ENSA-ch08
Module Objectives
- Module Title: VPN and IPsec Concepts
- Objective: Explain the usage of VPNs and IPsec for securing site-to-site and remote access connectivity.
VPN Technology
- Definition of VPN:
- Virtual Private Networks (VPNs) create end-to-end private network connections.
- While virtual, they transport data across a public network, encrypting the data for confidentiality.
Benefits of VPN Technology
- Cost Savings:
- Reduces connectivity costs and increases remote connection bandwidth.
- Security:
- Utilizes encryption and authentication protocols to protect data from unauthorized access.
- Scalability:
- Easy to add new users without significant infrastructure changes; utilizes internet for connectivity.
- Compatibility:
- Implemented across a wide variety of WAN technologies, enabling high-speed connections for remote workers.
Types of VPNs
- Site-to-Site VPNs:
- Terminated on VPN gateways which encrypt traffic only between gateways; internal hosts are unaware of VPN usage.
- Remote Access VPNs:
- Dynamically created connections between a client and a VPN device.
- Clientless: Connection secured via a web browser SSL connection.
- Client-based: Requires VPN client software on the remote user’s device.
Enterprise and Service Provider VPNs
- Enterprise VPNs:
- Managed by the organization, using IPsec and SSL for site-to-site and remote access.
- Service Provider VPNs:
- Managed by providers using Multiprotocol Label Switching (MPLS) to secure channels between enterprise sites.
Types of VPNs
Remote-Access VPNs
- Let remote/mobile users securely connect to the enterprise.
- Can be created using IPsec or SSL.
SSL VPNs
- Authentication uses public key infrastructure and digital certificates.
- Suitable for web-based applications and file sharing.
- Comparison with IPsec:
- Application Support: Extensive for IPsec; Limited for SSL.
- Authentication Strength: Strong for IPsec vs Moderate for SSL.
- Encryption Strength: Strong (IPsec: 56-256 bits) vs Moderate to strong (SSL: 40-256 bits).
Site-to-Site IPsec VPNs
- Connect networks over untrusted networks (e.g., the internet).
- Normal unencrypted traffic sent through VPN gateways which encapsulate and encrypt it.
GRE over IPsec
- Generic Routing Encapsulation (GRE) is a non-secure protocol; encapsulated by IPsec for secure transmission.
Dynamic Multipoint VPNs (DMVPNs)
- Facilitates the creation of multiple VPNs dynamically and scalably, using a hub-and-spoke architecture.
IPsec Virtual Tunnel Interface (VTI)
- Simplifies configuration for multiple sites; supports both unicast and multicast encrypted traffic.
Service Provider MPLS VPNs
- Traffic is labeled and forwarded using MPLS, ensuring security by preventing visibility of customer traffic to each other.
IPsec Technologies
- Purpose: Secures VPNs across IP networks.
- Key Functions:
- Confidentiality: Encryption to prevent unauthorized reading.
- Integrity: Hashing to verify that data has not changed in transit.
- Origin Authentication: Authenticated using the IKE protocol.
- Diffie-Hellman: For secure key exchange.
IPsec Protocol Encapsulation
- Authentication Header (AH): When confidentiality is not required.
- Encapsulation Security Protocol (ESP): Provides confidentiality.
IPsec Encryption Algorithms
- Examples: DES (56-bit), 3DES (three independent 56-bit keys), AES (128, 192, 256 bits), SEAL (160-bit).
Data Integrity
- HMAC: Ensures message integrity using hash values.
- Examples: MD5 (128-bit), SHA (160-bit).
Authentication Methods
- Pre-shared Key (PSK):
- Easy manual configuration but does not scale well.
- RSA: Uses digital certificates for authentication.
Key Exchange via Diffie-Hellman
- Securely establishes shared keys over insecure channels.
- Varies by group sizes; larger sizes offer more security.
Revision Summary
- A VPN encrypts data for confidentiality across the public network.
- Key benefits of VPNs include cost savings, security, scalability, and compatibility.
- Remote-access and site-to-site VPNs serve different connectivity needs.
- Various tunneling protocols, including GRE and DMVPN, enhance flexibility and scalability.
- IPsec provides crucial security mechanisms (confidentiality, integrity, authentication, key exchange) to protect data during transmission.