ENSA-ch08

Module Objectives

  • Module Title: VPN and IPsec Concepts
  • Objective: Explain the usage of VPNs and IPsec for securing site-to-site and remote access connectivity.

VPN Technology

  • Definition of VPN:
    • Virtual Private Networks (VPNs) create end-to-end private network connections.
    • While virtual, they transport data across a public network, encrypting the data for confidentiality.
Benefits of VPN Technology
  • Cost Savings:
    • Reduces connectivity costs and increases remote connection bandwidth.
  • Security:
    • Utilizes encryption and authentication protocols to protect data from unauthorized access.
  • Scalability:
    • Easy to add new users without significant infrastructure changes; utilizes internet for connectivity.
  • Compatibility:
    • Implemented across a wide variety of WAN technologies, enabling high-speed connections for remote workers.
Types of VPNs
  1. Site-to-Site VPNs:
    • Terminated on VPN gateways which encrypt traffic only between gateways; internal hosts are unaware of VPN usage.
  2. Remote Access VPNs:
    • Dynamically created connections between a client and a VPN device.
    • Clientless: Connection secured via a web browser SSL connection.
    • Client-based: Requires VPN client software on the remote user’s device.
Enterprise and Service Provider VPNs
  • Enterprise VPNs:
    • Managed by the organization, using IPsec and SSL for site-to-site and remote access.
  • Service Provider VPNs:
    • Managed by providers using Multiprotocol Label Switching (MPLS) to secure channels between enterprise sites.

Types of VPNs

Remote-Access VPNs
  • Let remote/mobile users securely connect to the enterprise.
  • Can be created using IPsec or SSL.
SSL VPNs
  • Authentication uses public key infrastructure and digital certificates.
  • Suitable for web-based applications and file sharing.
  • Comparison with IPsec:
    • Application Support: Extensive for IPsec; Limited for SSL.
    • Authentication Strength: Strong for IPsec vs Moderate for SSL.
    • Encryption Strength: Strong (IPsec: 56-256 bits) vs Moderate to strong (SSL: 40-256 bits).
Site-to-Site IPsec VPNs
  • Connect networks over untrusted networks (e.g., the internet).
  • Normal unencrypted traffic sent through VPN gateways which encapsulate and encrypt it.
GRE over IPsec
  • Generic Routing Encapsulation (GRE) is a non-secure protocol; encapsulated by IPsec for secure transmission.
Dynamic Multipoint VPNs (DMVPNs)
  • Facilitates the creation of multiple VPNs dynamically and scalably, using a hub-and-spoke architecture.
IPsec Virtual Tunnel Interface (VTI)
  • Simplifies configuration for multiple sites; supports both unicast and multicast encrypted traffic.
Service Provider MPLS VPNs
  • Traffic is labeled and forwarded using MPLS, ensuring security by preventing visibility of customer traffic to each other.

IPsec Technologies

  • Purpose: Secures VPNs across IP networks.
  • Key Functions:
    • Confidentiality: Encryption to prevent unauthorized reading.
    • Integrity: Hashing to verify that data has not changed in transit.
    • Origin Authentication: Authenticated using the IKE protocol.
    • Diffie-Hellman: For secure key exchange.
IPsec Protocol Encapsulation
  • Authentication Header (AH): When confidentiality is not required.
  • Encapsulation Security Protocol (ESP): Provides confidentiality.
IPsec Encryption Algorithms
  • Examples: DES (56-bit), 3DES (three independent 56-bit keys), AES (128, 192, 256 bits), SEAL (160-bit).
Data Integrity
  • HMAC: Ensures message integrity using hash values.
  • Examples: MD5 (128-bit), SHA (160-bit).
Authentication Methods
  1. Pre-shared Key (PSK):
    • Easy manual configuration but does not scale well.
  2. RSA: Uses digital certificates for authentication.
Key Exchange via Diffie-Hellman
  • Securely establishes shared keys over insecure channels.
  • Varies by group sizes; larger sizes offer more security.

Revision Summary

  • A VPN encrypts data for confidentiality across the public network.
  • Key benefits of VPNs include cost savings, security, scalability, and compatibility.
  • Remote-access and site-to-site VPNs serve different connectivity needs.
  • Various tunneling protocols, including GRE and DMVPN, enhance flexibility and scalability.
  • IPsec provides crucial security mechanisms (confidentiality, integrity, authentication, key exchange) to protect data during transmission.