as authentication, integrity, and encryption.
🧠 IPSec = secure IP tunneling.
IKE Phase 1 establishes initial secure parameters, authenticates the peers, and builds the secure relationship.
🧠 Phase 1 = build the secure relationship.
IKE Phase 2 negotiates the actual IPSec connection and transform information, including AH/ESP, encryption, hashing, and mode.
🧠 Phase 2 = negotiate the IPSec connection
A Security Association defines agreed authentication, encryption, and IPSec security settings.
🧠 SA = agreed security settings.
Anti-replay detects and rejects captured valid packets that are resent later.
🧠 Anti-Replay = don't accept the same old packet again.
GRE vs IPSec
GRE carries traffic through tunnels. IPSec protects traffic. GRE alone does not encrypt.
A passenger protocol is the protocol being carried inside the GRE tunnel, such as IPv6, OSPF, or EIGRP.
🧠 Passenger = what's riding inside GRE.
AH authenticates and protects integrity without encryption. ESP can provide encryption, integrity, authentication, and anti-replay.
🧠 AH = authenticate. ESP = encrypt + protect.