Slide 1

Slide 1 text

Marc Khayat, CCIE #41288 Technical Manager 14-Dec-19 New module in CCNAv7 VPN and IPSec VPN Concepts

Slide 2

Slide 2 text

© 2019 Cisco and/or its affiliates. All rights reserved. Cisco Confidential • VPN Technology • Types of VPN • IPSec Agenda

Slide 3

Slide 3 text

© 2019 Cisco and/or its affiliates. All rights reserved. Cisco Confidential VPN Technology

Slide 4

Slide 4 text

© 2019 Cisco and/or its affiliates. All rights reserved. Cisco Confidential • Cost Savings • Security • Scalability • Compatibility Virtual Private Networks

Slide 5

Slide 5 text

© 2019 Cisco and/or its affiliates. All rights reserved. Cisco Confidential Basic VPN Types Remote-Access VPN Site-to-Site VPN Access

Slide 6

Slide 6 text

© 2019 Cisco and/or its affiliates. All rights reserved. Cisco Confidential Who manages the VPN?

Slide 7

Slide 7 text

© 2019 Cisco and/or its affiliates. All rights reserved. Cisco Confidential Types of VPN

Slide 8

Slide 8 text

© 2019 Cisco and/or its affiliates. All rights reserved. Cisco Confidential • Clientless VPN connection: • SSL • Browser-based • Client-based VPN connection • IPSec or SSL • Software such as AnyConnect Remote-Access VPNs

Slide 9

Slide 9 text

© 2019 Cisco and/or its affiliates. All rights reserved. Cisco Confidential SSL or IPSec?

Slide 10

Slide 10 text

© 2019 Cisco and/or its affiliates. All rights reserved. Cisco Confidential • Router or Firewall • Pass IP traffic only • Unicast Site-to-Site IPSec VPNs

Slide 11

Slide 11 text

© 2019 Cisco and/or its affiliates. All rights reserved. Cisco Confidential • GRE: no encryption, supports multicast/broadcast • Encapsulate traffic in GRE tunnel, then encrypt using IPSec. GRE over IPSec

Slide 12

Slide 12 text

© 2019 Cisco and/or its affiliates. All rights reserved. Cisco Confidential • Dynamically expand your GRE/IPSec tunnels • Spoke-to-spoke ensured by NHRP • Simplifies tunnel management Dynamic Multipoint VPNs

Slide 13

Slide 13 text

© 2019 Cisco and/or its affiliates. All rights reserved. Cisco Confidential • VTI simplifies config and makes it flexible • Supports multicast => no need for GRE IPsec Virtual Tunnel Interface

Slide 14

Slide 14 text

© 2019 Cisco and/or its affiliates. All rights reserved. Cisco Confidential • Layer 3 MPLS VPN - The service provider participates in customer routing by establishing a peering between the customer’s routers and the provider’s routers. • Layer 2 MPLS VPN - The service provider is not involved in the customer routing. Instead, the provider deploys a Virtual Private LAN Service (VPLS) to emulate an Ethernet multiaccess LAN segment over the MPLS network. Service Provider MPLS VPNs

Slide 15

Slide 15 text

© 2019 Cisco and/or its affiliates. All rights reserved. Cisco Confidential IPSec

Slide 16

Slide 16 text

© 2019 Cisco and/or its affiliates. All rights reserved. Cisco Confidential • Confidentiality - encryption • Integrity - hashing algorithms • Origin authentication - pre- shared keys (passwords), digital certificates, or RSA certificates • Diffie-Hellman - Secure key exchange IPSec Technologies

Slide 17

Slide 17 text

© 2019 Cisco and/or its affiliates. All rights reserved. Cisco Confidential • Select your preferred and supported protocols. • Build your own security associations. Security functions

Slide 18

Slide 18 text

© 2019 Cisco and/or its affiliates. All rights reserved. Cisco Confidential • Authentication Header (AH) • Encapsulation Security Protocol (ESP). IPsec Protocol Encapsulation

Slide 19

Slide 19 text

© 2019 Cisco and/or its affiliates. All rights reserved. Cisco Confidential • Data encryption • Symmetric algorithms Confidentiality

Slide 20

Slide 20 text

© 2019 Cisco and/or its affiliates. All rights reserved. Cisco Confidential • Data that is received is exactly the same data that was sent. Integrity

Slide 21

Slide 21 text

© 2019 Cisco and/or its affiliates. All rights reserved. Cisco Confidential • VPNs ends must confirm their identities Authentication

Slide 22

Slide 22 text

© 2019 Cisco and/or its affiliates. All rights reserved. Cisco Confidential • Public key exchange method to share secret key used for encryption/decryption Secure Key Exchange with Diffie-Hellman

Slide 23

Slide 23 text

© 2019 Cisco and/or its affiliates. All rights reserved. Cisco Confidential • Default is tunnel mode • Transport mode is used when VPN gateways are the destination of data stream. Transport vs Tunnel Mode

Slide 24

Slide 24 text

© 2019 Cisco and/or its affiliates. All rights reserved. Cisco Confidential

Slide 25

Slide 25 text

No content