Security Fundamentals // Lesson 05

IPsec VPNs.

Describe remote-access and site-to-site IPsec VPNs, tunnels, peers and the security services they provide.

IPsecRemote accessSite-to-siteIKEESP
01 // Mental model

Start with the big picture.

An individual user or endpoint establishes a protected connection into an organisation.

CCNA focus: A VPN protects data across an untrusted path; it does not automatically make every endpoint or authorised action safe. Authentication, segmentation and endpoint controls still matter.
02 // Building blocks

Know what each part does.

01

Remote access

An individual user or endpoint establishes a protected connection into an organisation.

02

Site-to-site

Security gateways protect traffic between networks, usually transparently to inside hosts.

03

IKE

Negotiates peers, authenticates them and establishes cryptographic security associations.

04

IPsec/ESP

Protects data with confidentiality, integrity, origin authentication and anti-replay services as selected.

03 // Compare and recognise

Read the clues.

ItemWhat to remember
Tunnel modeProtects the original IP packet inside a new outer IP packet; common for gateway VPNs.
PeerThe remote VPN endpoint participating in negotiation.
Interesting trafficTraffic selected by policy for protection in policy-based designs.
NAT traversalEncapsulates IPsec for operation through NAT where supported.
04 // Traffic flow

Traffic flow.

Remote access: laptop -> encrypted tunnel -> VPN gateway -> internal service

Site-to-site: Branch LAN -> branch gateway
              == protected IPsec tunnel ==
              HQ gateway -> HQ LAN

Read the example from top to bottom, then verify the resulting state. Configuration is only complete when the output matches the intended design.

05 // Exam and troubleshooting

Turn facts into a method.

  • Protects the original IP packet inside a new outer IP packet; common for gateway VPNs.
  • The remote VPN endpoint participating in negotiation.
  • Traffic selected by policy for protection in policy-based designs.
  • Encapsulates IPsec for operation through NAT where supported.
Exam checkpoint: A VPN protects data across an untrusted path; it does not automatically make every endpoint or authorised action safe. Authentication, segmentation and endpoint controls still matter.
06 // Check yourself

IPsec VPNs quiz.

1. Which VPN type usually connects two entire networks through gateways?

2. What does IKE primarily establish?

3. Which mode wraps the original IP packet with a new outer header?

4. What security property prevents undetected packet alteration?

5. Does a VPN remove the need for endpoint security?

Score: 0 / 5