now, after you choose whether or not you want to be in tunnel mode or transport mode, the next decision you want to make is what sort of protocols you want to use for I p sec.
There are two main ones that provide the security service.
One is called a H, which stands for authentication. Hutter
Authentication header will provide non repudiation
because what will happen is I p sack and authentication is the authentication header is going to run something called an I c v
an integrity check value.
That integrity check value is essentially a hash.
We haven't talked about what hashing is yet, but the whole purpose of a hash is to detect modification
by running this integrity check value on the header of the packet that guarantees the header hasn't been modified.
When a packet is spoofed, it's the IP header that does get modified.
So what we get is an assurance that the I P header has not been manipulated, which gives us authenticity
that giving us authenticity is great.
But we do not get confidentiality with the H
Honestly, a lot of times we use IP sec for confidentiality.
We want to encrypt our data so often we're going to use a different protocol called ESPN.
ESPN stands for encapsulating security payload.
That's the protocol that's going to provide us with encryption.
It also uses something called a Mac, which is a message authentication code to determine whether or not there's been modification of the packet.
You really get pretty decent integrity, checking a little bit of authenticity and encryption with the SP, so it's a very popular choice.
The third protocol mentioned here is one called Ike Internet Key Exchange.
I always think about like like you think about a roadie at a concert.
You go to a concert, you show up early and there's a guy in a T shirt and cut off jeans no matter what the weather is. And he's laying out cable. He's checking the lights, checking the sound, tuning the instruments.
Nobody is really there to see that guy unless it's his mom, right?
We're here to see the main act, and that's like
like doesn't provide the security services.
Ike doesn't get any of the glory.
All ICP does is go out ahead of the communication or ahead of the exchange of information and sets up and negotiates algorithms and keys, Internet key exchange
and actually like, is made up of two sub protocols.
Wang called Oakley and the other called
Oakley initiates the key agreement through an algorithm called Diffie Hellman.
More to come on that later
I s a KMP sets up was referred to as a security association
And the security association is something you can think of, like a channel or unique identifier to reference each secure connection.
So if I have three different secure connections with three different systems,
have various essays, security associations
to identify, each one is unique. And actually, I'll have two essays, one for outgoing communication and one for an incoming communication
again. That Security Association allows me to keep each session as unique.
It has an identifying called the Security Parameters Index
and that one field will always be unique. Even if I have multiple secure sessions opened up on the same system,
the S P I will provide the randomness, or at least the pseudo randomness.
Next we got G R E, which is another protocol called generic routing encapsulation.
G R E doesn't really provide encryption or authentication.
It's just about encapsulation.
We saw this back in the olden days with systems using apple talk trying to traverse a TCP I network
so g r E would be used for encapsulation.
Now we see it with I P v s forward to IBV six networks.
Sometimes you'll see it for multicast traffic because multicast traffic can't traverse typical VPNs.
So G r E is something that's a protocol coming back into favor.
So let's wrap it up for remote access. We looked at dial up and talked about point to point protocol and the fact that it uses P A P C H A P and eat for authentication.
We said Point to point protocol provides the layer two connectivity and framing for w and connectivity and get authentication. We needed P A P, C h a p and eat
p a p. Sending passwords in plain text. We don't like it.
C H. A P protects our passwords better, but it's still only capable for password authentication.
And then keep is what we're using today in a lot of areas, because it will support more than just passwords, things like token certificates and so on.
What replaced dial up connectivity is tunneling and creating our VPNs,
and we're certainly looking at other ways to connect today beyond the VPNS.
But the VPNS were created with tunneling protocols.
We have point to point tunneling protocols, which was really the first main tunneling protocol.
We've got l two tp that enhance point to point tunneling protocol and allowed it to separate from I p networks.
L two tp has no built in security and it uses IP SEC to secure its traffic.
We have generic routing encapsulation, and we also talked about I P SEC, which can either be used for VPN tunnels. But it can certainly also be used on internal networks to protect traffic.
And those are your key takeaways.