VPN
VPN
• Site-to-Site VPNs:
– Intranet VPNs connect corporate headquarters, remote offices, and branch
offices over a public infrastructure.
– Extranet VPNs link customers, suppliers, partners, or communities of
interest to a corporate Intranet over a public infrastructure.
Cisco PIX 500 Series Security Appliances (Legacy) Secondary role Primary role
Cisco ASA 5500 Adaptive Security Appliances Primary role Secondary role
Yes
User Traffic IP Only?
No
No Yes
Unicast
Use GRE Tunnel Use IPsec VPN
Only?
Generic Routing Encapsulation (GRE)
ESP
AH ESP
+ AH
3
DES AES SEAL
DES
MD5 SHA
PSK RSA
ESP
AH ESP
+ AH
3
DES AES SEAL
DES
MD5 SHA
PSK RSA
• It only ensures the origin of the data and verifies that the
data has not been modified during transit.
• If the AH protocol is used alone, it provides weak protection.
• AH can have problems if the environment uses NAT.
Encapsulating Security Payload (ESP)
IPsec IPsec
IKE - Internet Key Exchange
IKE Phase 1 authenticates IPsec peers and negotiates IKE SAs to create a secure
Step 2
communications channel for negotiating IPsec SAs in Phase 2.
IKE Phase 2 negotiates IPsec SA parameters and creates matching IPsec SAs in the
Step 3
peers to protect data and messages exchanged between endpoints.
Data transfer occurs between IPsec peers based on the IPsec parameters and keys
Step 4
stored in the SA database.
Step 5 IPsec tunnel termination occurs by SAs through deletion or by timing out.
Step 1 – Interesting Traffic
Step 2 – IKE Phase 1
DH Key Exchange
DH Key Exchange
Peer Authentication
Step 3 – IKE Phase 2
IPsec Negotiation
Step 3 – IKE Phase 2
Security Associations
Step 4
IPsec Session
Step 5
Tunnel Termination
CCP ‘Wizards’
SSL IPsec
Moderate Stronger
Encryption
Key lengths from 40 bits to 128 bits Key lengths from 56 bits to 256 bits
Strong
Moderate
Authentication Two-way authentication using shared
One-way or two-way authentication
secrets or digital certificates
Moderate
Ease of Use Very high Can be challenging to nontechnical
users
Strong
Moderate
Overall Security Only specific devices with specific
Any device can connect
configurations can connect
SSL VPN
Clientless, Thin Client, or Full Client
Establishing SSL Session
Cisco Easy VPN
Cisco Easy VPN Components
• Cisco Easy VPN Server - A Cisco IOS router or Cisco PIX / ASA Firewall
acting as the VPN head-end device in site-to-site or remote-access
VPNs.
• Cisco Easy VPN Remote - A Cisco IOS router or Cisco PIX / ASA
Firewall acting as a remote VPN client.
• Cisco Easy VPN Client - An application supported on a PC used to
access a Cisco VPN server.
Cisco Easy VPN Exchange
Configuring Easy VPN Server
Configuring Easy VPN Server Physical
Interface
Configuring IKE Proposals
Configuring Transform Set
Configuring VPN Authentication Method List
Configuring VPN Authentication Group
Policy
Configuration Summary
Edit Easy VPN Server
Easy VPN Server Test
Connecting Using the Client
R1 R1-vpn-cluster.span.com