CHAPTER SEVEN Virtual Private Networks with IPsec

Terms You’ll Need to Understand:

Image

Virtual Private Network (VPN)

Image

IPsec

Image

Remote access VPNs

Image

Site-to-Site VPNs

Image

Secure Sockets Layer (SSL) VPN

Image

Easy VPN

Image

Web VPN

Image

Encryption algorithms and keys

Image

Hashing Media Authentication Code (HMAC)

Image

Diffie-Hellman (DH) Key Exchange

Image

Rivest Shamir Adleman (RSA) signatures

Image

Pre-shared keys (PSK)

Image

Hash, Authentication, Group, Lifetime, Encryption (HAGLE) memory aid

Image

Internet Key Exchange (IKE) policy set

Image

IPsec transform set

Image

Crypto Access Control List (ACL)

Image

Crypto map

Exam Topics Covered in This Chapter:

Image

Explain IKE protocol functionality and phases

Image

Describe the building blocks of IPSec and the security functions it provides

Image

Configure and verify an IPSec site-to-site VPN with pre-shared key authentication using SDM

Note

These exam topics are from cisco.com. Check there periodically for the latest exam topics and info.

IPsec is often described as a framework for real-time, secure communications. When properly configured, IPsec can scale to large networks, and in some cases, replace the requirement for dedicated WAN circuits. Organizations can leverage on existing high-speed Internet connections to provide reliable and secure transport of communications between the organization’s sites, as well as to its mobile workforce using IPsec. Understanding the systems that go into IPsec is critical to both configuring as well as troubleshooting the solution. Although this chapter will not go into great depth about the underlying theory of IPsec, it examines the separate components of the IPsec framework to the extent that this understanding will aid the reader in configuring IPsec. Toward the end of the chapter, we use first the CLI, then the Cisco SDM to configure a site-to-site IPsec VPN in order to cement the theory.

..................Content has been hidden....................

You can't read the all page of ebook, please click here login for view all page.
Reset