Describe remote-access and site-to-site IPsec VPNs, tunnels, peers and the security services they provide.
IPsecRemote accessSite-to-siteIKEESP
01 // Mental model
Start with the big picture.
An individual user or endpoint establishes a protected connection into an organisation.
CCNA focus: A VPN protects data across an untrusted path; it does not automatically make every endpoint or authorised action safe. Authentication, segmentation and endpoint controls still matter.
02 // Building blocks
Know what each part does.
01
Remote access
An individual user or endpoint establishes a protected connection into an organisation.
02
Site-to-site
Security gateways protect traffic between networks, usually transparently to inside hosts.
03
IKE
Negotiates peers, authenticates them and establishes cryptographic security associations.
04
IPsec/ESP
Protects data with confidentiality, integrity, origin authentication and anti-replay services as selected.
03 // Compare and recognise
Read the clues.
Item
What to remember
Tunnel mode
Protects the original IP packet inside a new outer IP packet; common for gateway VPNs.
Peer
The remote VPN endpoint participating in negotiation.
Interesting traffic
Traffic selected by policy for protection in policy-based designs.
NAT traversal
Encapsulates IPsec for operation through NAT where supported.
Read the example from top to bottom, then verify the resulting state. Configuration is only complete when the output matches the intended design.
05 // Exam and troubleshooting
Turn facts into a method.
Protects the original IP packet inside a new outer IP packet; common for gateway VPNs.
The remote VPN endpoint participating in negotiation.
Traffic selected by policy for protection in policy-based designs.
Encapsulates IPsec for operation through NAT where supported.
Exam checkpoint: A VPN protects data across an untrusted path; it does not automatically make every endpoint or authorised action safe. Authentication, segmentation and endpoint controls still matter.
06 // Check yourself
IPsec VPNs quiz.
1. Which VPN type usually connects two entire networks through gateways?
2. What does IKE primarily establish?
3. Which mode wraps the original IP packet with a new outer header?
4. What security property prevents undetected packet alteration?
5. Does a VPN remove the need for endpoint security?