You are on page 1of 15

Introducing VPN Solutions

LAN Extension into a WAN

2007 Cisco Systems, Inc. All rights reserved.

ICND2 v1.08-1

What Is a VPN?

Virtual: Information within a private network is transported over a public network. Private: The traffic is encrypted to keep the data confidential.
2007 Cisco Systems, Inc. All rights reserved. ICND2 v1.08-2

Benefits of VPN

Cost Security Scalability


2007 Cisco Systems, Inc. All rights reserved. ICND2 v1.08-3

Site-to-Site VPNs

Site-to-site VPN: extension of classic WAN

2007 Cisco Systems, Inc. All rights reserved.

ICND2 v1.08-4

Remote-Access VPNs

Remote-access VPN: evolution of dial-in networks and ISDN

2007 Cisco Systems, Inc. All rights reserved.

ICND2 v1.08-5

VPN Clients

(legacy)

2007 Cisco Systems, Inc. All rights reserved.

ICND2 v1.08-6

What Is IPsec?

IPsec acts at the network layer, protecting and authenticating IP packets.


It is a framework of open standards that is algorithm independent. It provides data confidentiality, data integrity, and origin authentication.
2007 Cisco Systems, Inc. All rights reserved. ICND2 v1.08-7

IPsec Security Services


Confidentiality Data integrity Authentication Antireplay protection

2007 Cisco Systems, Inc. All rights reserved.

ICND2 v1.08-8

Confidentiality (Encryption)

2007 Cisco Systems, Inc. All rights reserved.

ICND2 v1.08-9

Encryption Algorithms

Encryption algorithms:
DES AES
2007 Cisco Systems, Inc. All rights reserved.

3DES RSA
ICND2 v1.08-10

DH Key Exchange

Diffie-Hellman algorithms:
DH1 DH2

DH5
2007 Cisco Systems, Inc. All rights reserved. ICND2 v1.08-11

Data Integrity

Hashing algorithms:
HMAC-MD5
HMAC-SHA-1
2007 Cisco Systems, Inc. All rights reserved. ICND2 v1.08-12

Authentication

Peer authentication methods:


PSKs RSA signatures

2007 Cisco Systems, Inc. All rights reserved.

ICND2 v1.08-13

IPsec Security Protocols

2007 Cisco Systems, Inc. All rights reserved.

ICND2 v1.08-14

IPsec Framework

2007 Cisco Systems, Inc. All rights reserved.

ICND2 v1.08-15

You might also like